Staff Security Engineer, Proactive Security

DoorDash DoorDash · Consumer · FL · 315 Security Engineering

Staff Security Engineer responsible for threat modeling, hardening, and operation of security services within DoorDash’s Product and Cloud Security domains. This role involves defining and implementing security standards, partnering cross-functionally, leading technical direction, and managing security vulnerabilities. The role also includes influencing the secure adoption of LLMs and AI tools and mentoring junior engineers.

What you'd actually do

  1. Threat model, design, harden, and operationalize Product and Cloud Security services and controls at DoorDash scale.
  2. Define, document and implement security standards, guidelines and procedures to design and implement automated security controls and remediation tools with rigor and developer ergonomics.
  3. Partner cross-functionally with Core Infrastructure, Product Engineering, Legal, Security teams and Vendor Partners to build “paved paths” that provide actionable feedback to embed secure design practices into the product and infrastructure development process.
  4. Lead the technical direction and roadmap execution for your assigned area of ownership.
  5. Build and maintain high Operational Excellence (OE) to ensure we operate services with excellence, rigor and durable standards to ensure minimal downtime.

Skills

Required

  • security engineering
  • product security
  • infrastructure security
  • threat modeling
  • security services
  • security standards
  • security guidelines
  • security procedures
  • automated security controls
  • remediation tools
  • secure design practices
  • operational excellence
  • on-call rotation
  • vulnerability management
  • LLM security
  • AI tool security
  • mentoring
  • coaching
  • Python
  • Java
  • Terraform
  • GCP
  • AWS
  • distributed systems security
  • CI/CD
  • code analysis
  • architecture analysis
  • design analysis
  • root cause analysis
  • communication skills

Nice to have

  • Golang

What the JD emphasized

  • 8+ years of experience as a security engineer in a product security or infrastructure security discipline.
  • Able to demonstrate a track record of driving foundational improvements to a company’s infrastructure security posture.
  • Deep understanding of each OWASP top 10 vulnerability, distributed systems security and design.
  • Experience in CI/CD pipelines to automate security control enforcement and testing.
  • You proficient in analyzing code, architecture and designs from a security perspective
  • Strong experience with infrastructure as a code tooling like Terraform.
  • Expertise with cloud infrastructure and management in GCP and AWS.