4 hours ago
Base Salary
$160k - $235k/yr
Responsibilities
- Build, test, deploy, operate, tune, measure, and retire production detection-as-code pipelines.
- Develop risk-based analytics, alerting, enrichment, and automation across enterprise telemetry, marketplace activity, physical-security events, OSINT, support interactions, and other signals.
- Conduct technical triage and investigations, correlate signals, assess confidence and scope, and support Protective Services response decisions.
- Build agents and LLM-backed tooling, evaluate their quality and failure modes, and improve investigative workflows.
- Maintain detection repositories and use-case libraries, improve detection coverage and quality, and reduce false positives and repetitive work.
- Coordinate with Protective Services, investigators, incident response, insider risk, threat hunting, and external partners.
- Create engineering standards, testing practices, and documentation; mentor other engineers; and participate in the on-call rotation.
Requirements
- 7+ years of experience in detection engineering, alert development, threat hunting, incident response, security operations engineering, technically oriented threat intelligence, or security-focused software engineering.
- Production experience building and operating detection-as-code pipelines with source control, testing, review, deployment, and monitoring.
- Experience building automation, detections across diverse datasets, and agents or LLM-backed tooling for detection or investigation problems.
- Extensive knowledge of cloud-based and distributed systems and strong investigative judgment with incomplete or uncertain threat information.
- Mastery of SQL or SIEM query languages such as SPL or KQL and proficiency writing maintainable code in Python, Go, or another relevant language.
- Experience with MITRE ATT&CK, D3FEND, or similar frameworks and with global cross-functional security partners.
- Bachelor’s degree or equivalent practical experience.
- Preferred experience with Snowflake, Cortex, or Google SecOps.
Benefits
- Comprehensive benefits include medical, dental, vision, disability, basic life insurance, wellness benefits, mental health programs, family-forming assistance, commuter benefits match, and a 401(k) with employer matching.
- Regular employees receive 16 weeks of paid parental leave, 11 paid holidays, paid time off, and paid sick leave; salaried roles include flexible PTO and 80 hours of paid sick time annually.
- The position includes equity grant opportunities in addition to base salary.
- The role requires participation in an on-call rotation, and the expected fill date is December 6, 2026.
About DoorDash
DoorDash builds a marketplace and logistics platform that connects consumers with local restaurants and retailers for on-demand delivery and pickup, powered by a network of independent Dashers. It earns through delivery fees, merchant commissions, advertising, DashPass subscriptions, and white-label fulfillment via DoorDash Drive. Founded in 2013 and headquartered in San Francisco, the public company operates across the U.S. and selected international markets, and also researches automation through DoorDash Labs.
