Jobs / United States / Doordash INC
Manager, Third-Party Risk Management (TPRM)
Doordash INC · 🇺🇸 United States- Remote · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 396 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 147 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Doordash INC paid sponsored hires in similar roles10 certified filings for “Manager, New Verticals” (Management Analysts) in NY: $102k–$160k, median $140k. Most were filed at wage level II (50%) — 2 lottery entries, ≈31% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Doordash INC
The US Department of Labor certified 396 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 147 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Doordash INC →
About the role
About the Team DoorDash’s Global Governance, Risk and Compliance (GRC) team helps the business scale securely through practical risk-based decisions, reliable controls and clear accountability. Our third-party risk program protects the systems and data behind our marketplace across DoorDash, Wolt, and Deliveroo. About the Role We’re looking for a Third-Party Risk Management (TPRM) Manager to lead a technically rigorous global program and shape its AI-native future. You will own the vendor security risk lifecycle, lead complex assessments of integrations with our most critical systems and data, and develop a team that makes clear, evidence-based risk decisions. You will also set the vision and build practical agentic workflows that improve how we gather evidence, assess risk, and follow through on remediation. Reporting to the Global Head of GRC, you will serve as their US-based deputy and provide GRC leadership and escalation coverage during US business hours. You will directly manage TPRM analysts together with other US-based GRC team members assigned to your organization. This role combines hands-on technical judgment, program ownership and people leadership. You will be based in the United States, preferably within the Eastern or Central timezones, with core working hours aligned to US business needs and clear handoffs with global colleagues. What you will do • Run the day-to-day TPRM program operations from vendor discovery and risk tiering through due diligence, onboarding, continuous monitoring, remediation and exit. Maintain a reliable vendor inventory, policies, assessment standards, and service levels across DoorDash, Wolt, and Deliveroo, covering cloud, SaaS, business process outsourcing (BPO), and other critical suppliers. • Lead assessments of vendors connected to crown jewel systems, including identity platforms, production cloud, source code and CI/CD, and sensitive-data platforms. Examine architecture, data flows, permissions, and control evidence. Use structured threat modeling to identify realistic compromise paths and define testable requirements for access, isolation, secrets, encryption, logging and revocation. • Turn findings into accountable risk decisions. Agree mitigation plans and security contract terms with vendors, Legal, Privacy, Procurement, and system owners. Verify remediation, document residual risk acceptance with accountable business owners and review dates, and confirm access removal and data handling at termination. Address critical supplier dependencies, concentration risk, recovery capabilities, and exit readiness. • Set the vision for an AI-native TPRM function. Build a prioritized roadmap for applying AI and automation across the vendor lifecycle, with clear outcomes, dependencies, and ownership. Evaluate what to configure, buy, or build, and align delivery with Security Engineering, IT, and platform owners. • Build and pilot agentic workflows with the team to gather and reconcile evidence, identify control gaps, draft assessments, and coordinate follow-up. Scale the use cases that demonstrate better quality, coverage or turnaround. Use approved tools, APIs, and engineering partnerships, with evidence traceability, evaluations, data protection, appropriate access controls and human approval for consequential actions. • Own the TPRM framework for third-party AI and agentic services. Assess model and data providers, connectors, tool permissions, training-data use, retention, subprocessors, prompt injection, and data exfiltration. Set onboarding and monitoring requirements that respond to material changes in models, integrations, and vendor practices. • Hire, coach, and directly manage TPRM professionals and other US-based GRC direct reports. Own goals, workload, performance revie