About the RoleWe are hiring a Senior Detection Engineer to build and improve the technical capabilities Protective Services uses to identify threats to protected individuals. You will develop detections, pipelines, enrichment, and automation across enterprise security telemetry, marketplace signals, open-source information, and physical security systems. This detection problem extends beyond conventional cybersecurity alerts. Relevant indicators may appear across identities, endpoints, cloud environments, support interactions, marketplace activity, access-control events, or unstructured online content. You will determine how to combine those signals, distinguish meaningful escalation from noise, and directly investigate resulting activity alongside Protective Services partners. That proximity to active cases grounds engineering decisions in real investigative needs and reveals opportunities to improve fidelity, automate friction, and reduce time to action. This is a hands-on security engineering role. You will work in code, queries, data pipelines, detection repositories, and production systems; carry detections from hypothesis through deployment and optimization; and use operational outcomes to improve coverage and quality. This role reports to the Engineering Manager, Protective Services, and requires participation in an on-call rotation.
You're excited about this opportunity because you will...- Conduct hands-on detection engineering for Protective Services, translating threat intelligence, investigative needs, known incidents, and observed behavior into high-quality custom alerting
- Implement risk-based analytics that reduce unnecessary alert volume, prioritize meaningful threats, and give investigators the context to act
- Build, test, deploy, and operate detection-as-code pipelines that support reliable detection at DoorDash's scale
- Integrate enterprise telemetry, marketplace activity, physical security events, OSINT, support interactions, and other external signals into detections tailored to protective use cases
- Work with structured and unstructured data, applying rules, statistical methods, machine learning, and LLM-backed techniques where they measurably improve detection and investigation
- Develop and maintain automation and agentic tooling that improve detection efficacy, streamline investigative workflows, and reduce repetitive work
- Own the detection lifecycle from hypothesis and data validation through deployment, tuning, measurement, and retirement; maintain detection repositories and use case libraries
- Conduct technical triage and investigations, correlate signals across sources, assess confidence and scope, and help Protective Services partners determine the appropriate response
- Follow detections through investigation, response, and mitigation, using case outcomes, false positives, and missed indicators to improve detection coverage and quality
- Coordinate with internal and external partners on threats targeting DoorDash and lead projects that strengthen protective capabilities across DoorDash brands
- Create and maintain engineering standards, testing practices, and documentation that improve service consistency and reliability
- Mentor and uplevel other engineers through technical reviews, knowledge sharing, and hands-on collaboration
- Participate in our on-call rotation and support significant protective cases
We're excited about you because you have...- 7+ years of experience in detection engineering, alert development, threat hunting, incident response, security operations engineering, technically oriented threat intelligence, or software engineering applied to security problems
- Direct experience building, maintaining, and operating production detection-as-code pipelines using source control, testing, review, deployment, and monitoring
- A proven track record building automation that measurably improves detection accuracy, speed, or investigative quality
- Demonstrated experience building agents or LLM-backed tooling to solve detection or investigation problems, including evaluating quality, reliability, and failure modes
- Strong investigative judgment, including translating incomplete threat information into testable hypotheses, evaluating competing explanations, and communicating what the evidence supports
- Experience building detections across diverse security or behavioral datasets, with the ability to assess data quality and quickly learn unfamiliar sources
- Familiarity with telemetry relevant to protective investigations, such as marketplace activity, physical access, alarms, video, OSINT, or support interactions; expertise across every source is not expected
- Extensive knowledge of cloud-based and distributed systems, including troubleshooting across queries, code, pipelines, and source systems
- Experience working with global and cross-functional partners, including Protective Services, investigators, incident response, insider risk, and threat hunting teams
- Mastery of SQL or SIEM query languages such as SPL or KQL, and proficiency writing maintainable code in Python, Go, or another relevant language
- Experience using MITRE ATT&CK, D3FEND, or similar frameworks to assess detection coverage and communicate gaps while prioritizing real threat behavior and operational outcomes
- Excellent communication, presentation, and stakeholder management skills, sound discretion with sensitive information, and a commitment to mentoring other engineers
- A bachelor's degree or equivalent practical experience
- Experience with Snowflake, Cortex, or Google SecOps is preferred
We expect this position to be filled by 12-06-2026
CompensationThe successful candidate's starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee's work location. Ranges are market-dependent and may be modified in the future.
In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information.
DoorDash cares about you and your overall well-being. That's why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others.
To learn more about our benefits, visit our careers page here.
See below for paid time off details:
- For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year.
- For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week).
The national base pay range for this position within the United States, including Illinois and Colorado.
$159,800-$235,000 USD