Senior Information Security Specialist
On-siteLondon, England, United Kingdom
Job Summary
Design and operate a global compliance change management framework to identify new or changing security, privacy, regulatory, contractual, and framework obligations across DoorDash's markets and products. Maintain a structured view of the compliance landscape, including obligation inventories, control mappings, ownership models, risk decisions, and remediation status. Lead compliance-impact assessments for new regulations, framework updates, product launches, market expansions, vendor changes, and major technology initiatives. Facilitate compliance risk workshops with Engineering, Legal, Privacy, Product, Procurement, IT, Internal Audit, and business stakeholders to translate complex requirements into practical control expectations. Identify control gaps, assess residual risk, define remediation plans, and track progress through closure with clear accountability. Partner with control owners to improve evidence quality, audit readiness, and sustainable operation of controls across global frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, and DORA. Help mature the risk register, compliance reporting, dashboards, metrics, and executive-level risk communications while promoting a pragmatic compliance culture.
Required Qualifications
- 6+ years of experience in GRC, security compliance, technology risk, privacy compliance, IT audit, or a related field, preferably in a global technology, marketplace, SaaS, fintech or payments environment
- managed or materially contributed to a global compliance framework or security/privacy compliance management program
- built, operated or significantly improved a compliance change management, obligations management, control mapping or regulatory-change process
- hands-on experience facilitating risk assessments, compliance risk workshops, control self-assessments and remediation planning with cross-functional stakeholders
- strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and ability to quickly assess applicability of new frameworks or regulatory requirements
- understanding of how security and privacy controls operate in modern technology environments, including cloud infrastructure, identity and access management, SDLC, incident response, vendor risk, data governance and business continuity
- ability to translate legal, regulatory and framework requirements into clear, tangible control specifications to engineers and explain technical risk in business terms
- ability to communicate clearly, write with precision and create high-quality policies, procedures, risk memos, control narratives, executive updates, and decision records
- comfort navigating ambiguity, balancing multiple priorities and driving outcomes without relying on constant direction
- ability to build trust with technical and non-technical stakeholders and facilitate conversations rather than dictate outcomes
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.