About the Role
The Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. This role involves driving the continuous maturation of the TPRM program, architecting security strategies for the BPO and contingent worker ecosystem, and pioneering the Supplier Security AI Governance framework. You will also establish core program governance, lead risk assessments, and manage the end-to-end issues and remediation tracking process.
Responsibilities
- Drive the continuous maturation of our TPRM program, transforming it from a reactive, compliance-focused function into a proactive, strategic security partnership.
- Architect and govern the security strategy for our BPO and contingent worker ecosystem, from developing and operationalizing continuous security standards to implementing & monitoring robust technical controls and ensuring strict compliance through rigorous due diligence and regular audit cycles.
- Design and build process automations, optimizing and scaling the TPRM program to meet the business’s fast-moving priorities.
- Pioneer and lead the Supplier Security AI Governance framework, evaluating critical third-party AI risks to ensure the secure implementation of AI tools across the business.
- Establish and own core program governance and build a centralized reporting function, delivering actionable key metrics, risk dashboards, and progress updates to leadership for continuous visibility into third-party risk exposure.
- Partner cross-functionally with security engineering, procurement, business, privacy, and legal teams to provide security advisory and lead risk assessments.
- Lead the end-to-end issues and remediation tracking process, following up on all security findings and exceptions from assessments to ensure accountability and timely closure of remediation items.
- Execute the core TPRM lifecycle (perform risk assessments, due diligence questionnaires, new vendor onboarding, contract and data protection agreement reviews) and partner with internal SMEs (Sourcing, Enterprise Security, IT) to refine internal policies and frameworks for scale.
Requirements
- 7+ years of progressive experience in security-focused TPRM methodologies, including owning or successfully leading a TPRM program for a fast-paced, high-growth company.
- Experience with program building, conducting security and/or assurance audits, controls, and risk assessments, and remediation management.
- Deep technical understanding and experience conducting comprehensive security risk and gap assessments of cloud, SaaS, including Artificial Intelligence (AI) solutions, and infrastructure vendors, and evaluating risks that impact data security and application resilience.
- Proficiency in the technical review of core security assurance documentation. This encompasses, but is not limited to, CAIQ, SIG, SOC 2 Type 2 reports, Penetration Test reports, and compliance attestations (e.g., ISO 27001, PCI-DSS, etc).
- Experience in the technical vetting of complex vendor solutions. This involves scrutiny of API integrations with critical internal systems ('crown-jewels'), security of cloud-native services (AWS/Azure/GCP), and assessing agentic/generative AI platforms for vulnerabilities, data leakage, and system resilience.
- Practical experience in assessing the unique risks associated with AI/ML models, including analysis of data provenance, identification of model poisoning risks, and ensuring the secure handling of proprietary data used for model training or fine-tuning.
- Experience with implementing major information security, privacy, and risk management frameworks (e.g. NIST, ISO, SOC 2).
- Experience managing security and compliance programs across broad GRC disciplines within a complex, global public company environment.
- Experience solving complex, systemic issues that require creative thinking and cross-functional collaboration.
- Experience managing vendor risk across the full relationship lifecycle, including periodic re-assessments, amendments, scope changes, and continuous monitoring.
- Excellent verbal and written communication skills with the ability to effectively translate technical risk findings into a clear business context for diverse audiences, including executive leadership.
Skills
- Third-Party Risk Management (TPRM)
- Security Audits
- Risk Assessments
- Remediation Management
- Cloud Security
- SaaS Security
- Artificial Intelligence (AI) Security
- Infrastructure Vendor Risk
- Data Security
- Application Resilience
- CAIQ
- SIG
- SOC 2 Type 2
- Penetration Test reports
- ISO 27001
- PCI-DSS
- API Integrations
- AWS
- Azure
- GCP
- Agentic AI
- Generative AI
- AI/ML Models
- NIST
- ISO
- SOC 2
- GRC
Location
- United States
- Illinois
- Colorado
- Remote
Work Type
- Full-time
Experience Level
- Senior
- 7+ years
Education Level
- Bachelor's degree in Information Security, Computer Science, Business Administration, or related field
- Master's degree in Information Security, Computer Science, Business Administration, or related field
Salary/Compensations
- $132,600—$195,000 USD
Benefits
- 401(k) plan with employer matching
- 16 weeks of paid parental leave
- Wellness benefits
- Commuter benefits match
- Paid time off
- Paid sick leave
- Medical benefits
- Dental benefits
- Vision benefits
- 11 paid holidays
- Disability insurance
- Basic life insurance
- Family-forming assistance
- Mental health program
- Flexible paid time off/vacation for salaried roles
- 80 hours of paid sick time per year for salaried roles
About the Company
- At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers.
- We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods.
- DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers.
- We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more.
Equal Opportunity
- We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel.
- In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status.
- Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office.
- Whether blatant or hidden, barriers to success have no place at DoorDash.
- We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply.
- Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.
- If you need any accommodations, please inform your recruiting contact upon initial connection.
