FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Manager, Third-Party Risk Management – TPRM
DoorDash. Run day-to-day TPRM operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation, and exit .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in managing third-party risk management (TPRM) operations, including vendor assessments, risk tiering, and compliance with security frameworks. Proficient in leveraging AI-native approaches and automation to enhance risk practices and streamline workflows.
Highest-signal resume keywords
Third-Party Risk Management (TPRM)Vendor Assessment LeadershipSecurity Frameworks ApplicationAI-Native Workflow ImplementationGRC Coordination
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Technical Third-Party Risk ManagementVendor Discovery and Risk TieringSAML/OIDC FederationOAuth Scopes and TokensCloud IAMSOC 2 Type II EvaluationPenetration Test InterpretationAPIs and Integration PatternsData ProtectionIncident Response
Soft Skills
Stakeholder CommunicationTeam LeadershipCross-Functional CoordinationProblem SolvingCoaching and Mentoring
Tools & Technologies
TPRM PlatformsGRC ToolsAI-Assisted WorkflowsCloud Security SolutionsWorkflow Automation Tools
Certifications & Qualifications
ISO 27001PCI DSS
Industry Keywords
Risk ManagementSecurity EngineeringData FlowsControl EvidenceMitigation Plans
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Run day-to-day TPRM operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation, and exit
- Maintain vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo
- Lead assessments of vendors connected to critical systems, including identity platforms, production cloud, source code and CI/CD, and sensitive-data platforms
- Examine architecture, data flows, permissions, and control evidence
- Use threat modeling to identify compromise paths and define requirements for access, isolation, secrets, encryption, logging, and revocation
- Agree mitigation plans and security contract terms with vendors, Legal, Privacy, Procurement, and system owners
- Verify remediation and document residual risk acceptance, access removal, and data handling at termination
- Address supplier dependencies, concentration risk, recovery capabilities, and exit readiness
- Set the vision and roadmap for an AI-native TPRM function
- Build and pilot agentic workflows for evidence gathering, control-gap identification, assessment drafting, and follow-up coordination
- Evaluate what to configure, buy, or build, partnering with Security Engineering, IT, and platform owners
- Own the TPRM framework for third-party AI and agentic services
- Hire, coach, and directly manage TPRM professionals and US-based GRC direct reports
- Provide US-hours GRC coverage and escalation support for the Global Head of GRC
- Lead stakeholder discussions and coordinate GRC input to incidents, audits, and urgent business decisions
- Report critical-system exposure, overdue remediation, exception aging, assessment quality, and review turnaround to leadership and auditors
- Measure AI and automation improvements and translate material risks into business impact
Requirements
What you’ll need- 6+ years of progressive experience in technical third-party risk, security risk, or security engineering
- Substantial hands-on experience leading complex vendor assessments and owning a TPRM program
- Track record of improving risk practices in a technology environment
- Experience leading distributed teams and coordinating delivery across different GRC specialties
- Experience assessing enterprise integrations and failure modes
- Knowledge of SAML/OIDC federation, OAuth scopes and tokens, SCIM provisioning, APIs, service accounts, cloud IAM, network boundaries, and data flows
- Strong assurance and control-testing skills
- Ability to evaluate SOC 2 Type II scope, exceptions, subservice organizations, and customer responsibilities
- Ability to interpret penetration tests and ISO 27001 or PCI DSS evidence
- AI-native working approach, including use of AI-assisted workflows
- Experience implementing or improving TPRM/GRC platforms and workflow automation
- Practical knowledge of APIs and integration patterns
- Ability to define requirements, work with structured data, and partner with engineers
- Hands-on knowledge of cloud and SaaS security, privileged supplier or BPO access, data protection, incident response, and recovery
- Ability to apply security frameworks and threat modeling to vendor deployments
- Knowledge of AI-specific risks including data use, tool permissions, and prompt injection
- Experience representing a security or GRC leader and making decisions within delegated authority
- Ability to communicate with engineers, Legal, Procurement, and business leaders
- United States-based, preferably within Eastern or Central timezones
- Core working hours aligned to US business needs
Benefits
Comp & perks- Equity grants
- 401(k) plan with employer matching
- 16 weeks of paid parental leave
- Wellness benefits
- Commuter benefits match
- Paid time off
- Paid sick leave
- Medical, dental, and vision benefits
- 11 paid holidays
- Disability insurance
- Basic life insurance
- Family-forming assistance
- Mental health program
- Flexible paid time off/vacation for salaried roles
- 80 hours of paid sick time per year for salaried roles
- Premium healthcare
- Wellness expense reimbursement