Description
OpenRouter is hiring a hands-on GRC and compliance program owner to run its Drata and SafeBase programs, maintain SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and EU AI Act readiness, drive personnel compliance, lead security ceremonies, and translate emerging regulations into operational controls. The role reports to the Head of IT & Security, requires several years of GRC or compliance experience, at least one end-to-end SOC 2 audit cycle, and strong technical communication with engineering; it is a strategic, operational role with little daily management.
