Senior Detection Engineer, Protective Services

3 hours, 33 minutes ago
Full-time
Senior
DevOps and Infrastructure
DoorDash

DoorDash

DoorDash empowers small business owners by providing an affordable and convenient platform for local delivery services, primarily focusing on restaurant food delivery.

Air Freight & Logistics
10K-50K
Founded 2012

Description

  • Build, test, deploy, operate, and optimize detection-as-code pipelines at DoorDash scale.
  • Translate threat intelligence, incidents, investigative needs, and observed behavior into custom risk-based detections.
  • Integrate enterprise telemetry, marketplace activity, physical security events, OSINT, support interactions, and external signals.
  • Develop automation, agents, and investigative tooling that improve detection quality and reduce repetitive work.
  • Own the detection lifecycle from hypothesis and data validation through deployment, tuning, measurement, and retirement.
  • Conduct technical triage and investigations by correlating signals, assessing confidence and scope, and supporting response decisions.
  • Use investigation outcomes, false positives, and missed indicators to improve detection coverage and quality.
  • Coordinate with Protective Services, investigators, incident response, insider risk, threat hunting, and external partners.
  • Maintain engineering standards, testing practices, documentation, detection repositories, and use-case libraries.
  • Mentor engineers, lead protective-capability projects, and participate in the on-call rotation.

Requirements

  • 7+ years of experience in detection engineering, alert development, threat hunting, incident response, security operations engineering, technical threat intelligence, or security-focused software engineering.
  • Production experience building and operating detection-as-code pipelines with source control, testing, review, deployment, and monitoring.
  • Track record of developing automation that improves detection accuracy, response speed, or investigative quality.
  • Experience building and evaluating agents or LLM-backed tools for detection or investigation use cases.
  • Strong investigative judgment and ability to turn incomplete information into testable hypotheses.
  • Experience working with diverse structured and unstructured security or behavioral datasets and assessing data quality.
  • Knowledge of telemetry such as marketplace activity, physical access, alarms, video, OSINT, or support interactions.
  • Strong knowledge of cloud-based and distributed systems, including troubleshooting queries, code, pipelines, and source systems.
  • Mastery of SQL or SIEM query languages such as SPL or KQL, plus proficiency in Python, Go, or another relevant language.
  • Experience with MITRE ATT&CK, D3FEND, or similar frameworks; Snowflake, Cortex, or Google SecOps experience preferred.
  • Excellent communication, stakeholder management, discretion with sensitive information, and mentoring skills.
  • Bachelor’s degree or equivalent practical experience.

Benefits

  • U.S. base salary range of $159,800–$235,000, plus equity grant opportunities.
  • 401(k) plan with employer matching.
  • Medical, dental, vision, disability, and basic life insurance.
  • Flexible paid time off, 80 hours of paid sick time annually for salaried roles, and 11 paid holidays.
  • 16 weeks of paid parental leave and family-forming assistance.
  • Wellness, commuter benefits matching, and mental health programs.
  • Accommodation support and commitment to an inclusive, non-discriminatory workplace.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cybersecurity Engineering & Operations Director

Onit 251-1K IT Services

Onit is seeking a Director of Cybersecurity Engineering & Operations to lead security engineering, operations, and incident response across its AI-driven legal operations SaaS platforms and corporate infrastructure.

AWS Bash CI/CD Cloudflare CrowdStrike Cybersecurity DevSecOps Kubernetes Linux LLM Penetration Testing Python Secrets Management SIEM Terraform WAF
3 hours, 33 minutes ago

Senior DevSecOps Engineer

360Learning 251-1K Diversified Consumer Services

360Learning is hiring a Senior DevSecOps Engineer to secure and automate the Azure and Kubernetes infrastructure supporting its collaborative learning platform while strengthening detection, vulnerability management, and audit readiness.

AWS Azure CI/CD GCP GitOps Go Kubernetes Python Secrets Management Shell Scripting SIEM Terraform
3 hours, 33 minutes ago

Network & Security Support Engineer

Kerv 51-250 IT Services

Kerv Digital is seeking a remote Network & Security Support Engineer to support Kerv Connected Cloud’s managed network and security environments, delivering planned out-of-hours work and resolving critical customer incidents during UK night shifts.

DevSecOps DHCP DNS Fortinet Load Balancing
4 hours, 3 minutes ago

Staff Engineer, Identity & Access Management (IAM)

Recursion 251-1K Pharmaceuticals

Recursion is hiring an Identity and Access Management leader to modernize IAM across its products, infrastructure, and corporate applications while advancing its zero-trust security strategy.

Active Directory AWS Azure C++ Java Linux macOS OAuth OpenID Connect Python SAML Unix
4 hours, 3 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers