×
Register Here to Apply for Jobs or Post Jobs. X

Senior Analyst, Third-Party Risk Management; TPRM

Job in Milwaukee, Milwaukee County, Wisconsin, 53244, USA
Listing for: Doordashusa
Full Time position
Listed on 2026-07-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Senior Analyst, Third-Party Risk Management (TPRM)

About the Team

Come help us build the world's most trusted on-demand logistics engine for delivery! We're building a team of great minds to help us secure and maintain a 24x7, no-downtime, global infrastructure system that powers Door Dash’s multi-sided marketplace of consumers, merchants, and drivers.

About the Role

The Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced environment, taking ownership, and driving improvements in our security posture, we want to talk to you! You will report to the Manager, GRC within our Security organization.

You’re excited about this opportunity because you will…
  • Drive the continuous maturation of our TPRM program
    , transforming it from a reactive, compliance-focused function into a proactive, strategic security partnership.
  • Architect and govern the security strategy for our BPO and contingent worker ecosystem
    , from developing and operationalizing continuous security standards to implementing & monitoring robust technical controls and ensuring strict compliance through rigorous due diligence and regular audit cycles.
  • Design and build process automations, optimizing and scaling the TPRM program to meet the business’s fast-moving priorities.
  • Pioneer and lead the Supplier Security AI Governance framework
    , evaluating critical third-party AI risks to ensure the secure implementation of AI tools across the business.
  • Establish and own core program governance and build a centralized reporting function
    , delivering actionable key metrics, risk dashboards, and progress updates to leadership for continuous visibility into third-party risk exposure.
  • Partner cross-functionally with security engineering, procurement, business, privacy, and legal teams to provide security advisory and lead risk assessments.
  • Lead the end-to-end issues and remediation tracking process
    , following up on all security findings and exceptions from assessments to ensure accountability and timely closure of remediation items.
  • Execute the core TPRM lifecycle (perform risk assessments, due diligence questionnaires, new vendor onboarding, contract and data protection agreement reviews) and partner with internal SMEs (Sourcing, Enterprise Security, IT) to refine internal policies and frameworks for scale.
We’re excited about you because you have…
  • 7+ years of progressive experience in security-focused TPRM methodologies, including owning or successfully leading a TPRM program for a fast-paced, high-growth company.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or related field.
  • Experience with program building, conducting security and/or assurance audits, controls, and risk assessments, and remediation management.
  • Deep technical understanding and experience conducting comprehensive security risk and gap assessments of cloud, SaaS, including Artificial Intelligence (AI) solutions, and infrastructure vendors, and evaluating risks that impact data security and application resilience.
  • Proficiency in the technical review of core security assurance documentation. This encompasses, but is not limited to, CAIQ, SIG, SOC 2 Type 2 reports, Penetration Test reports, and compliance attestations (e.g., ISO 27001, PCI-DSS, etc).
  • Experience in the technical vetting of complex vendor solutions. This involves scrutiny of API integrations with critical internal systems ('crown-jewels'), security of cloud-native services (AWS/Azure/GCP), and assessing agentic/generative AI platforms for vulnerabilities, data leakage, and system resilience.
  • Practical experience in assessing the unique risks associated with AI/ML models, including analysis of data provenance, identification of model poisoning risks, and ensuring the secure handling of proprietary data used for model training or fine-tuning.
  • Experience with implementing major information security, privacy, and risk management frameworks (e.g. NIST, ISO, SOC
    2).
  • Experience managing security and compliance programs across broad GRC disciplines within a complex, global public company…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary