Build OpenRouter's vendor/third-party risk management program from scratch, assessing AI model providers and subprocessors in a novel regulatory environment.
About OpenRouter OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads. We are a small team that punches above its weight. Every person here has direct impact on the product and our users.
About the Role Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl — they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.
If you've ever finished a vendor review and thought this should take a third as long and catch twice as much — and wanted to be the one to fix it — keep reading.
What You'll Do
What We're Looking For
Nice to Have
If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.
Sourced from the a16z Speedrun talent network — apply on Speedrun.