Sr. Security Compliance Specialist

DoorDash DoorDash · Consumer · Hartford, CT · 315 Security Engineering

This role is for a Sr. Security Compliance Specialist at DoorDash, focusing on scaling and maturing the company's global compliance program. The specialist will lead internal and external audits (SOC 1, SOC 2, PCI DSS), act as a liaison with auditors, and support the evolution of the compliance framework through policy development and control design. The role involves driving audit readiness, tracking and remediating findings, and identifying opportunities for process improvement, including automation. Experience in high-growth, technology-driven, or regulated environments is required, along with strong experience in implementing and assessing controls across common frameworks.

What you'd actually do

  1. Lead end-to-end execution of internal and external audits (SOC 1, SOC 2, PCI DSS), from planning through to reporting.
  2. Act as the primary point of contact for auditors, coordinating stakeholders and ensuring high-quality, consistent evidence.
  3. Establish and improve audit readiness processes to reduce disruption and increase efficiency.
  4. Drive tracking and remediation of audit findings, ensuring issues are resolved sustainably.
  5. Partner with the Security Compliance Manager to shape and mature the global compliance program.

Skills

Required

  • 7+ years of experience in security compliance, GRC, or technology risk
  • Strong track record in high-growth, technology-driven, or regulated environments
  • Significant experience leading external audits (e.g., SOC 1, SOC 2, PCI DSS)
  • Proven ability to drive readiness and manage the full audit lifecycle
  • Strong experience implementing and assessing controls across common frameworks such as PCI DSS, SOC 2, ISO 27001, and NIST CSF
  • Demonstrated ability to identify control gaps, assess risk, and drive remediation
  • Experience developing, implementing, or improving security policies, standards, and procedures
  • Strong understanding of compliance metrics and reporting
  • Ability to influence and drive accountability across technical and non-technical stakeholders
  • Excellent verbal and written communication skills
  • Experience mentoring or supporting junior team members

Nice to have

  • Professional certifications such as CISA, CISSP, CISM, or CRISC

What the JD emphasized

  • security compliance
  • SOC 1
  • SOC 2
  • PCI DSS
  • audit readiness
  • control frameworks
  • regulated environments
  • security policies
  • control gaps
  • audit findings
  • compliance metrics