Senior Analyst, Third-Party Risk Management (TPRM)

4 weeks, 1 day ago
Full-time
Senior
Cybersecurity
DoorDash

DoorDash

DoorDash empowers small business owners by providing an affordable and convenient platform for local delivery services, primarily focusing on restaurant food delivery.

Air Freight & Logistics
10K-50K
Founded 2012

Description

  • Drive the continuous maturation of the third-party risk management program from reactive compliance toward proactive security partnership.
  • Architect and govern security strategy for business process outsourcing and contingent worker ecosystems, including security standards, technical controls, due diligence, and audit cycles.
  • Design and build process automations to scale the TPRM program and support fast-moving business priorities.
  • Lead the Supplier Security AI Governance framework and assess third-party AI risks for secure AI adoption across the business.
  • Establish program governance and centralized reporting, including key metrics, risk dashboards, and leadership updates.
  • Partner with security engineering, procurement, business, privacy, legal, sourcing, enterprise security, and IT teams on security advisory and risk assessments.
  • Lead end-to-end issues and remediation tracking to ensure findings, exceptions, and remediation items are closed on time.
  • Execute the TPRM lifecycle, including risk assessments, due diligence questionnaires, vendor onboarding, and contract and data protection agreement reviews.
  • Refine internal policies and frameworks for scalable vendor risk management.
  • Manage vendor risk across the full relationship lifecycle, including reassessments, amendments, scope changes, and continuous monitoring.

Requirements

  • 7+ years of progressive experience in security-focused third-party risk management, including ownership or leadership of a TPRM program in a fast-paced, high-growth company.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or a related field.
  • Experience building programs, conducting security or assurance audits, managing controls, performing risk assessments, and overseeing remediation.
  • Deep technical understanding of cloud, SaaS, AI, and infrastructure vendor risk assessments, including impacts to data security and application resilience.
  • Experience reviewing security assurance documentation such as CAIQ, SIG, SOC 2 Type 2 reports, penetration test reports, and compliance attestations including ISO 27001 and PCI-DSS.
  • Experience vetting complex vendor solutions, including API integrations with critical internal systems and cloud-native services in AWS, Azure, or GCP.
  • Practical experience assessing AI/ML risks, including data provenance, model poisoning, and secure handling of proprietary training or fine-tuning data.
  • Experience implementing information security, privacy, and risk management frameworks such as NIST, ISO, and SOC 2.
  • Experience managing security and compliance programs across broad GRC disciplines in a complex global public company environment.
  • Experience solving systemic issues through creative thinking and cross-functional collaboration.
  • Excellent verbal and written communication skills, including the ability to explain technical risk findings in business terms for executive audiences.
  • CISA, CISSP, CISM, or other industry certifications are a plus.

Benefits

  • Starting base salary range of $132,600 to $195,000 USD.
  • Opportunities for equity grants.
  • 401(k) plan with employer matching.
  • 16 weeks of paid parental leave.
  • Medical, dental, and vision insurance.
  • 11 paid holidays.
  • Disability and basic life insurance.
  • Flexible paid time off for salaried roles, plus 80 hours of paid sick time per year.
  • Wellness benefits, including a wellness expense reimbursement and mental health program.
  • Commuter benefits match and family-forming assistance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IT Operations Specialist

Alpaca 51-250 Capital Markets

Alpaca is hiring an IT Operations Specialist to support its globally distributed team and help maintain secure, reliable internal IT operations for a remote brokerage infrastructure company.

Cybersecurity Linux macOS
19 hours, 53 minutes ago

Chargeback Data Analyst (MX)

Signifyd 251-1K IT Services

Signifyd is hiring a Data Analyst for its Chargeback Investigations team to use data and operational analysis to reduce fraud-related losses and improve dispute outcomes for merchants.

Databricks Looker Python Shopify SQL
20 hours, 8 minutes ago

Director of Security Operations, Remote

Aledade 1K-5K Health Care Providers & Services

Aledade is hiring a Director of Security Operations to lead its SOC and security response efforts that protect the company’s assets, data, patients, and reputation.

HIPAA SIEM
20 hours, 38 minutes ago

Senior Business Operations & Programme Manager, EMEA

Lever 251-1K Professional Services

Senior Business Operations & Programme Manager, Europe at Tiberius Aerospace, overseeing defence programme delivery and commercial operations across European and UK contracts as the company scales its regional business.

CRM ERP Salesforce
21 hours, 8 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers