CronJobs

security jobs

Manager, Third-Party Risk Management (TPRM)

DoorDash USA · United States- Remote

remoteunknown$164,200–$164,200Posted Oct 8, 2026PythonSQLSAMLOIDCOAuthSCIMCI/CD

Apply on the employer site

About this role

## About the Team DoorDash’s Global Governance, Risk and Compliance (GRC) team helps the business scale securely through practical risk-based decisions, reliable controls, and clear accountability. Our third-party risk program protects the systems and data behind our marketplace across DoorDash, Wolt, and Deliveroo. ## About the Role We’re looking for a **Third-Party Risk Management (TPRM) Manager** to lead a technically rigorous global program and shape its **AI-native** future. You’ll own the vendor security risk lifecycle, lead complex assessments of integrations with our most critical systems and data, and develop a team that makes clear, evidence-based risk decisions. You’ll also set the vision and build practical **agentic workflows** to improve how we gather evidence, assess risk, and follow through on remediation. Reporting to the **Global Head of GRC**, you’ll serve as their **US-based deputy** and provide GRC leadership and escalation coverage during US business hours. You’ll directly manage TPRM analysts and other US-based GRC team members assigned to your organization. **Location:** United States (preferably Eastern or Central timezones). ## What You Will Do - Run day-to-day TPRM program operations from **vendor discovery and risk tiering** through **due diligence, onboarding, continuous monitoring, remediation, and exit**. Maintain vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo (including cloud, SaaS, BPO, and other critical suppliers). - Lead assessments of vendors connected to **crown jewel systems** (identity platforms, production cloud, source code/CI/CD, sensitive-data platforms). Review architecture, data flows, permissions, and control evidence. Use structured threat modeling to identify realistic compromise paths and define testable requirements for access, isolation, secrets, encryption, logging, and revocation. - Turn findings into accountable risk decisions. Align mitigation plans and security contract terms with vendors and partners (Legal, Privacy, Procurement, system owners). Verify remediation, document residual risk acceptance with accountable business owners, and confirm access removal and data handling at termination. Address concentration risk, recovery capabilities, and exit readiness. - Set the vision for an **AI-native TPRM** function. Build a prioritized roadmap for applying AI/automation across the vendor lifecycle with clear outcomes, dependencies, and ownership. - Build and pilot **agentic workflows** to gather and reconcile evidence, identify control gaps, draft assessments, and coordinate follow-up. Scale use cases that improve quality, coverage, or turnaround—using approved tools/APIs with evidence traceability, evaluations, data protection, appropriate access controls, and human approval for consequential actions. - Own the TPRM framework for **third-party AI and agentic services**. Assess model/data providers, connectors, tool permissions, training-data use, retention, subprocessors, prompt injection, and data exfiltration. Set onboarding and monitoring requirements for material changes in models, integrations, and vendor practices. - Hire, coach, and directly manage TPRM professionals and other US-based GRC direct reports. Own goals, workload, performance reviews, career development, and succession planning. Improve technical assessment and automation skills across GRC disciplines. - Provide US-hours GRC coverage and escalation s

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord