Detection Engineer, Protective Services
DoorDash USA · United States - Remote
About this role
**Detection Engineer, Protective Services** **About the Team** DoorDash is one of the world’s leading on-demand logistics platforms. Across DoorDash, Deliveroo, and Wolt, our operations span more than 40 countries, dozens of offices, and tens of thousands of employees. Global Safety and Security helps protect our people, property, operations, brand, and reputation across that footprint—using technology, agility, and a people-first approach to stay ahead of evolving risks. Within the team, **Protective Services** focuses on the safety of our executives, their families, and the operations that support them. The **detection engineering** function brings together enterprise, marketplace, open-source, and physical security signals to identify threats that don’t fit neatly within a traditional SOC boundary. This role builds detection capabilities that turn those signals into timely, actionable intelligence. **About the Role** Detection engineering looks a little different here. As a **Detection Engineer on Protective Services**, you’ll build technical capabilities to help identify and investigate threats to protected individuals. Signals may surface across identities and endpoints, cloud environments, marketplace activity, support interactions, physical access events, or open-source information. You’ll connect those signals to find what matters by building detections, enrichment, and automation; separating meaningful risk from noise; and investigating what you uncover alongside Protective Services partners. This is a hands-on engineering role working across code, queries, data pipelines, detection repositories, and production systems. You’ll take detections from initial hypothesis through deployment and tuning, then use real-world outcomes to improve them. You’ll own well-understood problems and partner with senior engineers when deeper judgment is needed. This role reports to the **Engineering Manager, Protective Services** and participates in an **on-call rotation**. **You’ll be excited about this opportunity because you will…** - Translate threat intelligence, incidents, investigative needs, and observed behavior into production detections that surface meaningful risk, reduce noise, and provide actionable context. - Build, test, deploy, tune, and maintain detections and supporting pipelines using source-controlled engineering practices designed to operate reliably at scale. - Correlate signals across enterprise telemetry, marketplace activity, physical security events, OSINT, support interactions, and other relevant data to identify and prioritize potential threats. - Apply rules, statistical methods, machine learning, and LLM-based techniques where they improve detection quality, prioritization, or investigative context. - Investigate detections by querying and correlating data, validating hypotheses, and assessing confidence, scope, and potential impact with Protective Services partners. - Follow detections through investigation and resolution, using outcomes, false positives, missed indicators, and investigative friction to continuously improve detection logic, tooling, and workflows. - Contribute to technical reviews, testing, documentation, standards, and automation that strengthen reliability and maintainability. - Participate in on-call and support major investigations, clearly communicating confidence and limitations of available signals. **We’re excited about you because you have…** - 3+ years of experience in detection
Listing freshness
CronJobs last confirmed this listing 52m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.