Summary
DoorDash is a leading on-demand logistics and technology platform with a global safety and security function. The Detection Engineer, Protective Services will build, deploy, and maintain production detections that identify threats to protected individuals by correlating signals across enterprise, marketplace, physical security, and open-source data. The role also involves investigating detections, improving detection quality and workflows, and participating in on-call support.
Responsibilities
- Translate threat intelligence, incidents, investigative needs, and observed behavior into production detections that surface meaningful risk, reduce noise, and provide actionable context
- Build, test, deploy, tune, and maintain detections and supporting pipelines using source-controlled engineering practices designed to operate reliably at scale
- Correlate signals across enterprise telemetry, marketplace activity, physical security events, OSINT, support interactions, and other relevant data to identify and prioritize potential threats
- Apply rules, statistical methods, machine learning, and LLM-based techniques where they improve detection quality, prioritization, or investigative context
- Investigate detections by querying and correlating data, validating hypotheses, and assessing confidence, scope, and potential impact in partnership with Protective Services
- Follow detections through investigation and resolution, using outcomes, false positives, missed indicators, and investigative friction to continuously improve detection logic, tooling, and workflows
- Contribute to technical reviews, testing, documentation, standards, and automation that strengthen the reliability and maintainability of the detection function
- Participate in on-call and support major investigations, clearly communicating the confidence and limitations of available signals
Skills
- 3+ years of experience in detection engineering, threat hunting, incident response, security operations engineering, technical threat intelligence, or software engineering applied to security problems
- Experience contributing to production detection pipelines using source control, testing, review, deployment, and monitoring practices
- Proficiency in SQL or a security query language and the ability to write maintainable code in Python, Go, or another relevant language
- Strong analytical skills with the ability to explore unfamiliar datasets, assess data quality, troubleshoot across systems, and turn threat information into testable detection hypotheses
- Experience triaging alerts and investigations, correlating signals across data sources, assessing confidence and scope, and clearly communicating what the evidence supports
- Experience building detections or conducting investigations using security, behavioral, or other relevant telemetry
- Experience using automation or analytics to improve detection and investigation workflows
- Familiarity with frameworks such as MITRE ATT&CK or D3FEND and their use in organizing detection coverage and identifying gaps
- Strong collaboration and communication skills, with the ability to work effectively across engineering, investigative, and response teams and handle sensitive information appropriately
- Bachelor's degree or equivalent practical experience
- Exposure to identity, endpoint, cloud, marketplace, physical security, OSINT, or unstructured data is a plus
- Familiarity with machine learning or LLM-based techniques is a plus
- Experience with Snowflake, Cortex, or Google SecOps is preferred
Qualifications
Must Haves
- 3+ years of experience in detection engineering, threat hunting, incident response, security operations engineering, technical threat intelligence, or software engineering applied to security problems
- Experience contributing to production detection pipelines using source control, testing, review, deployment, and monitoring practices
- Proficiency in SQL or a security query language and the ability to write maintainable code in Python, Go, or another relevant language
- Strong analytical skills with the ability to explore unfamiliar datasets, assess data quality, troubleshoot across systems, and turn threat information into testable detection hypotheses
- Experience triaging alerts and investigations, correlating signals across data sources, assessing confidence and scope, and clearly communicating what the evidence supports
- Experience building detections or conducting investigations using security, behavioral, or other relevant telemetry
- Experience using automation or analytics to improve detection and investigation workflows
- Familiarity with frameworks such as MITRE ATT&CK or D3FEND and their use in organizing detection coverage and identifying gaps
- Strong collaboration and communication skills, with the ability to work effectively across engineering, investigative, and response teams and handle sensitive information appropriately
- Bachelor's degree or equivalent practical experience
Nice to Haves
- Exposure to identity, endpoint, cloud, marketplace, physical security, OSINT, or unstructured data is a plus
- familiarity with machine learning or LLM-based techniques is a plus
- Experience with Snowflake, Cortex, or Google SecOps is preferred
Benefits
- Opportunities for equity grants
- 401(k) plan with employer matching
- 16 weeks of paid parental leave
- Wellness benefits
- Commuter benefits match
- Paid time off
- Paid sick leave in compliance with applicable laws
- Medical benefits
- Dental benefits
- Vision benefits
- 11 paid holidays
- Disability insurance
- Basic life insurance
- Family-forming assistance
- Mental health program
- For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year
- Premium healthcare
- Wellness expense reimbursement
- United States - Remote work arrangement