About the Role Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the ...
About the Role Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the ...
Sr. Analyst - Third Party Risk
Alpharetta, GA · On-site
$85K/yr
Third-Party Risk Senior Analyst - First Century Bank First Century Bank has an exciting career opportunity available for a Third-Party Risk Sr. Analyst to join our team. The Bank is growing its ...
Sr. Analyst - Third Party Risk
Alpharetta, GA · On-site
$85K/yr
Third-Party Risk Senior Analyst - First Century Bank First Century Bank has an exciting career opportunity available for a Third-Party Risk Sr. Analyst to join our team. The Bank is growing its ...
Third Party Risk Analyst
Tampa, FL · Remote
$60K - $90K/yr
Remote (Candidate must reside in the state of FL) Position Type: Full Time The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments ...
Third Party Risk Analyst
Tampa, FL · Remote
$60K - $90K/yr
Remote (Candidate must reside in the state of FL) Position Type: Full Time The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments ...
Third Party Risk Analyst
Tampa, FL · On-site +1
$60K - $90K/yr
Remote (Candidate must reside in the state of FL) Position Type: Full Time The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments ...
Third Party Risk Analyst
Tampa, FL · On-site +1
$60K - $90K/yr
Remote (Candidate must reside in the state of FL) Position Type: Full Time The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments ...
Third-Party Risk Senior Analyst - First Century Bank First Century Bank has an exciting career opportunity available for a Third-Party Risk Sr. Analyst to join our team. The Bank is growing its ...
Quick apply
Third-Party Risk Senior Analyst - First Century Bank First Century Bank has an exciting career opportunity available for a Third-Party Risk Sr. Analyst to join our team. The Bank is growing its ...
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst
Johnston, RI · On-site
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst
Johnston, RI · On-site
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
We are seeking a Third-Party Cybersecurity Risk Analyst to support the assessment, monitoring, and management of cybersecurity risks associated with third-party vendors and service providers. This ...
We are seeking a Third-Party Cybersecurity Risk Analyst to support the assessment, monitoring, and management of cybersecurity risks associated with third-party vendors and service providers. This ...
Risk Analyst
Woodbury, NY · On-site
$32 - $35/hr
Third-Party Risk Analyst II The Third-Party Risk Analyst II supports the Enterprise Risk Management team by assessing and monitoring risks associated with current and prospective third-party vendors.
Quick apply
Risk Analyst
Woodbury, NY · On-site
$32 - $35/hr
Third-Party Risk Analyst II The Third-Party Risk Analyst II supports the Enterprise Risk Management team by assessing and monitoring risks associated with current and prospective third-party vendors.
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
Third Party Risk Officer
Memphis, TN · On-site
The Third Party Risk Officer is responsible for the development, implementation, and ongoing ... Prepare and present program reports, risk insights, and metrics to senior management and the Board.
Third Party Risk Officer
Memphis, TN · On-site
The Third Party Risk Officer is responsible for the development, implementation, and ongoing ... Prepare and present program reports, risk insights, and metrics to senior management and the Board.
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of defense, with ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · On-site
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · On-site
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Officer
Memphis, TN · On-site
The Third Party Risk Officer is responsible for the development, implementation, and ongoing ... Prepare and present program reports, risk insights, and metrics to senior management and the Board.
Third Party Risk Officer
Memphis, TN · On-site
The Third Party Risk Officer is responsible for the development, implementation, and ongoing ... Prepare and present program reports, risk insights, and metrics to senior management and the Board.
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI · Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Senior Third Party Risk Analyst information
See salary details
$53.5K - $61.6K
1% of jobs
$61.6K - $69.7K
1% of jobs
$69.7K - $77.8K
3% of jobs
$77.8K - $85.9K
12% of jobs
$91.2K is the 25th percentile. Wages below this are outliers.
$85.9K - $94K
12% of jobs
$94K - $102K
14% of jobs
The median wage is $106.1K / yr.
$102K - $110.1K
14% of jobs
$110.1K - $118.2K
10% of jobs
$118.2K - $126.3K
3% of jobs
$126.3K - $134.4K
2% of jobs
$135.3K is the 75th percentile. Wages above this are outliers.
$134.4K - $142.5K
28% of jobs
$53.5K
$109.8K
$142.5K
How much do senior third party risk analyst jobs pay per year?
What is a senior third party risk analyst?
What are the key skills and qualifications needed to thrive as a senior third party risk analyst?
How does a senior third party risk analyst typically collaborate with other departments to manage vendor risks?
What is the difference between Senior Third Party Risk Analyst vs Third Party Risk Analyst?
| Aspect | Senior Third Party Risk Analyst | Third Party Risk Analyst |
|---|---|---|
| Required Credentials | Bachelor's degree, certifications like CTPRP or CRISC, experience in risk management | Bachelor's degree, certifications like CTPRP or CRISC, entry to mid-level experience |
| Work Environment | Financial institutions, large corporations, consulting firms | Financial services, healthcare, technology companies |
| Employer & Industry Usage | Used in organizations with complex third-party relationships | Common in industries with third-party dependencies |
The Senior Third Party Risk Analyst typically has more experience and handles complex risk assessments, often leading initiatives. The Third Party Risk Analyst is usually an entry to mid-level role focused on supporting risk evaluations. Both roles require similar credentials but differ in responsibility level and scope.
What cities are hiring for Senior Third Party Risk Analyst jobs?
Cities with the most Senior Third Party Risk Analyst job openings:
What are the most commonly searched types of Third Party Risk Analyst jobs?
The most popular types of Third Party Risk Analyst jobs are:
What states have the most Senior Third Party Risk Analyst jobs?
States with the most job openings for Senior Third Party Risk Analyst jobs include:
What job categories do people searching Senior Third Party Risk Analyst jobs look for?
The top searched job categories for Senior Third Party Risk Analyst jobs are:

Full-time
Posted 19 days ago
Job description
OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.
We are a small team that punches above its weight. Every person here has direct impact on the product and our users.
About the Role
Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.
If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.
What You'll Do
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.
- Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.
- Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.
- Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
- Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
- Build continuous monitoring for critical vendors and run annual reviews on a real cadence.
- Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.
What We're Looking For
- 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.
- Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
- Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.
- Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
- A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
- Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.
Nice to Have
- Experience assessing AI/ML vendors or inference infrastructure
- ISO 42001 or NIST AI RMF
- Scripting and automation to eliminate your own toil
- GRC platform administration (Drata, Vanta, or similar)
- Time at an early-stage startup where you built the function rather than joined it
- CISSP, CISA, CRISC, or CTPRP.
If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.