Senior Detection Engineer

Doordashusa
United States
Remote

Who this role is best for

A natural match if you have experience in agentic detection engineering for scalable delivery networks and cross-functional collaboration with threat intelligence and incident response teams.

Best fit for

  • Candidates with over a decade of experience in detection engineering, especially in cloud environments
    — “7+ years of experience in secure coding, alert development, and detection engineering.
  • Candidates who have operationalized detection-as-code pipelines in previous roles
    — “Direct experience building, maintaining, and operating a detection-as-code pipeline
  • Individuals who can translate industry frameworks into actionable detection strategies
    — “Experience translating MITRE ATT&CK, D3FEND, and other industry frameworks into meaningful rationalizations of detection coverage

Things to consider

  • On-call rotation is mandatory, requiring availability for incident response
    — “participation in an on-call rotation is required for this role.
  • Salary is localized to the candidate’s work location within the US
    — “Base salary is localized according to an employee’s work location.

How to stand out

  • Highlight experience with agentic tooling and detection-as-code pipelines in your resume
    — “Develop and maintain agentic tooling to increase detection efficacy and efficiency
  • Showcase mastery of SIEM querying (SQL, SPL, KQL) and Python/Go in technical projects
    — “Mastery of SIEM querying (sql, spl, kql) and programming languages (python, go, etc)
  • Demonstrate cross-functional collaboration with incident response and threat intelligence teams
    — “Coordinate with cross-functional teams, internally and externally, on threats targeting DoorDash
  • Quantify achievements in reducing alert volumes via risk-based analytics
    — “implementing risk-based analytics to reduce alert volumes and promote high-fidelity alert content
  • Emphasize experience with global teams and non-traditional security environments
    — “Detection at DoorDash spans more than the corporate estate... marketplace itself
Pace · Fast PacedCollaboration · HighAutonomy · MediumDecision Impact · CompanyLevel · Senior

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • effective detection content
  • improved security posture
Typical background
cybersecuritydetection engineering

Skills & requirements

Required

Detection EngineeringSIEMCloud InfrastructureThreat IntelligenceAlert Development

Preferred

Agentic DetectionAutomation

Stack & domain

Secure CodingAlert DevelopmentDetection EngineeringSIEM QueryingCloud Based And Distributed SystemsCybersecurityThreat Detection

About the role

Original posting from Doordashusa via Greenhouse

About the Team

At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team that covers response, intelligence, insider risk, threat hunting, automation, and detection engineering.

We exist to keep our brands safe for the Dashers, merchants, and consumers who depend on us. Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration. 

About the Role

The senior detection engineer is part of the larger detection engineering team that creates, tunes, maintains, and improves the detection lifecycle. This hands-on role is at the forefront of agentic detection engineering of a rapidly maturing security function. You’ll work closely with our data pipelines team, incident response, insider risk, and threat intelligence teams to make the most effective detection content to detect threats as quickly as possible.  

Detection at DoorDash spans more than the corporate estate. You’ll build coverage across cloud infrastructure, corporate endpoints and identity, and the marketplace itself - where consumer, merchant, and Dasher platforms create abuse and insider-risk patterns you won’t find in a typical enterprise SOC. We’re actively consolidating detection onto a modern data platform, so you’ll have real influence over what the pipeline looks like.

This role reports to the Senior Manager, Cyber Defense located in the United States and participation in an on-call rotation is required for this role. 

You’re excited about this opportunity because you will…

Conduct hands-on detection engineering for custom alerting, to include implementing risk-based analytics to reduce alert volumes and promote high-fidelity alert content

Integrate external signals such as threat intelligence into alerting pipelines tailored to specific use cases 

Develop and maintain agentic tooling to increase detection efficacy and efficiency

Leverage security tooling, logs, and custom telemetry to build detections at scale

Work with structured and unstructured telemetry to produce meaningful security signals

Maintain detection repositories, use case libraries, and conduct routine content optimization

Coordinate with cross-functional teams, internally and externally, on threats targeting DoorDash

Participate in and lead projects that improve the security posture of all DoorDash brands

Create and maintain standards and documentation to improve service consistency

Mentor and uplevel other engineers within the Cyber Defense organization

Participate in and support our on-call rotation

We’re excited about you because you have…

7+ years of experience in secure coding, alert development, and detection engineering.

Direct experience building, maintaining, and operating a detection-as-code pipeline

A proven track record building automation that measurably improved detection accuracy, velocity, or quality

Demonstrated experience building agents to effectively and efficiently solve detection problems

Extensive knowledge of cloud based and distributed systems

Experience working with global and cross-functional partners, especially incident response, insider risk, and threat hunting teams

Mastery of SIEM querying (sql, spl, kql) and programming languages (python, go, etc)

Experience translating MITRE ATT&CK, D3FEND, and other industry frameworks into meaningful rationalizations of detection coverage 

Excellent verbal and written communication, presentation, and stakeholder management skills

Experience with Snowflake, Cortex, Google SecOps is preferred  

Compensation

The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future.

In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.

DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others.

To learn more about our benefits, visit our careers page here.

See below for paid time off details:

For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.

For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).

The national base pay range for this position within the United States, including Illinois and Colorado.$159,800—$235,000 USDAbout DoorDash

At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods.

DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more.

Our Commitment to Diversity and Inclusion

We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel.

Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non-discrimination.

Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

If you need any accommodations, please inform your recruiting contact upon initial connection.

Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only

We used Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provided Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound from August 21, 2023, through December 21, 2023.  We resumed using Covey Scout for Inbound again on June 29, 2024, and ceased using Covey Scout for Inbound on April 30, 2026.

The Covey tool has been reviewed by an independent auditor. Results of the audit may be viewed here: https://getcovey.com/nyc-local-law-144.

Source: Doordashusa careers (Greenhouse)

Similar roles