Senior Analyst, Third-Party Risk Management (TPRM)

DoorDash

New York (NY)

On-site

USD 132,600 - 195,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DoorDash is seeking a security‑minded Sr. Analyst for Third‑ Party Risk Management. You will own the TPRM lifecycle, drive risk assessments, and partner with security, procurement, privacy, and legal teams to strengthen the company’s vendor security posture.

You will lead the development of AI governance for third‑party tools, build scalable automations, and deliver risk dashboards to leadership for ongoing visibility into third‑party risk exposure.

Qualifications

  • Experience owning or leading a TPRM program in a fast‑paced, high‑growth company.
  • Strong background in security risk assessments, audits, and remediation management.
  • Technical vetting of cloud/SaaS vendors, AI/ML risk, and API integrations.

Responsibilities

  • Drive maturation of the TPRM program from reactive to proactive security partner.
  • Architect security strategy for the BPO and contingent worker ecosystem.
  • Design and implement process automations to scale the TPRM program.
  • Lead AI governance framework for third‑party AI risks.
  • Own core governance, metrics, and risk dashboards for leadership.
  • Partner with security, procurement, privacy, and legal teams on risk assessments.
  • Oversee end‑to‑end remediation tracking for findings and exceptions.
  • Implement and refine the TPRM lifecycle with internal SMEs.

Skills

TPRM program ownership
Security strategy for BPO
Automation design
AI governance
Security dashboards
Cross-functional collaboration
Remediation tracking
Core TPRM lifecycle
Security audits & risk assessments
Cloud/SaaS risk assessments
APIs & cloud vendor risk
AI/ML risk analysis
NIST/ISO/SOC 2 frameworks
GRC program management
Vendor risk lifecycle
Effective communication
Security certifications (CISA/CISSP/C|

Education

Bachelor’s/master’s in Information Security or related field

Job description

About the Team

Come help us build the world's most trusted on‑demand logistics engine for delivery! We're building a team of great minds to help us secure and maintain a 24x7, no‑downtime, global infrastructure system that powers DoorDash’s multi‑sided marketplace of consumers, merchants, and drivers.

About the Role

The Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security‑focused Third‑Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast‑paced environment, taking ownership, and driving improvements in our security posture, we want to talk to you! You will report to the Manager, GRC within our Security organization.

You’re excited about this opportunity because you will…
  • Drive the continuous maturation of our TPRM program, transforming it from a reactive, compliance‑focused function into a proactive, strategic security partnership.
  • Architect and govern the security strategy for our BPO and contingent worker ecosystem, from developing and operationalizing continuous security standards to implementing & monitoring robust technical controls and ensuring strict compliance through rigorous due diligence and regular audit cycles.
  • Design and build process automations, optimizing and scaling the TPRM program to meet the business’s fast‑moving priorities.
  • Pioneer and lead the Supplier Security AI Governance framework, evaluating critical third‑party AI risks to ensure the secure implementation of AI tools across the business.
  • Establish and own core program governance and build a centralized reporting function, delivering actionable key metrics, risk dashboards, and progress updates to leadership for continuous visibility into third‑party risk exposure.
  • Partner cross‑functionally with security engineering, procurement, business, privacy, and legal teams to provide security advisory and lead risk assessments.
  • Lead the end‑to‑end issues and remediation tracking process, following up on all security findings and exceptions from assessments to ensure accountability and timely closure of remediation items.
  • Execute the core TPRM lifecycle (perform risk assessments, due diligence questionnaires, new vendor onboarding, contract and data protection agreement reviews) and partner with internal SMEs (Sourcing, Enterprise Security, IT) to refine internal policies and frameworks for scale.
We’re excited about you because you have…
  • 7+ years of progressive experience in security‑focused TPRM methodologies, including owning or successfully leading a TPRM program for a fast‑paced, high‑growth company.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or related field.
  • Experience with program building, conducting security and/or assurance audits, controls, and risk assessments, and remediation management.
  • Deep technical understanding and experience conducting comprehensive security risk and gap assessments of cloud, SaaS, including Artificial Intelligence (AI) solutions, and infrastructure vendors, and evaluating risks that impact data security and application resilience.
  • Proficiency in the technical review of core security assurance documentation. This encompasses, but is not limited to, CAIQ, SIG, SOC 2 Type 2 reports, Penetration Test reports, and compliance attestations (e.g., ISO 27001, PCI‑DSS, etc).
  • Experience in the technical vetting of complex vendor solutions. This involves scrutiny of API integrations with critical internal systems ('crown‑jewels'), security of cloud‑native services (AWS/Azure/GCP), and assessing agentic/generative AI platforms for vulnerabilities, data leakage, and system resilience.
  • Practical experience in assessing the unique risks associated with AI/ML models, including analysis of data provenance, identification of model poisoning risks, and ensuring the secure handling of proprietary data used for model training or fine‑tuning.
  • Experience with implementing major information security, privacy, and risk management frameworks (e.g. NIST, ISO, SOC 2).
  • Experience managing security and compliance programs across broad GRC disciplines within a complex, global public company environment.
  • Experience solving complex, systemic issues that require creative thinking and cross‑functional collaboration.
  • Experience managing vendor risk across the full relationship lifecycle, including periodic re‑assessments, amendments, scope changes, and continuous monitoring.
  • Excellent verbal and written communication skills with the ability to effectively translate technical risk findings into a clear business context for diverse audiences, including executive leadership.
  • CISA, CISSP, CISM, or other industry certifications are a plus.

We expect this position to be filled by 9/13/26.

Compensation

The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job‑related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market‑dependent and may be modified in the future.

In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.

DoorDash cares about you and your overall well‑being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family‑forming assistance, and a mental health program, among others.

To learn more about our benefits, visit our careers page here.

Paid Time Off Details
  • For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
  • For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).

The national base pay range for this position within the United States, including Illinois and Colorado.

$132,600 — $195,000 USD

Statement of Non‑Discrimination

In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non‑binary or gender non‑conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently‑abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non‑discrimination.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Third-Party Risk Management (TPRM)
Senior Analyst, Third-Party Risk Management (TPRM)

DoorDash USA • United States

Hybrid
USD 132,000 - 195,000
401(k) plan
Parental leave (16 weeks)
Wellness benefits
+4
Senior Security Data Engineer
Senior Security Data Engineer

DoorDash USA • San Francisco (CA)

On-site
USD 160,000 - 235,000
401(k) with matching
Paid parental leave
Wellness benefits
+3
Senior Associate, Customer Experience - Safety
Senior Associate, Customer Experience - Safety

DoorDash • Los Angeles (CA)

On-site
USD 75,000 - 110,000
Equity grants
401(k) plan with employer matching
Paid parental leave
+1
Enterprise Security Engineer
Enterprise Security Engineer

DoorDash • United States

On-site
USD 130,000 - 192,000
401(k) plan with employer matching
16 weeks of paid parental leave
Medical, dental, and vision benefits
+1
Senior Manager, Customer Experience
Senior Manager, Customer Experience

DoorDash • Seattle (WA)

On-site
USD 143,000 - 211,000
401(k) plan with employer matching
16 weeks of paid parental leave
Wellness benefits
+2
Supervisor, Community Response
Supervisor, Community Response

DoorDash • Tempe (AZ)

On-site
USD 83,000 - 122,000
401(k) plan with employer matching
16 weeks paid parental leave
Wellness benefits
+2
Senior Manager, Customer Experience
Senior Manager, Customer Experience

DoorDash • Chicago (IL)

On-site
USD 143,000 - 211,000
401(k) plan with employer matching
16 weeks of paid parental leave
Comprehensive medical, dental, and vision benefits
Senior/Staff Deep Reinforcement Learning Engineer - DoorDash Dot
Senior/Staff Deep Reinforcement Learning Engineer - DoorDash Dot

DoorDash • California (MO)

On-site
USD 168,000 - 247,000
401(k) matching
Parental leave (16 weeks)
Wellness benefits
+6
Senior Systems Engineer - DoorDash Air
Senior Systems Engineer - DoorDash Air

DoorDash • California (MO)

On-site
USD 131,000 - 285,000
401(k) matching
Parental leave (16 weeks)
Wellness benefits
+7
Senior Associate, Sales Strategy & Operations, Commercial Operations
Senior Associate, Sales Strategy & Operations, Commercial Operations

DoorDash • New York (NY)

On-site
USD 88,000 - 130,000
401(k) plan with employer matching
Paid parental leave
Wellness benefits
+2