Staff Security Engineer
DoorDash
- Location
- San Francisco, CA
- Work model
- On-Site
- Level
- Staff
- Salary
- $193.8k/yr
- H-1B history
- 147 approvals (FY2023)
- Posted
- 3h ago
Skills
About this role
About the Team
At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of Consumers, Merchants, and Dashers. Security is paramount to the success of our business, and DoorDash Security aspires to be one the world’s most admired security team. We are committed to building the world's most trusted on-demand, logistics engine for delivery! We're expanding our team of great minds to help us secure and maintain a 24x7, no downtime, global infrastructure system that powers DoorDash’s multi-sided marketplace of Consumers, Merchants, and Dashers.
About the Role
Our Security Engineering team is looking for an Engineering Manager, Proactive Security to set and lead the technical direction for platform hardening at DoorDash, Wolt and Deliveroo globally.
You will be a part of our inclusive, collaborative global team responsible for building “paved road” Platform Security controls to harden our compute and storage platforms and provide for a safe, secure and resilient delivery network. This is a US or Canada remote position reporting directly to the Director of our Security Engineering team.
You’re excited about this opportunity because you will…
• Set and execute the technical vision for the Security Engineering Platform team, spanning AWS and GCP account/workload hardening, and vital tier-0 services (Access, Identity, Teleport, HashiCorp Vault, Tokenization and others).
• Influence and drive improvements to engineering standards, leverage advancements and LLMs to improve productivity and velocity.
• Own the hardening roadmap for tier-0 cloud infrastructure and access services, backed by rigorous, follow-the-sun on-call. Success is measured in eliminating classes of misconfiguration and exposure at the platform layer, not in shipping code for its own sake.
• Coach and mentor highly skilled tech leads and engineers as a "player-coach," leaning in at the lowest technical level on cloud hardening, identity, and secrets management problems, and lead the team to build the right durable controls.
• Partner cross-functionally with Core Infrastructure, Compute, Data, and other engineering platform teams to harden the shared cloud and access substrate that all of DoorDash, Wolt, and Deliveroo build on, and deliver bespoke, in-house services where vendored platform controls don't fit.
• Build and maintain high Operational Excellence (OE) practices for tier-0 security platforms with rigorous on-call rotations, clear escalation paths, and minimal downtime, since these systems are load-bearing for every other team's ability to ship and operate safely.
• Drive continuous hardening of AWS and GCP environments so insecure defaults are annihilated and prevented before they ever reach production.
• Influence and enable the secure and responsible adoption of AI tooling and agentic workflows from a platform hardening and access-control perspective.
We’re excited about you because…
• 12+ years of experience as a Security or Infrastructure Platform Engineer at an internet-scale organization, with 3+ years of demonstrated technical leadership leading teams building outcomes at global scale.
• Deep hands-on expertise hardening AWS and/or GCP at scale, including account structure, guardrails, workload and network posture, and golden image pipelines.
• Demonstrated