Overview
About the Team
Full job description
About the Team DoorDash’s Global Governance, Risk and Compliance (GRC) team helps the business scale securely through practical risk-based decisions, reliable controls and clear accountability. Our third-party risk program protects the systems and data behind our marketplace across DoorDash, Wolt, and Deliveroo. About the Role We’re looking for a Third-Party Risk Management (TPRM) Manager to lead a technically rigorous global program and shape its AI-native future. You will own the vendor security risk lifecycle, lead complex assessments of integrations with our most critical systems and data, and develop a team that makes clear, evidence-based risk decisions. You will also set the vision and build practical agentic workflows that improve how we gather evidence, assess risk, and follow through on remediation. Reporting to the Global Head of GRC, you will serve as their US-based deputy and provide GRC leadership and escalation coverage during US business hours. You will directly manage TPRM analysts together with other US-based GRC team members assigned to your organization. This role combines hands-on technical judgment, program ownership and people leadership. You will be based in the United States, preferably within the Eastern or Central timezones, with core working hours aligned to US business needs and clear handoffs with global colleagues. What you will do Run the day-to-day TPRM program operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation and exit. Maintain a reliable vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo, covering cloud, SaaS, business process outsourcing (BPO), and other critical suppliers. Lead assessments of vendors connected to crown jewel systems, including identity platforms, production cloud, source code and CI/CD, and sensitive-data platforms. Examine architecture, data flows, permissions, and control evidence. Use structured threat modeling to identify realistic compromise paths and define testable requirements for access, isolation, secrets, encryption, logging and revocation. Turn findings into accountable risk decisions. Agree mitigation plans and security contract terms with vendors, Legal, Privacy, Procurement, and system owners. Verify remediation, document residual risk acceptance with accountable business owners and review dates, and confirm access removal and data handling at termination. Address critical supplier dependencies, concentration risk, recovery capabilities, and exit readiness. Set the vision for an AI-native TPRM function. Build a prioritized roadmap for applying AI and automation across the vendor lifecycle, with clear outcomes, dependencies, and ownership. Evaluate what to configure, buy, or build, and align delivery with Security Engineering, IT, and platform owners. Build and pilot agentic workflows with the team to gather and reconcile evidence, identify control gaps, draft assessments, and coordinate follow-up. Scale the use cases that demonstrate better quality, coverage or turnaround. Use approved tools, APIs, and engineering partnerships, with evidence traceability, evaluations, data protection, appropriate access controls and human approval for consequential actions. Own the TPRM framework for third-party AI and agentic services. Assess model and data providers, connectors, tool permissions, training-data use, retention, subprocessors, prompt injection, and data exfiltration. Set onboarding and monitoring requirements that respond to material changes in models, integrations, and vendor practices. Hire, coach, and directly manage TPRM professionals and other US-based GRC direct reports. Own goals, workload, performance reviews, career development, and succession planning. Raise the team’s technical assessment and automation skills, working with functional leads to align priorities across GRC disciplines. Provide US-hours GRC coverage and escalation support in partnership with the Global Head of GRC. Lead stakeholder discussions, resolve operational escalations, and coordinate GRC input to vendor incidents, audits, and urgent business decisions. Exercise agreed delegated authority, route risk acceptance to accountable owners, and maintain clear decisions and handoffs with global leadership. Make risk and program performance visible to leadership and auditors. Report critical-system exposure, overdue remediation, exception aging, assessment quality, and review turnaround. Measure how AI and automation improve coverage or reduce effort, and translate material risks into business impact to guide priorities and investment. What you bring 6+ years of progressive experience in technical third-party risk, security risk, or security engineering, including substantial hands-on experience leading complex vendor assessments and ownership of a TPRM program. A track record of improving risk practices in a technology environment. Experience leading distributed teams and coordinating delivery across different GRC specialties. Deep experience assessing enterprise integrations and their failure modes. You can examine SAML/OIDC federation, OAuth scopes and tokens, SCIM provisioning, APIs, service accounts, cloud IAM, network boundaries, and data flows, then turn findings into practical integration requirements and verified remediation. Strong assurance and control-testing skills. You can evaluate SOC 2 Type II scope, exceptions, subservice organizations, and customer responsibilities; interpret penetration tests and ISO 27001 or PCI DSS evidence where relevant; and validate whether the evidence covers the service, integration, and data use being proposed. An AI-native working approach: you actively use AI to improve your work and have built or piloted AI-assisted workflows. You can articulate a vision for agentic TPRM, identify useful applications, and explain how you evaluate outputs, handle failures, and protect sensitive information. Experience implementing or improving TPRM/GRC platforms and workflow automation, with practical knowledge of APIs and integration patterns. You can define requirements, work with structured data, and partner with engineers on delivery. Python, SQL, low-code orchestration, and production-scale agentic experience are advantages. Hands-on knowledge of cloud and SaaS security, privileged supplier or BPO access, data protection, incident response, and recovery. You can apply security frameworks and threat modeling to a vendor’s actual deployment and assess AI-specific risks such as data use, tool permissions, and prompt injection. Sound judgment and executive communication, with experience representing a security or GRC leader, making decisions within delegated authority, and resolving difficult risk tradeoffs. You can earn credibility with engineers, Legal, Procurement, and business leaders while managing urgent US-hours escalations. Compensation The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future. In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information. DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others. To learn more about our benefits, visit our careers page here . See below for paid time off details: For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year. For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week). The national base pay range for this position within the United States, including Illinois and Colorado. $164,200 — $241,500 USD About DoorDash At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods. DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more. Our Commitment to Diversity and Inclusion We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel. Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non-discrimination. Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation. If you need any accommodations, please inform your recruiting contact upon initial connection. Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only We used Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provided Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound from August 21, 2023, through December 21, 2023. We resumed using Covey Scout for Inbound again on June 29, 2024, and ceased using Covey Scout for Inbound on April 30, 2026. The Covey tool has been reviewed by an independent auditor. Results of the audit may be viewed here: https://getcovey.com/nyc-local-law-144 . Beware of recruitment scams: DoorDash, Deliveroo, and Wolt will never ask you to pay money or share sensitive financial information during hiring — learn more about our legitimate recruiting process at Recruitment Scam Awareness - DoorDash .
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Doordashusa (greenhouse) →