2 дня назад
Security Risk Analyst (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Risk Analyst (AI): Building OpenRouter's third-party risk management function for model providers, subprocessors, and SaaS vendors with an accent on security assessments, regulatory mapping, and risk-based decision-making. Focus on designing TPRM workflows, critically reviewing SOC 2 and ISO 27001 evidence, implementing GRC automation, and addressing vendor risk across AI infrastructure and data flows.
Location: Remote (US)
Company
provides an AI routing and infrastructure layer for accessing, managing, and optimizing AI usage through a unified API, billing interface, and analytics platform.
What you will do
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling.
- Critically review SOC 2 and ISO reports, penetration tests, DPAs, and subprocessor lists.
- Evaluate residual risk, compensating controls, exceptions, and risk acceptance decisions.
- Design and implement the third-party risk management program, including intake, tiering, SLAs, escalation, and annual reviews.
- Implement tooling integrated with Drata and ticketing systems to reduce assessment time.
- Build continuous monitoring for critical vendors and map vendor risk to compliance obligations.
Requirements
- 4+ years of experience in third-party/vendor security risk or security assessments.
- Working fluency with SOC 2, ISO 27001, HIPAA, and GDPR, plus practical knowledge of the EU AI Act.
- Technical literacy in cloud architecture, access models, encryption, and data flows.
- Experience with DPAs, BAAs, and security exhibits, including the ability to assess material contract clauses.
- Strong writing skills, independent execution, and comfort working with ambiguity.
- Must be based in the United States for this remote role.
Nice to have
- Experience assessing AI/ML vendors or inference infrastructure.
- ISO 42001 or NIST AI RMF experience.
- Scripting and automation experience.
- GRC platform administration experience with Drata, Vanta, or similar tools.
- Early-stage startup experience or CISSP, CISA, CRISC, or CTPRP certification.
Culture & Benefits
- Small team with direct individual impact on the product and users.
- Bias toward shipping and independently driving implementation.
- Opportunity to build a security risk function from the ground up in an evolving AI regulatory environment.
- Full-time remote employment in the United States.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Analyst, Third-Party Risk Management (TPRM) (AI)
132 600 - 195 000$
2 дня назад
Security Analyst III (SaaS)
5 дней назад
Director of Compliance & AI Governance
2 дня назад
Junior GRC Analyst (AI)
2 дня назад
InfoSec Analyst II, Trust (AI Governance)
96 000 - 160 000$
1 день назад
GRC/IT Compliance Analyst
108 000 - 130 000$