
About OpenRouter
OpenRouter is the leading AI routing and infrastructure layer that enterprises use to access, manage, and optimize the best large language models across providers—without lock-in, capacity constraints, or unnecessary cost. We power the most advanced AI teams in the world by giving them the flexibility to move fast, scale confidently, and stay future-proof as models evolve.
As enterprise adoption of AI accelerates, OpenRouter sits at the center of how organizations operationalize LLMs across research, product, and production workloads.
About the Role
As GRC Manager, you will own OpenRouter's compliance program day to day, reporting to the Head of IT & Security. You will be responsible for managing tools like Drata and Safebase, and ensuring compliance with regulations such as SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act. This role requires a strategic builder ready to roll up their sleeves, as you will run the program with very little daily management.
The real work involves effectively engaging engineers mid-sprint for evidence, ensuring company-wide training completion, and building cross-functional influence. This is not a role for overseeing a program someone else operates. You will also navigate a space where regulation is still being written, requiring you to interpret novel requirements for the business without an established playbook.
What You'll Do
- Own Drata end to end — administration, integrations, monitoring test health, and manual evidence collection where automation doesn't reach.
- Curate the SafeBase knowledge base to enable sales to self-serve most customer security questionnaires, and serve as the escalation point for complex inquiries.
- Drive personnel compliance: manage policy acknowledgments, device compliance, and recurring security and compliance training. This involves actively chasing people down and building habits, not just running reports.
- Lead recurring ceremonies: user access reviews, penetration tests, BCDR and incident response tabletops, annual policy review and updates, and risk assessments.
- Work directly with Engineering on product-related compliance questions, from data handling to customer commitments.
- Maintain audit readiness across SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act.
- Translate emerging AI regulation into actionable controls for the business, rather than waiting for external checklists.
- Partner with HR, Legal, Customer Support, and Finance to integrate compliance into existing workflows.
What We're Looking For
- Several years of hands-on experience in GRC or compliance, having built and run programs, not just governed them.
- At least one SOC 2 audit cycle owned end to end, from evidence collection through fieldwork.
- Admin-level fluency in a compliance automation platform (Drata strongly preferred).
- Technical proficiency sufficient to engage in meaningful conversations with engineers about architecture and data flows.
- Proven ability to influence cross-functionally without becoming a person others avoid.
- Comfortable with shifting requirements and operating in situations where precedent does not exist.
Nice to Have
- PCI DSS experience in a startup environment.
- HIPAA experience as a Business Associate.
- Familiarity with the EU AI Act or other emerging AI regulation.
- Certifications such such as CISA, CISSP, or CIPP.
- Experience as a first compliance hire.
- Scripting skills for evidence collection.
Timezone overlap
UTC-8–-4
Open to
US
Sign in to track applications and earn points.