Manager, Third-Party Risk Management – TPRM

Job not on LinkedIn

🔥 49 minutes ago

🇺🇸 United States – Remote

💵 $164.2k - $241.5k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔒 Insurance

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of DoorDash

DoorDash

10,000+ employees

🍽️ Food & Beverage

📦 Logistics

🛍️ eCommerce

Food & Beverage • Logistics • eCommerce

DoorDash is a leading food delivery service that connects customers with local businesses and restaurants. By empowering local economies, DoorDash facilitates the growth and success of restaurants and retailers, offering a flexible work environment for its employees. The company emphasizes innovation and aims to redefine the local commerce experience while providing extensive benefits and opportunities for team members across various career areas.

📋 Description

• Run day-to-day TPRM operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation, and exit • Maintain vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo • Lead assessments of vendors connected to critical systems, including identity platforms, production cloud, source code and CI/CD, and sensitive-data platforms • Examine architecture, data flows, permissions, and control evidence • Use threat modeling to identify compromise paths and define requirements for access, isolation, secrets, encryption, logging, and revocation • Agree mitigation plans and security contract terms with vendors, Legal, Privacy, Procurement, and system owners • Verify remediation and document residual risk acceptance, access removal, and data handling at termination • Address supplier dependencies, concentration risk, recovery capabilities, and exit readiness • Set the vision and roadmap for an AI-native TPRM function • Build and pilot agentic workflows for evidence gathering, control-gap identification, assessment drafting, and follow-up coordination • Evaluate what to configure, buy, or build, partnering with Security Engineering, IT, and platform owners • Own the TPRM framework for third-party AI and agentic services • Hire, coach, and directly manage TPRM professionals and US-based GRC direct reports • Provide US-hours GRC coverage and escalation support for the Global Head of GRC • Lead stakeholder discussions and coordinate GRC input to incidents, audits, and urgent business decisions • Report critical-system exposure, overdue remediation, exception aging, assessment quality, and review turnaround to leadership and auditors • Measure AI and automation improvements and translate material risks into business impact

🎯 Requirements

• 6+ years of progressive experience in technical third-party risk, security risk, or security engineering • Substantial hands-on experience leading complex vendor assessments and owning a TPRM program • Track record of improving risk practices in a technology environment • Experience leading distributed teams and coordinating delivery across different GRC specialties • Experience assessing enterprise integrations and failure modes • Knowledge of SAML/OIDC federation, OAuth scopes and tokens, SCIM provisioning, APIs, service accounts, cloud IAM, network boundaries, and data flows • Strong assurance and control-testing skills • Ability to evaluate SOC 2 Type II scope, exceptions, subservice organizations, and customer responsibilities • Ability to interpret penetration tests and ISO 27001 or PCI DSS evidence • AI-native working approach, including use of AI-assisted workflows • Experience implementing or improving TPRM/GRC platforms and workflow automation • Practical knowledge of APIs and integration patterns • Ability to define requirements, work with structured data, and partner with engineers • Hands-on knowledge of cloud and SaaS security, privileged supplier or BPO access, data protection, incident response, and recovery • Ability to apply security frameworks and threat modeling to vendor deployments • Knowledge of AI-specific risks including data use, tool permissions, and prompt injection • Experience representing a security or GRC leader and making decisions within delegated authority • Ability to communicate with engineers, Legal, Procurement, and business leaders • United States-based, preferably within Eastern or Central timezones • Core working hours aligned to US business needs

🏖️ Benefits

• Equity grants • 401(k) plan with employer matching • 16 weeks of paid parental leave • Wellness benefits • Commuter benefits match • Paid time off • Paid sick leave • Medical, dental, and vision benefits • 11 paid holidays • Disability insurance • Basic life insurance • Family-forming assistance • Mental health program • Flexible paid time off/vacation for salaried roles • 80 hours of paid sick time per year for salaried roles • Premium healthcare • Wellness expense reimbursement

Apply Now

Similar Jobs

🔥 1 hour ago

AAA

5001 - 10000

🚘 Automotive

🛡️ Insurance

📦 Logistics

Capital modeling lead building stochastic economic capital models for CSAA Insurance Group, a AAA personal-lines P&C insurer. Supporting risk-based capital allocation and strategic business decisions.

🔥 3 hours ago

Quadax, Inc.

501 - 1000

🏥 Healthcare

☁️ SaaS

🤖 Artificial Intelligence

Insurance Specialist processing medical insurance claims for Quadax Inc. Verifying coverage, resolving rejections, correcting claims, and monitoring payer issues.

🔥 3 hours ago

MarineMax

1001 - 5000

✈️ Travel

🍽️ Food & Beverage

📦 Logistics

Boat Insurance Advisor developing marine insurance business for Newcoast and MarineMax customers. Managing prospects, quotes, CRM pipelines, and relationships with sales teams and carriers.

🇺🇸 United States – Remote

💰 $950M Post-IPO Debt - MarineMax on 2023-07

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔒 Insurance

🔥 4 hours ago

TD

10,000+ employees

🏦 Banking

💸 Finance

🛡️ Insurance

Risk Manager optimizing credit risk segmentation and policies for TD, a global financial institution. Analyzing data and advising Senior Management on credit strategies.

🔥 4 hours ago

The Delaney Agency

201 - 500

💼 Consulting

👥 B2C

🛡️ Insurance

Remote life insurance sales representative serving families seeking coverage. Working warm leads, supporting underwriting, and earning commission-based income.