Manager, Cyber Defense
At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team that covers response, intelligence, insider risk, threat hunting, automation, and detection engineering. We exist to keep our brands safe for the Dashers, merchants, and consumers who depend on us. Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration.
About the role
The Manager of Cyber Defense will lead the Incident Response capability of our US team. This role is responsible for supporting the organization’s security posture by helping the team identify, investigate, and mitigate cybersecurity threats and incidents, while also advancing automation to improve speed, quality, and scale. The manager will be responsible for the global integration of our program, mentorship of team members, and play an active response role in large scale incidents. The team operates in close collaboration with partners in the US, UK, EU, and India, with many team members participating in on-call and follow-the-sun incident response activities. Serving in the incident response and leadership on-call rotation is required for this role. The Manager will report to the Senior Manager of Cyber Defense (also located within the US) and partner closely on execution, team leadership, and operational coverage.
Responsibilities
- Lead and develop the US Threat Response team, part of the US Cyber Defense team.
- Serve as a hands-on people leader, supporting team well-being, performance, career growth, and day-to-day execution.
- Hire, mentor, and develop security professionals, fostering a culture of continuous learning, resilience, knowledge sharing, and strong collaboration.
- Ensure the team is working on the most valuable items from a shared global backlog, with clear priorities and sustainable work-in-progress limits.
- Partner with the Senior Manager and team leads across the UK, Finland, and India to coordinate ownership, resolve resourcing questions, and maintain strong cross-regional execution.
- For exceptional high-priority or high-impact incidents affecting US-based functions, serve as Incident Commander and coordinate response activities with relevant teams.
- Support communications with stakeholders during incidents, including executive updates when needed.
- In partnership with Legal, support engagement with law enforcement where required.
- Track, monitor, and report team metrics and operational outcomes for business reviews and Cyber Defense reporting.
- Execute business-critical projects and operational improvements that strengthen the effectiveness of the Cyber Defense program.
- Help scale and mature team processes, playbooks, and coordination models in support of a global, follow-the-sun response function.
- Advise and execute on long term plans, strategies, and shared work items in collaboration with relevant stakeholders.
Requirements
- Demonstrated experience in information security, including leadership responsibilities in areas such as incident response, incident management, investigations, threat hunting, or threat intelligence.
- A player-coach who can execute the technical tasks just as well as rally the team around shared goals.
- Solid experience scaling and mentoring security teams.
- Comfortable working with global partners in a follow-the-sun operating model.
- Effective people leader who can coach, support, and grow high-performing teams.
- Sound judgment during incidents and ability to help teams stay organized and effective under pressure.
- Clear thinking and pragmatic action when balancing urgent operational needs with longer-term improvements.
- Strong understanding of information security operations frameworks and operating models.
- Clear communication with technical and non-technical stakeholders, including cross-functional partners and leadership.
- Lead with a people-first approach, invite discussion rather than dictate it, and work well across different viewpoints and functions.
- Interest in how automation and AI can improve security operations and team effectiveness.
Benefits
- 401(k) plan with employer matching
- 16 weeks of paid parental leave
- Wellness benefits
- Commuter benefits match
- Paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act)
- Medical, dental, and vision benefits
- 11 paid holidays
- Disability and basic life insurance
- Family-forming assistance
- Mental health program
For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).
Pay
The national base pay range for this position within the United States, including Illinois and Colorado, is $193,800—$285,000 USD. In addition to base salary, the compensation for this role includes opportunities for equity grants.