Staff Security Engineer, Proactive Security

2 days, 14 hours ago
Full-time
Lead
Cybersecurity
DoorDash

DoorDash

DoorDash empowers small business owners by providing an affordable and convenient platform for local delivery services, primarily focusing on restaurant food delivery.

Air Freight & Logistics
10K-50K
Founded 2012

Description

  • Threat model, design, harden, and operationalize Product and Cloud Security services and controls at DoorDash scale.
  • Define, document, and implement security standards, guidelines, and procedures.
  • Build automated security controls and remediation tools with strong developer ergonomics.
  • Partner with Core Infrastructure, Product Engineering, Legal, Security teams, and vendor partners to embed secure design practices into product and infrastructure development.
  • Lead technical direction and roadmap execution for the assigned area of ownership.
  • Maintain high operational excellence to support minimal downtime and durable service standards.
  • Participate in the on-call rotation and respond to incidents with urgency and rigor.
  • Manage the lifecycle of product and cloud security vulnerabilities, including identification, triage, remediation, reporting, and metrics.
  • Influence and enable the secure and responsible adoption of LLMs and AI tools.
  • Mentor and coach earlier-career engineers on operational excellence and security engineering standards.

Requirements

  • 8+ years of experience as a security engineer in product or infrastructure security.
  • Deep hands-on AWS experience across identity, IAM, SSO, and infrastructure hardening.
  • GCP experience is a plus.
  • Experience writing production-quality automation and tooling daily.
  • Hands-on AI experimentation applied to cloud security problems.
  • Proficiency in Python or another language such as Golang.
  • Strong experience with IaC tooling such as Terraform.
  • Experience driving foundational improvements to infrastructure security posture in large production environments.
  • Experience with CI/CD pipelines for automated control enforcement.
  • Deep understanding of OWASP Top 10 and distributed systems security and design.
  • Ability to analyze code, architecture, and designs from a security perspective.
  • Strong analytical, investigative, and root cause analysis skills, with clear written and verbal communication.

Benefits

  • Base salary range of $193,800 to $285,000 USD.
  • Opportunities for equity grants.
  • 401(k) plan with employer matching.
  • 16 weeks of paid parental leave.
  • Medical, dental, and vision benefits.
  • 11 paid holidays plus paid time off and paid sick leave.
  • Wellness benefits and commuter benefits match.
  • Disability and basic life insurance, family-forming assistance, and a mental health program.
  • Flexible paid time off/vacation for salaried roles, plus 80 hours of paid sick time per year.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Saviynt IAM Specialist

The Missing Link 51-250 Internet Software & Services

The Missing Link is seeking a Security Engineer - Saviynt to support large enterprise identity governance initiatives, design and deliver Saviynt-based solutions, and strengthen its growing cyber security practice.

Active Directory Azure Cybersecurity JavaScript PowerShell REST API SAP SQL
16 hours, 9 minutes ago

AI Security Architect (REMOTE - United States)

EnableComp 251-1K Insurance

EnableComp is seeking a remote AI Security Architect to secure and govern its AI and machine learning initiatives within its healthcare revenue cycle management environment.

Azure Cybersecurity HIPAA LLM Machine Learning
16 hours, 25 minutes ago

Senior Infrastructure Security Engineer

Dropbox 1K-5K Internet Software & Services

Dropbox is hiring a Security Engineer to secure its AI and agentic infrastructure while helping protect products and users across cloud and on-prem environments.

Bash CI/CD CrowdStrike Go Java Kubernetes Linux LLM Node.js OAuth OpenID Connect OWASP Python Ruby Rust SIEM
16 hours, 25 minutes ago

Staff, Security Engineer

Fullscript 251-1K Health Care Providers & Services

Fullscript is hiring a Staff Security Engineer to lead hands-on security engineering across its healthcare technology platform, shaping secure product development and protecting systems that support practitioners and patients.

AWS GitHub GitLab GraphQL JavaScript Node.js Penetration Testing Ruby on Rails
16 hours, 54 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers