deliveroo - Senior Information Security Specialist
Requirements
• You have 6+ years of experience in GRC, security compliance, technology risk, privacy compliance, IT audit, or a related field, preferably in a global technology, marketplace, SaaS, fintech or payments environment. • You have managed or materially contributed to a global compliance framework or security/privacy compliance management program. • You have built, operated or significantly improved a compliance change management, obligations management, control mapping or regulatory-change process. • You have hands-on experience facilitating risk assessments, compliance risk workshops, control self-assessments and remediation planning with cross-functional stakeholders. • You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements. • You understand how security and privacy controls operate in modern technology environments, including cloud infrastructure, identity and access management, SDLC, incident response, vendor risk, data governance and business continuity. • You can translate legal, regulatory and framework requirements into clear, tangible control specifications to engineers and explain technical risk in business terms. • You communicate clearly, write with precision and can create high-quality policies, procedures, risk memos, control narratives, executive updates, and decision records. • You are comfortable navigating ambiguity, balancing multiple priorities and driving outcomes without relying on constant direction. • You build trust with technical and non-technical stakeholders and can facilitate conversations rather than dictate outcomes.
Responsibilities
• Design and operate a global compliance change management framework to identify new or changing security, privacy, regulatory, contractual and framework obligations across DoorDash’s markets and products. • Maintain a structured view of DoorDash’s compliance landscape, including obligation inventories, control mappings, ownership models, risk decisions and remediation status. • Lead compliance-impact assessments for new regulations, framework updates, product launches, market expansions, vendor changes and major technology initiatives. • Facilitate compliance risk workshops with Engineering, Legal, Privacy, Product, Procurement, IT, Internal Audit and business stakeholders. • Translate complex regulatory, security, and privacy requirements into practical control expectations and specifications that technical and non-technical teams can implement. • Identify control gaps, assess residual risk, define remediation plans and track progress through closure with clear accountability. • Partner with control owners to improve evidence quality, audit readiness, and sustainable operation of controls across global compliance frameworks. • Help mature DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications. • Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements. • Promote a risk-based, pragmatic compliance culture that enables DoorDash teams to move quickly while protecting customers, partners, employees and the business.
Benefits
• At Doordash we know that people are the heart of the business and we prioritise their welfare. Benefits differ by country, but we offer many benefits in areas including healthcare, well-being, parental leave, pensions, and generous annual leave allowances, including time off to support a charitable cause of your choice. Benefits are country-specific, please ask your recruiter for more information.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT