← Back to jobs

Senior Security Data Engineer

Company
DoorDash, Inc.
Location
United States
Work type
Full Time · Remote
Posted
2026-09-01

Job description

About the Role
Security at DoorDash, Deliveroo, and Wolt runs on telemetry, and our data pipelines team owns all of it. You will own multi-terabyte-per-day ingest across AWS and GCP, including reliability, cost, and schema, so that every detection engineer, threat hunter, and responder across three brands can find what they need. Most of your week goes to code, pipelines, and query performance rather than alert triage. The team spans the US and UK, so you will be in the room (or the thread) with IT, legal, privacy, incident response, insider risk, threat intelligence, and detection engineering on a regular basis. Very little of this work happens in isolation, and that is the fun of it. This role reports to the Senior Manager of Cyber Defense in the United States. The role includes participation in an on-call rotation for pipeline health.

You’re excited about this opportunity because you will…
Own multi-terabyte-per-day log pipelines across AWS and GCP: ingest, routing, enrichment, schema management, and onboarding new sources as the business adds them
Control ingest cost and volume, cutting noise at the edge without dropping the audit logs investigators depend on
Model security data and tune query performance in Snowflake, BigQuery, and Redshift, including the tables detection engineering builds on
Ship production services and integrations that other teams depend on: custom SIEM connectors, API clients, and automation
Set and defend SLOs for log availability and freshness, and build the dashboards and alerting that prove them
Own infrastructure as code and CI/CD for all of the above, including the deployment path that detections-as-code rides on
Build AI agents and automated runbooks that speed up triage and time to fix across cloud infrastructure
Enforce IAM and service account governance for the pipeline's cloud workloads
Lead cross-functional projects spanning infrastructure, platform engineering, and incident response
Create and maintain the standards and documentation that keep the service consistent, and mentor engineers across Cyber Defense

We’re excited about you because you have…
5+ years building and operating high-volume data pipelines in production at multi-terabyte-per-day scale, with tools like Kafka, Cribl, Dataflow, Kinesis, or CloudWatch
4+ years writing production software in Python, Go, Rust, or Java: services and tooling that other engineers run, beyond one-off scripts
Deep hands-on experience with AWS and GCP, including infrastructure as code and ownership of CI/CD pipelines on GitHub, GitLab, or Bitbucket
Strong SQL and data modeling in a columnar warehouse such as Snowflake, BigQuery, or Redshift, covering partitioning, cost control, and query tuning
A track record owning reliability for a platform other engineers depend on, including on-call
Experience building executive dashboards and engineering metrics that people actually act on
Proven leadership and technical project management across infrastructure, platform engineering, and incident response
Exceptional written and verbal communication, a collaborative instinct, and a habit of continuous learning
Familiarity with an enterprise SIEM as an operator or a consumer (Google SecOps/Chronicle, Splunk, Elastic, CrowdStrike LogScale) is a plus, as is time with Kubernetes, Docker, and runtime security controls
Any hands-on time with security telemetry sources, detections-as-code (YARA-L, Sigma, SPL), LLM-assisted workflows, penetration testing, red teaming, or triaging bug bounty reports is a bonus

Original source