Back to Remote jobs   >   All Others   >   risk manager
Manager, Third-Party Risk Management @DoorDash USA
All Others
Salary usd 164,200 - 2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay

[Hiring] Manager, Third-Party Risk Management @DoorDash USA

YDay - DoorDash USA is hiring a remote Manager, Third-Party Risk Management. 💸 Salary: usd 164,200 - 241,500 per year 📍Location: USA

Role Description

We’re looking for a Third-Party Risk Management (TPRM) Manager to lead a technically rigorous global program and shape its AI-native future. You will own the vendor security risk lifecycle, lead complex assessments of integrations with our most critical systems and data, and develop a team that makes clear, evidence-based risk decisions. You will also set the vision and build practical agentic workflows that improve how we gather evidence, assess risk, and follow through on remediation.

Reporting to the Global Head of GRC, you will serve as their US-based deputy and provide GRC leadership and escalation coverage during US business hours. You will directly manage TPRM analysts together with other US-based GRC team members assigned to your organization.

This role combines hands-on technical judgment, program ownership and people leadership. You will be based in the United States, preferably within the Eastern or Central timezones, with core working hours aligned to US business needs and clear handoffs with global colleagues.

What you will do

  • Run the day-to-day TPRM program operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation and exit.
  • Maintain a reliable vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo, covering cloud, SaaS, business process outsourcing (BPO), and other critical suppliers.
  • Lead assessments of vendors connected to crown jewel systems, including identity platforms, production cloud, source code and CI/CD, and sensitive-data platforms.
  • Examine architecture, data flows, permissions, and control evidence.
  • Use structured threat modeling to identify realistic compromise paths and define testable requirements for access, isolation, secrets, encryption, logging and revocation.
  • Turn findings into accountable risk decisions.
  • Agree mitigation plans and security contract terms with vendors, Legal, Privacy, Procurement, and system owners.
  • Verify remediation, document residual risk acceptance with accountable business owners and review dates, and confirm access removal and data handling at termination.
  • Address critical supplier dependencies, concentration risk, recovery capabilities, and exit readiness.
  • Set the vision for an AI-native TPRM function.
  • Build a prioritized roadmap for applying AI and automation across the vendor lifecycle, with clear outcomes, dependencies, and ownership.
  • Evaluate what to configure, buy, or build, and align delivery with Security Engineering, IT, and platform owners.
  • Build and pilot agentic workflows with the team to gather and reconcile evidence, identify control gaps, draft assessments, and coordinate follow-up.
  • Scale the use cases that demonstrate better quality, coverage or turnaround.
  • Use approved tools, APIs, and engineering partnerships, with evidence traceability, evaluations, data protection, appropriate access controls and human approval for consequential actions.
  • Own the TPRM framework for third-party AI and agentic services.
  • Assess model and data providers, connectors, tool permissions, training-data use, retention, subprocessors, prompt injection, and data exfiltration.
  • Set onboarding and monitoring requirements that respond to material changes in models, integrations, and vendor practices.
  • Hire, coach, and directly manage TPRM professionals and other US-based GRC direct reports.
  • Own goals, workload, performance reviews, career development, and succession planning.
  • Raise the team’s technical assessment and automation skills, working with functional leads to align priorities across GRC disciplines.
  • Provide US-hours GRC coverage and escalation support in partnership with the Global Head of GRC.
  • Lead stakeholder discussions, resolve operational escalations, and coordinate GRC input to vendor incidents, audits, and urgent business decisions.
  • Exercise agreed delegated authority, route risk acceptance to accountable owners, and maintain clear decisions and handoffs with global leadership.
  • Make risk and program performance visible to leadership and auditors.
  • Report critical-system exposure, overdue remediation, exception aging, assessment quality, and review turnaround.
  • Measure how AI and automation improve coverage or reduce effort, and translate material risks into business impact to guide priorities and investment.

Qualifications

  • 6+ years of progressive experience in technical third-party risk, security risk, or security engineering, including substantial hands-on experience leading complex vendor assessments and ownership of a TPRM program.
  • A track record of improving risk practices in a technology environment.
  • Experience leading distributed teams and coordinating delivery across different GRC specialties.
  • Deep experience assessing enterprise integrations and their failure modes.
  • Strong assurance and control-testing skills.
  • An AI-native working approach.
  • Experience implementing or improving TPRM/GRC platforms and workflow automation.
  • Hands-on knowledge of cloud and SaaS security, privileged supplier or BPO access, data protection, incident response, and recovery.
  • Sound judgment and executive communication.

Compensation

The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future.

In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.

Benefits

  • Comprehensive benefits package to all regular employees.
  • 401(k) plan with employer matching.
  • 16 weeks of paid parental leave.
  • Wellness benefits.
  • Commuter benefits match.
  • Paid time off and paid sick leave in compliance with applicable laws.
  • Medical, dental, and vision benefits.
  • 11 paid holidays.
  • Disability and basic life insurance.
  • Family-forming assistance.
  • Mental health program.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   All Others   >   risk manager
Manager, Third-Party Risk Management @DoorDash USA
All Others
Salary usd 164,200 - 2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 131,007+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later