Security Engineer, Insider Threat

DoorDash DoorDash · Consumer · San Francisco, CA · 315 Security Engineering

Security Engineer focused on insider threats, investigating anomalous events, developing detections, and creating automated workflows using AI/ML tools. The role involves data analysis, incident response, and collaboration with Legal and HR.

What you'd actually do

  1. Use monitoring and detection platforms to investigate anomalous activity for potential insider risk, and develop detections to proactively identify similar behaviors at scale
  2. Support the onboarding, implementation, and improvement of custom tooling designed to alert on anomalous behaviors
  3. Create and maintain a use case library to inform detections, and develop corresponding playbooks, leveraging version-controlled workflows (e.g., Git) to ensure consistency and scalability
  4. Create standard operating procedures and cross-functional processes to govern investigation and response collaboration between teams
  5. Leverage and help develop agentic and AII-assisted workflows to automate and scale insider threat investigations and detection capabilities

Skills

Required

  • 2-5+ years of experience in insider threat investigations, incident response, or federal law enforcement
  • Strong verbal and written communication skills with experience presenting findings to stakeholders
  • Experience conducting ethical, complex investigations in partnership with Legal, HR, and cross-functional stakeholders
  • Hands-on experience with insider risk and security tooling including SIEM/SOAR platforms, UEBA, UAM, and DLP tools
  • Proficiency querying large-scale datasets to support investigations (e.g. SQL) and familiarity with log sources, data pipelines, and parsing
  • Familiarity with scripting and automation, and experience working in cloud and distributed environments using version control

What the JD emphasized

  • insider threat investigations
  • ethical, complex investigations
  • agentic and AII-assisted workflows