Internal Audit Security Senior Manager

DoorDash
San Francisco, CA; Sunnyvale, CA; Seattle, WA; Los Angeles, CA; New York, NYPosted 23 February 2026

Job Description

<div class="content-intro"><p><img style="display: none; max-width: 100%;" src="https://click.appcast.io/greenhouse-te8/a31.png?ent=34e=22630t=1701374353806" width="1px"> <img style="display: none; max-width: 100%;" src="https://track.jobadx.com/v1/i.gif?utm_pixel=224e990b-8ff4-4287-8d5d-2ff09647f181utm_ptz=ESTutm_rqt=track" alt="" width="1"></p></div><h1><strong>About the Team</strong></h1><p>At DoorDash, the Internal Audit team aims to provide independent assurance that DoorDash’s risk management, governance and internal control processes are operating effectively. We are a small team that is looking to expand and bring on motivated professionals in this field. We don’t think of ourselves as a typical audit function - we are obsessively focused on risks to the organizations which reflects in the type of projects we support and execute. </p><p>DoorDash is rapidly growing - we are expanding in multiple geos and launching new products. This exciting growth allows us to drive creative analysis, strategy, and solutions. Our focus areas include financial, operational, regulatory, security, IT, and more.</p><h1><strong>About the Role</strong></h1><p>This is an exciting opportunity to establish and lead the inaugural Security function within our Internal Audit department. As the Internal Audit Security Lead/Manager, you will be instrumental in defining and executing our security risk assessment strategy, serving as a strategic partner to our Global Security and Privacy teams, and leading end-to-end security assessments. This role demands a proactive and strategic thinker with a strong foundation in cybersecurity and a passion for building a robust security audit program.</p><p>You will report to the Director of IT Internal Audit in our Internal Audit organization.</p><p>This role will have a flexible hybrid schedule and will be based near the U.S. West Coast or East Coast office hub (in San Francisco Bay Area, Seattle, Los Angeles or New York).</p><h1><strong>You’re excited about this opportunity because you will…</strong></h1><ul><li>Stand up the first-ever Security function within Internal Audit, developing foundational processes and methodologies.</li><li>Play a key role in defining Internal Audit’s roadmap for managing and assessing security-related risks, aligning with organizational priorities and industry best practices.</li><li>Act as a strategic partner to Global Security and Privacy teams, collaborating on the definition and development of roadmaps and remediation processes.</li><li>Develop and execute risk-based IT and cybersecurity audit plans, including scoping, testing, and reporting of various security domains, including vulnerability management, access control, incident response, data security, and cloud security.</li><li>Leverage your understanding of leading industry regulations and standards, including NIST, ISO 27001, SOC 2, and PCI DSS and provide recommendations to the stakeholders.</li><li>Aid in the development and implementation of continuous monitoring for key security controls.</li><li>Utilize data analytics to identify security trends and potential risks.</li></ul><h1><strong>We’re excited about you because…</strong></h1><ul><li>You have 8+ years of experience in IT audit, cybersecurity, or a related field.</li><li>You have experience building a Security assessment program ground up and planning and executing Security Risk Assessments.</li><li>You have experience planning and executing audits of various security domains, including vulnerability management, access control, incident response, data security, and cloud security.</li><li>You have effective communication, presentation, and interpersonal skills.</li><li>You have a strong understanding of IT and cybersecurity frameworks and standards (e.g., NIST, ISO 27001, SOC 2, PCI DSS).</li><li>You have experience collaborating with a geographically distributed team.</li><li>You have experience with GRC tools and security solutions like Panther, Wiz or Google ... (truncated, view full listing at source)