DoorDash

DoorDash

DoorDash empowers small business owners by providing an affordable and convenient platform for local delivery services, primarily focusing on restaurant food delivery.

Air Freight & Logistics
10K-50K
Founded 2012

Description

  • Manage the full third-party risk lifecycle, including vendor discovery, tiering, due diligence, onboarding, monitoring, remediation, and exit.
  • Lead technical assessments of vendors connected to critical systems, cloud environments, source code, CI/CD, identity platforms, and sensitive data.
  • Define mitigation plans, security contract terms, remediation requirements, residual-risk acceptance, and vendor exit controls.
  • Develop and execute an AI-native TPRM roadmap, including agentic workflows for evidence collection, assessment, and follow-up.
  • Own the risk framework for third-party AI and agentic services, including model providers, connectors, permissions, data use, subprocessors, and prompt injection risks.
  • Hire, coach, and manage TPRM analysts and other US-based GRC team members.
  • Provide US-hours GRC leadership, escalation support, and delegated decision-making for vendor incidents, audits, and urgent business needs.
  • Report TPRM performance and risk metrics to leadership and auditors, including critical-system exposure, remediation status, exceptions, and automation outcomes.

Requirements

  • 6+ years of progressive experience in technical third-party risk, security risk, or security engineering, including ownership of a TPRM program.
  • Experience leading distributed teams and coordinating work across GRC specialties.
  • Deep knowledge of enterprise integrations, including SAML/OIDC, OAuth, SCIM, APIs, service accounts, cloud IAM, network boundaries, and data flows.
  • Strong assurance and control-testing experience with SOC 2 Type II, penetration tests, ISO 27001, and PCI DSS evidence.
  • Experience using or piloting AI-assisted workflows and defining an AI-native or agentic TPRM strategy.
  • Experience implementing or improving TPRM/GRC platforms and workflow automation, with knowledge of APIs and integration patterns.
  • Python, SQL, low-code orchestration, and production-scale agentic experience are preferred.
  • Hands-on knowledge of cloud and SaaS security, privileged supplier access, data protection, incident response, recovery, threat modeling, and AI-specific risks.
  • Strong executive communication, judgment, stakeholder management, and experience handling urgent US-hours escalations.
  • Ability to work in the United States, preferably in the Eastern or Central time zones.

Benefits

  • Base salary range of $164,200–$241,500 USD, localized by work location.
  • Equity grant opportunities.
  • Medical, dental, and vision insurance, plus disability and basic life insurance.
  • 401(k) plan with employer matching.
  • 16 weeks of paid parental leave and family-forming assistance.
  • Flexible paid time off, paid sick leave, and 11 paid holidays.
  • Wellness, commuter matching, and mental health benefits.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Incident Response Lead

Aspenview Technology Partners Internet Software & Services

AspenView Technology Partners is hiring a US-based Incident Response Lead to direct major incident response and digital forensics for a large consumer lender supported by nearshore security operations teams.

AWS Azure Elasticsearch GCP Linux SIEM Splunk
3 days, 1 hour ago

Staff Security Researcher (Europe Remote)

Invicti 251-1K Internet Software & Services

Invicti Security is hiring a hands-on Offensive Security Researcher in Europe to research emerging web, cloud, and AI threats and turn findings into accurate, production-ready detection capabilities.

Burp Suite GraphQL HTTP JavaScript Kubernetes Nmap Python REST API
3 days, 2 hours ago

Director, OT/IoT Security Services- Remote (Anywhere in the U.S.)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Director of OT/IoT Security Services to lead its industrial cybersecurity practice, overseeing its team, service portfolio, delivery quality, client engagements, and financial performance.

Cybersecurity
5 days ago

Technical Consultant - Network Security SASE

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to independently deliver enterprise SASE and SSE deployments, configuring Zero Trust architectures across platforms such as Zscaler, Palo Alto Prisma Access, Cisco Secure Access, and Netskope.

Network Security
1 week, 6 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers