Senior Information Security Specialist

Deliveroo
London, United Kingdom
On-site

Who this role is best for

Best suited to candidates with experience in global compliance frameworks working in technology-driven marketplace environments.

Best fit for

  • Candidates with experience managing global compliance frameworks in tech or SaaS environments
    — “managed or materially contributed to a global compliance framework or security/privacy compliance management program
  • Individuals who have driven risk assessments and remediation planning across cross-functional teams
    — “facilitate risk assessments, compliance risk workshops, control self-assessments and remediation planning with cross-functional stakeholders
  • Candidates with a background in translating complex compliance requirements into actionable control expectations
    — “translate complex regulatory, security, and privacy requirements into practical control expectations and specifications

Things to consider

  • The role requires managing multiple compliance frameworks simultaneously across global markets
    — “Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements
  • The position demands clear communication of compliance risk to leadership in business terms
    — “help leadership understand compliance risk in clear business terms

How to stand out

  • Highlight experience with global regulatory change management and cross-functional risk assessments
    — “create and operationalise a global compliance change process framework
  • Showcase your ability to translate complex compliance requirements into technical specifications
    — “translate complex regulatory, security, and privacy requirements into practical control expectations
  • Demonstrate past success in driving accountability for remediation across teams
    — “identify control gaps, assess residual risk, define remediation plans and track progress through closure with clear accountability
Pace · SteadyCollaboration · HighAutonomy · MediumDecision Impact · Company

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • design and operate a global compliance change management framework
  • facilitate compliance risk workshops
  • translate complex regulatory requirements into practical control expectations
Typical background
6+ years of experience in GRC, security compliance, technology risk, privacy compliance, IT audit

Skills & requirements

Required

Global Compliance FrameworksSecurity CompliancePrivacy ComplianceRisk ManagementCompliance Change Management

Preferred

Control MappingRisk Communications

Stack & domain

ISO 27001SOC 2NIST CSFPCI DSSGDPRUK GDPRNIS2DORALeadershipCommunicationSecurityPrivacyCompliance

About the role

Original posting from Deliveroo via Ashby

About the team

At Doordash, Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our multi-sided marketplace of consumers, merchants, Dashers, and partners. Security, privacy, and compliance are foundational to earning and maintaining trust as we expand globally.

The Governance, Risk, and Compliance team partners across Security, Engineering, Legal, Privacy, Product, IT, Procurement, Internal Audit, and business teams to help DoorDash understand its compliance obligations, manage security and privacy risk, and build durable programs that scale with the company.

About the role

We’re looking for a Senior Information Security Specialist to help mature DoorDash’s global security and privacy compliance risk program. You will create and operationalise a global compliance change process framework that helps DoorDash detect changes in our compliance landscape, assess impact, identify gaps, and drive accountable remediation across teams.

This is a senior individual contributor role for someone who has managed global compliance frameworks and security/privacy compliance programs in a technology company. You will bring structure to ambiguous compliance changes, translate requirements into actionable control expectations, facilitate risk workshops, and help leadership understand compliance risk in clear business terms.

What you'll be doing

  • Design and operate a global compliance change management framework to identify new or changing security, privacy, regulatory, contractual and framework obligations across DoorDash’s markets and products.
  • Maintain a structured view of DoorDash’s compliance landscape, including obligation inventories, control mappings, ownership models, risk decisions and remediation status.
  • Lead compliance-impact assessments for new regulations, framework updates, product launches, market expansions, vendor changes and major technology initiatives.
  • Facilitate compliance risk workshops with Engineering, Legal, Privacy, Product, Procurement, IT, Internal Audit and business stakeholders.
  • Translate complex regulatory, security, and privacy requirements into practical control expectations and specifications that technical and non-technical teams can implement.
  • Identify control gaps, assess residual risk, define remediation plans and track progress through closure with clear accountability.
  • Partner with control owners to improve evidence quality, audit readiness, and sustainable operation of controls across global compliance frameworks.
  • Help mature DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications.
  • Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements.
  • Promote a risk-based, pragmatic compliance culture that enables DoorDash teams to move quickly while protecting customers, partners, employees and the business.

Requirements

  • You have 6+ years of experience in GRC, security compliance, technology risk, privacy compliance, IT audit, or a related field, preferably in a global technology, marketplace, SaaS, fintech or payments environment.
  • You have managed or materially contributed to a global compliance framework or security/privacy compliance management program.
  • You have built, operated or significantly improved a compliance change management, obligations management, control mapping or regulatory-change process.
  • You have hands-on experience facilitating risk assessments, compliance risk workshops, control self-assessments and remediation planning with cross-functional stakeholders.
  • You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements.
  • You understand how security and privacy controls operate in modern technology environments, including cloud infrastructure, identity and access management, SDLC, incident response, vendor risk, data governance and business continuity.
  • You can translate legal, regulatory and framework requirements into clear, tangible control specifications to engineers and explain technical risk in business terms.
  • You communicate clearly, write with precision and can create high-quality policies, procedures, risk memos, control narratives, executive updates, and decision records.
  • You are comfortable navigating ambiguity, balancing multiple priorities and driving outcomes without relying on constant direction.
  • You build trust with technical and non-technical stakeholders and can facilitate conversations rather than dictate outcomes.

Why Doordash, Deliveroo and Wolt

Our mission is to transform the way you shop and eat, bringing the neighbourhood to your door by connecting consumers, restaurants, shops and riders. We are transforming the way the world eats and shops by making access to food and products more convenient and enjoyable. We give people the opportunity to buy what they want, as they want it, when and where they want it.

We are a technology-driven company at the forefront of the most rapidly expanding industry in the world. We are still a small team, making a very large impact, looking to answer some of the most interesting questions out there. We move fast, value autonomy and ownership, and we are always looking for new ideas.

Workplace & Benefits

At Doordash we know that people are the heart of the business and we prioritise their welfare. Benefits differ by country, but we offer many benefits in areas including healthcare, well-being, parental leave, pensions, and generous annual leave allowances, including time off to support a charitable cause of your choice. Benefits are country-specific, please ask your recruiter for more information.

Diversity

At Doordash, we believe a great workplace is one that represents the world we live in and how beautifully diverse it can be. That means we have no judgement when it comes to any one of the things that make you who you are - your gender, race, sexuality, religion or a secret aversion to coriander. All you need is a passion for (most) food and a desire to be part of one of the fastest-growing businesses in a rapidly growing industry.

We are committed to diversity, equity and inclusion in all aspects of our hiring process. We recognise that some candidates may require adjustments to apply for a position or fairly participate in the interview process. If you require any adjustments, please don't hesitate to let us know. We will make every effort to provide the necessary adjustments to ensure you have an equitable opportunity to succeed.

Source: Deliveroo careers (Ashby)

Similar roles