Senior Analyst, Third-Party Risk Management (TPRM)

DoorDash USA

United States

Hybrid

USD 132,600 - 195,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan
Parental leave (16 weeks)
Wellness benefits
Commuter benefits
Paid time off
Paid sick leave
Medical/dental/vision benefits

Job summary

DoorDash is seeking a Senior Analyst in Third-Party Risk Management (TPRM) to lead strategic risk programs across the U.S. and remote workforce.

You will drive maturation of the TPRM program, architect security strategies for the vendor ecosystem, and implement scalable automation to meet rapid business needs. This role demands deep expertise in security risk assessments, cloud/SaaS environments, AI risk, and cross-functional collaboration with security, procurement, legal, and privacy teams.

Qualifications

  • 7+ years in security-focused TPRM for fast-growing companies.
  • Bachelor’s or Master’s in Information Security, CS, or related field.
  • Experience with audits, controls, risk assessments, and remediation management.
  • Deep technical understanding of cloud/SaaS risks including AI solutions and infra vendors.
  • Proficiency in reviewing security docs (CAIQ, SIG, SOC 2 Type 2, pen tests).
  • Experience vetting complex vendor solutions, API integrations, cloud-native services, and AI platforms.
  • Experience with frameworks (NIST, ISO, SOC 2) and cross-functional GRC programs.

Responsibilities

  • Mature the TPRM program from reactive to proactive security partner.
  • Architect security strategy for BPO/contingent worker ecosystem; implement robust controls.
  • Design and build process automations to scale the TPRM program.
  • Lead the Supplier Security AI Governance framework and assess AI risks.
  • Establish core governance and centralized risk reporting for leadership.
  • Partner with security, procurement, privacy, and legal to advise on risk.
  • Own end-to-end remediation tracking and closure of findings.
  • Execute core TPRM lifecycle and refine policies for scale.

Skills

TPRM program
Security risk assessments
Cloud risk
AI/ML risk
Vendor risk management
Audit & due diligence
Executive communication

Education

Bachelor's or Master’s in Information Security / CS

Tools

AWS
Azure
GCP

Job description

Senior Analyst, Third-Party Risk Management (TPRM)

Milwaukee WI; Chicago, IL; New York, NY; San Francisco, CA; Phoenix, AZ; Austin, TX; United States - Remote

About the Team

Come help us build the world’s most trusted on‑demand logistics engine for delivery! We’re building a team of great minds to help us secure and maintain a 24x7, no‑downtime, global infrastructure system that powers DoorDash’s multi‑sided marketplace of consumers, merchants, and drivers.

About the Role

The Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security‑focused Third‑Party Risk Management (TPRM) Senior Analyst. If you are comfortable and have experience working in a fast‑paced environment, taking ownership, and driving improvements in our security posture, we want to talk to you! You will report to the Manager, GRC within our Security organization.

You’re excited about this opportunity because you will…
  • Drive the continuous maturation of our TPRM program, transforming it from a reactive, compliance‑focused function into a proactive, strategic security partnership.
  • Architect and govern the security strategy for our BPO and contingent worker ecosystem, from developing and operationalizing continuous security standards to implementing & monitoring robust technical controls and ensuring strict compliance through rigorous due diligence and regular audit cycles.
  • Design and build process automations, optimizing and scaling the TPRM program to meet the business’s fast‑moving priorities.
  • Pioneer and lead the Supplier Security AI Governance framework, evaluating critical third‑party AI risks to ensure the secure implementation of AI tools across the business.
  • Establish and own core program governance and build a centralized reporting function, delivering actionable key metrics, risk dashboards, and progress updates to leadership for continuous visibility into third‑party risk exposure.
  • Partner cross‑functionally with security engineering, procurement, business, privacy, and legal teams to provide security advisory and lead risk assessments.
  • Lead the end‑to‑end issues and remediation tracking process, following up on all security findings and exceptions from assessments to ensure accountability and timely closure of remediation items.
  • Execute the core TPRM lifecycle (perform risk assessments, due diligence questionnaires, new vendor onboarding, contract and data protection agreement reviews) and partner with internal SMEs (Sourcing, Enterprise Security, IT) to refine internal policies and frameworks for scale.
We’re excited about you because you have…
  • 7+ years of progressive experience in security‑focused TPRM methodologies, including owning or successfully leading a TPRM program for a fast‑paced, high‑growth company.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or related field.
  • Experience with program building, conducting security and/or assurance audits, controls, and risk assessments, and remediation management.
  • Deep technical understanding and experience conducting comprehensive security risk and gap assessments of cloud, SaaS, including Artificial Intelligence (AI) solutions, and infrastructure vendors, and evaluating risks that impact data security and application resilience.
  • Proficiency in the technical review of core security assurance documentation. This includes, but is not limited to, CAIQ, SIG, SOC 2 Type 2 reports, penetration test reports, and compliance attestations (e.g., ISO 27001, PCI‑DSS).
  • Experience in the technical vetting of complex vendor solutions, scrutiny of API integrations with critical internal systems, security of cloud‑native services (AWS/Azure/GCP), and assessing agentic/generative AI platforms for vulnerabilities, data leakage, and system resilience.
  • Practical experience assessing the unique risks associated with AI/ML models, including analysis of data provenance, identification of model poisoning risks, and ensuring secure handling of proprietary data used for model training or fine‑tuning.
  • Experience with implementing major information security, privacy, and risk management frameworks (e.g., NIST, ISO, SOC 2).
  • Experience managing security and compliance programs across broad GRC disciplines within a complex, global public company environment.
  • Experience solving complex, systemic issues that require creative thinking and cross‑functional collaboration.
  • Experience managing vendor risk across the full relationship lifecycle, including periodic re‑assessments, amendments, scope changes, and continuous monitoring.
  • Excellent verbal and written communication skills with the ability to effectively translate technical risk findings into a clear business context for diverse audiences, including executive leadership.
  • CISA, CISSP, CISM, or other industry certifications are a plus.
Compensation

The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job‑related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market‑dependent and may be modified in the future.

In addition to base salary, the compensation for this role includes opportunities for equity grants.

Benefits

DoorDash cares about you and your overall well‑being. We offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g., Colorado Healthy Families and Workplaces Act). Medical, dental, and vision benefits; 11 paid holidays; disability and basic life insurance; family‑forming assistance; and a mental health program are also available.

For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year. For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked; paid sick time accrued at 1 hour for every 30 hours worked.

National Base Pay Range (United States)

$132,600 - $195,000 USD

About DoorDash

At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and iterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door‑to‑door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods.

Our Commitment to Diversity and Inclusion

We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. We hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives.

Statement of Non‑Discrimination

No employee or applicant will face discrimination or harassment based on race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. We also strive to prevent other subtle forms of inappropriate behavior.

Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

If you need any accommodations, please inform your recruiting contact after initial connection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Third-Party Risk Management (TPRM)
Senior Analyst, Third-Party Risk Management (TPRM)

DoorDash • New York (NY)

On-site
USD 132,000 - 195,000
Agent, Critical Incident Response Team - Chicago, IL
Agent, Critical Incident Response Team - Chicago, IL

DoorDash High Volume • Chicago (IL)

On-site
USD 38,000 - 56,000
401(k) plan with employer matching
Paid parental leave
Wellness benefits
+1
Senior Director, Internal Audit
Senior Director, Internal Audit

DoorDash • Los Angeles (CA)

On-site
USD 249,000 - 312,000
Senior Director, Internal Audit
Senior Director, Internal Audit

DoorDash • Seattle (WA)

On-site
USD 249,000 - 312,000
Equity grants
Premium healthcare
Senior Associate, Strategy & Operations, Regulatory Readiness
Senior Associate, Strategy & Operations, Regulatory Readiness

DoorDash • New York (NY)

On-site
USD 87,000 - 128,000
401(k) matching
Paid parental leave
Medical, dental, vision coverage
+6
Senior Analyst, Protective Services
Senior Analyst, Protective Services

DoorDash, Inc. • Northern (KY)

Hybrid
USD 81,000 - 135,000
401(k) match
Paid parental leave
Wellness benefits
+1
Senior Associate, Customer Experience - Safety
Senior Associate, Customer Experience - Safety

DoorDash • Los Angeles (CA)

On-site
USD 75,000 - 110,000
Equity grants
401(k) plan with employer matching
Paid parental leave
+1
Sr. Staff Technical Program Manager (Hardware) - Dot
Sr. Staff Technical Program Manager (Hardware) - Dot

DoorDash High Volume • Town of Oakland (WI)

On-site
USD 194,000 - 285,000
401(k) matching
Parental leave (16 weeks)
Wellness benefits
+3
Head of Safety, Robot Operations
Head of Safety, Robot Operations

DoorDash USA • San Francisco (CA)

On-site
USD 155,000 - 230,000
401(k) with employer matching
Paid parental leave
Health, dental, and vision benefits
+4
Senior Associate, Project Management, Asset Protection and Safety
Senior Associate, Project Management, Asset Protection and Safety

DoorDash • Austin (TX)

Hybrid
USD 82,000 - 121,000
401(k) plan with employer matching
Paid parental leave
Wellness benefits