What you will do- Own the vendor security review lifecycle: intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.
- Evaluate vendor evidence: SOC 2 reports, ISO certificates, pen-test results, and security questionnaires - deliver clear risk recommendations.
- Review vendor contracts, DPAs, and MSAs from a security standpoint; provide approval recommendations before contracts are signed.
- Build scalable tiering frameworks, intake workflows, and continuous monitoring capabilities that grow with vendor volume.
- Partner with Procurement, Legal, and Privacy to integrate security review into onboarding and renewal cycles without becoming a bottleneck.
- Complete and maintain external partnership-facing security questionnaires and trust-center content in support of integrations.
- Partner with Security team members to design and deliver security awareness training programs, including role-specific content on phishing, social engineering, third-party risk, and data handling.
- Track training completion and effectiveness; align program content with TPRM findings and emerging threats.
- Partner with IT and Security teams to design and run quarterly user access review campaigns, ensuring timely completion, accurate certification decisions, and clear remediation of access exceptions.
- Report on TPRM, training, and access review metrics to security leadership: cycle time, open findings, remediation aging, and completion rates.
Your profile- 5+ years in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.
- Hands-on experience evaluating SOC 2 reports, ISO certificates, and penetration test results, and translating findings into business-ready risk recommendations.
- Familiarity with contract review from a security perspective (e.g., DPAs & MSA) and comfort working with Legal and Procurement.
- Working knowledge of cloud security (AWS), IAM, and data-protection principles.
- Strong communicator: able to distill complex risk findings for non-technical stakeholders at all levels.
- Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.
- Relevant certification: CISA, CISM, CISSP, or equivalent security certification.
- Experience with TPRM or GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.
- Experience developing or delivering security awareness training, including content creation or phishing simulation.
- Background in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive data.
For this role, the target base salary range in San Francisco is $131,000-$164,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.
Turo highly values having employees working in-office to foster a collaborative work environment and company culture. This is central to how we work, and this role will be subject to our current in-office hybrid schedule that requires Turists to work in the office three days per week on Mondays, Wednesdays, and Thursdays. We expect that employees will meet these required in-office days consistently as part of their role. Your recruiter can share more information about this requirement and the in-office perks Turo offers.
BenefitsCompetitive salary, equity, benefits, and perks for all full-time employees
Employer-paid medical, dental, and vision insurance (Country specific)
Retirement employer match
Learning & Development stipend to invest in your professional development
Turo host matching program
Turo travel credit
Cell phone and internet stipend
Paid time off to relax and recharge
Paid holidays, volunteer time off, and parental leave
For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activities
We are committed to building a diverse team. If you are from a background that's underrepresented in tech, we'd love to meet you.
Aside from an award winning work environment and the opportunity to be part of the world’s largest car sharing marketplace, we are also growing the team quickly - join us! Even if you don't meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.