Senior Detection Engineer
At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team covering response, intelligence, insider risk, threat hunting, automation, and detection engineering. Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration.
About the role
The senior detection engineer is part of the larger detection engineering team that creates, tunes, maintains, and improves the detection lifecycle. This hands-on role focuses on agentic detection engineering within a rapidly maturing security function. You’ll collaborate closely with our data pipelines team, incident response, insider risk, and threat intelligence teams to develop effective detection content that identifies threats as quickly as possible.
Detection at DoorDash spans beyond the corporate estate, covering cloud infrastructure, corporate endpoints and identity, and the marketplace—where consumer, merchant, and Dasher platforms create unique abuse and insider-risk patterns. We’re actively consolidating detection onto a modern data platform, giving you real influence over its design. This role reports to the Senior Manager, Cyber Defense in the United States and requires participation in an on-call rotation.
Responsibilities
- Conduct hands-on detection engineering for custom alerting, including implementing risk-based analytics to reduce alert volumes and promote high-fidelity alert content.
- Integrate external signals such as threat intelligence into alerting pipelines tailored to specific use cases.
- Develop and maintain agentic tooling to increase detection efficacy and efficiency.
- Leverage security tooling, logs, and custom telemetry to build detections at scale.
- Work with structured and unstructured telemetry to produce meaningful security signals.
- Maintain detection repositories, use case libraries, and conduct routine content optimization.
- Coordinate with cross-functional teams, internally and externally, on threats targeting DoorDash.
- Participate in and lead projects that improve the security posture of all DoorDash brands.
- Create and maintain standards and documentation to improve service consistency.
- Mentor and uplevel other engineers within the Cyber Defense organization.
- Participate in and support our on-call rotation.
Requirements
- 7+ years of experience in secure coding, alert development, and detection engineering.
- Direct experience building, maintaining, and operating a detection-as-code pipeline.
- A proven track record of building automation that measurably improved detection accuracy, velocity, or quality.
- Demonstrated experience building agents to effectively and efficiently solve detection problems.
- Extensive knowledge of cloud-based and distributed systems.
- Experience working with global and cross-functional partners, especially incident response, insider risk, and threat hunting teams.
- Mastery of SIEM querying (SQL, SPL, KQL) and programming languages (Python, Go, etc.).
- Experience translating MITRE ATT&CK, D3FEND, and other industry frameworks into meaningful rationalizations of detection coverage.
- Excellent verbal and written communication, presentation, and stakeholder management skills.
- Experience with Snowflake, Cortex, or Google SecOps is preferred.
Pay
The national base pay range for this position within the United States, including Illinois and Colorado, is $159,800—$235,000 USD. The successful candidate’s starting pay will be determined based on job-related factors including skills, experience, qualifications, work location, and market conditions. In addition to base salary, this role includes opportunities for equity grants.
Benefits
- Comprehensive benefits package, including medical, dental, and vision insurance.
- 401(k) plan with employer matching.
- 16 weeks of paid parental leave.
- Wellness benefits and commuter benefits match.
- Paid time off and paid sick leave in compliance with applicable laws (e.g., Colorado Healthy Families and Workplaces Act).
- 11 paid holidays.
- Disability and basic life insurance.
- Family-forming assistance and a mental health program.
Schedule
For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g., about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g., about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).