Senior Security Data Engineer
DoorDash · United States of America
- Зарплата
- 159 800 – 235 000 $
- Грейд
- Senior
- Формат
- Удалённо
- Занятость
- Полная
- Категория
- Безопасность
Откликнуться
Прямого контакта в посте нет
Откройте вакансию в Telegram-боте: там весь исходный пост и способ отклика.
Открыть в TelegramОписание
Senior Security Data Engineer
About the Team
At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team that covers response, intelligence, insider risk, threat hunting, automation, and detection engineering. We exist to keep our brands safe for the Dashers, merchants, and consumers who depend on us. Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration.
About the Role
Security at DoorDash, Deliveroo, and Wolt runs on telemetry, and our data pipelines team owns all of it. You will own multi-terabyte-per-day ingest across AWS and GCP, including reliability, cost, and schema, so that every detection engineer, threat hunter, and responder across three brands can find what they need. Most of your week goes to code, pipelines, and query performance rather than alert triage. The team spans the US and UK, so you will be in the room (or the thread) with IT, legal, privacy, incident response, insider risk, threat intelligence, and detection engineering on a regular basis. Very little of this work happens in isolation, and that is the fun of it. This role reports to the Senior Manager of Cyber Defense in the United States. The role includes participation in an on-call rotation for pipeline health.
You’re excited about this opportunity because you will…
- Own multi-terabyte-per-day log pipelines across AWS and GCP: ingest, routing, enrichment, schema management, and onboarding new sources as the business adds them
- Control ingest cost and volume, cutting noise at the edge without dropping the audit logs investigators depend on
- Model security data and tune query performance in Snowflake, BigQuery, and Redshift, including the tables detection engineering builds on
- Ship production services and integrations that other teams depend on: custom SIEM connectors, API clients, and automation
- Set and defend SLOs for log availability and freshness, and build the dashboards and alerting that prove them
- Own infrastructure as code and CI/CD for all of the above, including the deployment path that detections-as-code rides on
- Build AI agents and automated runbooks that speed up triage and time to fix across cloud infrastructure
- Enforce IAM and service account governance for the pipeline's cloud workloads
- Lead cross-functional projects spanning infrastructure, platform engineering, and incident response
- Create and maintain the standards and documentation that keep the service consistent, and mentor engineers across Cyber Defense
We’re excited about you because you have…
- 5+ years building and operating high-volume data pipelines in production at multi-terabyte-per-day scale, with tools like Kafka, Cribl, Dataflow, Kinesis, or CloudWatch
- 4+ years writing production software in Python, Go, Rust, or Java: services and tooling that other engineers run, beyond one-off scripts
- Deep hands-on experience with AWS and GCP, including infrastructure as code and ownership of CI/CD pipelines on GitHub, GitLab, or Bitbucket
- Strong SQL and data modeling in a columnar warehouse such as Snowflake, BigQuery, or Redshift, covering partitioning, cost control, and query tuning
- A track record owning reliability for a platform other engineers depend on, including on-call
- Experience building executive dashboards and engineering metrics that people actually act on
- Proven leadership and technical project management across infrastructure, platform engineering, and incident response
- Exceptional written and verbal communication, a collaborative instinct, and a habit of continuous learning
- Familiarity with an enterprise SIEM as an operator or a consumer (Google SecOps/Chronicle, Splunk, Elastic, CrowdStrike LogScale) is a plus, as is time with Kubernetes, Docker, and runtime security controls
- Any hands-on time with security telemetry sources, detections-as-code (YARA-L, Sigma, SPL), LLM-assisted workflows, penetration testing, red teaming, or triaging bug bounty reports is a bonus
Compensation
The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future.
In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.
DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others.
To learn more about our benefits, visit our careers page here.
See below for paid time off details:
- For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
- For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).
About DoorDash
At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods.
DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more.
Our Commitment to Diversity and Inclusion
We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel.
Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or
About the Team
At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team that covers response, intelligence, insider risk, threat hunting, automation, and detection engineering. We exist to keep our brands safe for the Dashers, merchants, and consumers who depend on us. Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration.
About the Role
Security at DoorDash, Deliveroo, and Wolt runs on telemetry, and our data pipelines team owns all of it. You will own multi-terabyte-per-day ingest across AWS and GCP, including reliability, cost, and schema, so that every detection engineer, threat hunter, and responder across three brands can find what they need. Most of your week goes to code, pipelines, and query performance rather than alert triage. The team spans the US and UK, so you will be in the room (or the thread) with IT, legal, privacy, incident response, insider risk, threat intelligence, and detection engineering on a regular basis. Very little of this work happens in isolation, and that is the fun of it. This role reports to the Senior Manager of Cyber Defense in the United States. The role includes participation in an on-call rotation for pipeline health.
You’re excited about this opportunity because you will…
- Own multi-terabyte-per-day log pipelines across AWS and GCP: ingest, routing, enrichment, schema management, and onboarding new sources as the business adds them
- Control ingest cost and volume, cutting noise at the edge without dropping the audit logs investigators depend on
- Model security data and tune query performance in Snowflake, BigQuery, and Redshift, including the tables detection engineering builds on
- Ship production services and integrations that other teams depend on: custom SIEM connectors, API clients, and automation
- Set and defend SLOs for log availability and freshness, and build the dashboards and alerting that prove them
- Own infrastructure as code and CI/CD for all of the above, including the deployment path that detections-as-code rides on
- Build AI agents and automated runbooks that speed up triage and time to fix across cloud infrastructure
- Enforce IAM and service account governance for the pipeline's cloud workloads
- Lead cross-functional projects spanning infrastructure, platform engineering, and incident response
- Create and maintain the standards and documentation that keep the service consistent, and mentor engineers across Cyber Defense
We’re excited about you because you have…
- 5+ years building and operating high-volume data pipelines in production at multi-terabyte-per-day scale, with tools like Kafka, Cribl, Dataflow, Kinesis, or CloudWatch
- 4+ years writing production software in Python, Go, Rust, or Java: services and tooling that other engineers run, beyond one-off scripts
- Deep hands-on experience with AWS and GCP, including infrastructure as code and ownership of CI/CD pipelines on GitHub, GitLab, or Bitbucket
- Strong SQL and data modeling in a columnar warehouse such as Snowflake, BigQuery, or Redshift, covering partitioning, cost control, and query tuning
- A track record owning reliability for a platform other engineers depend on, including on-call
- Experience building executive dashboards and engineering metrics that people actually act on
- Proven leadership and technical project management across infrastructure, platform engineering, and incident response
- Exceptional written and verbal communication, a collaborative instinct, and a habit of continuous learning
- Familiarity with an enterprise SIEM as an operator or a consumer (Google SecOps/Chronicle, Splunk, Elastic, CrowdStrike LogScale) is a plus, as is time with Kubernetes, Docker, and runtime security controls
- Any hands-on time with security telemetry sources, detections-as-code (YARA-L, Sigma, SPL), LLM-assisted workflows, penetration testing, red teaming, or triaging bug bounty reports is a bonus
Compensation
The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future.
In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.
DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others.
To learn more about our benefits, visit our careers page here.
See below for paid time off details:
- For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
- For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).
About DoorDash
At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods.
DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more.
Our Commitment to Diversity and Inclusion
We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel.
Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or
- aws
- gcp
- bigquery
- snowflake
- redshift
- kafka
- python
- golang
- rust
- java
- kubernetes
- docker
- ci_cd
- github
- sql
Оценка вакансии
84/100 · хорошо
- Описание полное
- Зарплатная вилка указана
- Компания и проект описаны
- Контакта нет
- Стек описан подробно
- Формат работы понятен
Похожие вакансии
Director, Security Governance, Risk and Compliance
AI-балл 64/100Tricentis Americas, Inc. · Austin, United States
LeadОфисgdpriso_27001iso_27701
Cybersecurity Analyst Intern
AI-балл 64/100Southwest Airlines · Dallas, United States
$26 - $30 /hour
InternУдалённоagileawsoffice365
Senior Application Security Engineer
AI-балл 64/100CharterUP · Austin, United States
SeniorГибридawsiamjava
Director of Security Operations
AI-балл 84/100Backblaze · United States of America
205 000 – 230 000 $
HeadУдалённоiamnetwork_securitycloud
Senior Cybersecurity Analyst
AI-балл 61/100Nightwing
SeniorУдалённоbashlinuxlog_analysis