Senior Detection Engineer
DoorDash USA · United States - Remote
About this role
**Senior Detection Engineer — DoorDash (Global Cyber Defense)** ## About the Team DoorDash (including Deliveroo and Wolt) is building a scalable and reliable delivery network for consumers, merchants, and Dashers. Global Cyber Defense is a globally distributed team covering response, intelligence, insider risk, threat hunting, automation, and detection engineering. ## About the Role You’ll be part of the detection engineering team that creates, tunes, maintains, and improves the detection lifecycle. This hands-on role focuses on agentic detection engineering within a rapidly maturing security function. You’ll partner with data pipelines, incident response, insider risk, and threat intelligence teams to deliver high-impact detections quickly. Detection at DoorDash spans cloud infrastructure, corporate endpoints and identity, and the marketplace—where abuse and insider-risk patterns can differ from a typical enterprise SOC. The team is consolidating detection onto a modern data platform, giving you influence over the pipeline design. This role reports to the Senior Manager, Cyber Defense (US) and requires participation in an on-call rotation. ## You’ll Be Excited Because You Will… - Conduct hands-on detection engineering for custom alerting, including risk-based analytics to reduce alert volume and improve fidelity - Integrate external signals (e.g., threat intelligence) into alerting pipelines for specific use cases - Develop and maintain agentic tooling to improve detection efficacy and efficiency - Leverage security tooling, logs, and custom telemetry to build detections at scale - Work with structured and unstructured telemetry to produce meaningful security signals - Maintain detection repositories, use case libraries, and perform routine content optimization - Coordinate with cross-functional teams (internally and externally) on threats targeting DoorDash - Participate in and lead projects that improve the security posture across DoorDash brands - Create and maintain standards and documentation to improve service consistency - Mentor and up-level other engineers in Cyber Defense - Participate in and support the on-call rotation ## We’re Excited About You Because You Have… - 7+ years of experience in secure coding, alert development, and detection engineering - Direct experience building, maintaining, and operating a detection-as-code pipeline - A proven track record building automation that measurably improved detection accuracy, velocity, or quality - Demonstrated experience building agents to solve detection problems effectively and efficiently - Extensive knowledge of cloud-based and distributed systems - Experience working with global, cross-functional partners (especially incident response, insider risk, and threat hunting) - Mastery of SIEM querying (SQL, SPL, KQL) and programming languages (Python, Go, etc.) - Experience translating MITRE ATT&CK, D3FEND, and other frameworks into meaningful detection coverage rationalizations - Excellent verbal/written communication, presentation, and stakeholder management skills - Snowflake and Google SecOps experience is preferred ## Compensation (US) - **National base pay range:** **$159,800 — $235,000 USD** (localized by work location) - Equity grants and a comprehensive benefits package are included (401(k) with employer match, paid parental leave, wellness benefits, PTO/sick leave, medical/dental/vision, disability/basic life insurance, and more) ## About DoorDash DoorDash’s mi
Listing freshness
CronJobs last confirmed this listing 15m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.