About the role
Senior Security Data Engineer
United States - Remote
About the Team
At DoorDash, including international brands Deliveroo and Wolt, we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Global Cyber Defense is a highly talented and globally distributed team that covers response, intelligence, insider risk, threat hunting, automation, and detection engineering. We exist to keep our brands safe for the Dashers, merchants, and consumers who depend on us.
Our mission is to detect, investigate, and respond to cyber threats with speed and precision, while continuously hardening our defenses through automation, AI, and cross-regional collaboration.
About the Role
Security at DoorDash, Deliveroo, and Wolt runs on telemetry, and our data pipelines team owns all of it. You will own multi-terabyte-per-day ingest across AWS and GCP, including reliability, cost, and schema, so that every detection engineer, threat hunter, and responder across three brands can find what they need. Most of your week goes to code, pipelines, and query performance rather than alert triage.
The team spans the US and UK, so you will be in the room (or the thread) with IT, legal, privacy, incident response, insider risk, threat intelligence, and detection engineering on a regular basis. Very little of this work happens in isolation, and that is the fun of it. This role reports to the Senior Manager of Cyber Defense in the United States. The role includes participation in an on-call rotation for pipeline health.
You’re excited about this opportunity because you will…
Own multi-terabyte-per-day log pipelines across AWS and GCP: ingest, routing, enrichment, schema management, and onboarding new sources as the business adds them
Control ingest cost and volume, cutting noise at the edge without dropping the audit logs investigators depend on
Model security data and tune query performance in Snowflake, BigQuery, and Redshift, including the tables detection engineering builds on
Ship production services and integrations that other teams depend on: custom SIEM connectors, API clients, and automation
Set and defend SLOs for log availability and freshness, and build the dashboards and alerting that prove them
Own infrastructure as code and CI/CD for all of the above, including the deployment path that detections-as-code rides on
Build AI agents and automated runbooks that speed up triage and time to fix across cloud infrastructure
Enforce IAM and service account governance for the pipeline's cloud workloads
Lead cross-functional projects spanning infrastructure, platform engineering, and incident response
Create and maintain the standards and documentation that keep the service consistent, and mentor engineers across Cyber Defense
We’re excited about you because you have…
5+ years building and operating high-volume data pipelines in production at multi-terabyte-per-day scale, with tools like Kafka, Cribl, Dataflow, Kinesis, or CloudWatch
4+ years writing production software in Python, Go, Rust, or Java: services and tooling that other engineers run, beyond one-off scripts
Deep hands-on experience with AWS and GCP, including infrastructure as code and ownership of CI/CD pipelines on GitHub, GitLab, or Bitbucket
Strong SQL and data modeling in a columnar warehouse such as Snowflake, BigQuery, or Redshift, covering partitioning, cost control, and query tuning
A track record owning reliability for a platform other engineers depend on, including on-call
Experience building executive dashboards and engineering metrics that people actually act on
Proven leadership and technical project management across infrastructure, platform engineering, and incident response
Exceptional written and verbal communication, a collaborative instinct, and a habit of continuous learning
Familiarity with an enterprise SIEM as an operator or a consumer (Google SecOps/Chronicle, Splunk, Elastic, CrowdStrike LogScale) is a plus, as is time with Kubernetes, Docker, and runtime security controls
Any hands-on time with security telemetry sources, detections-as-code (YARA-L, Sigma, SPL), LLM-assisted workflows, penetration testing, red teaming, or triaging bug bounty reports is a bonus
Compensation
The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future.
In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.
DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others.
To learn more about our benefits, visit our careers page here.
See below for paid time off details:
For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).
The national base pay range for this position within the United States, including Illinois and Colorado.
$159,800 - $235,000 USD
Minimum requirements
- 5+ years building and operating multi-terabyte-per-day data pipelines using tools like Kafka, Cribl, Dataflow, Kinesis, or CloudWatch
- 4+ years writing production software in Python, Go, Rust, or Java with strong AWS and GCP experience including infrastructure as code and CI/CD pipelines
- Proficient in SQL and data modeling in Snowflake, BigQuery, or Redshift, with proven platform reliability ownership and on-call experience
This listing was parsed by AI and may not be complete. Check the official posting on Doordash's site for the most accurate information.