Detection Engineer, Protective Services

DoorDash, Inc

Confirmed live today High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$130,600–$192,000 / yr
Posted
12 days ago
Freshness
Confirmed live today

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $180k
This role $161k
$120k $231k
below market most similar roles pay here above market

This role pays less than 62% of similar roles. Most pay $145,000–$216,000 — the blue band above. At the midpoint, this role pays about $161k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About DoorDash, Inc

DoorDash, Inc. is an American company operating online food ordering and food delivery. It trades under the symbol DASH. With a 56% market share, DoorDash is the largest food delivery platform in the United States.

DoorDash, Inc currently has 83 open roles on FindRole.

Listed pay typically runs $159,800–$235,000 across 82 roles with salary data.

Most-posted roles

View all roles at DoorDash, Inc

At a glance

TL;DR · Detection Engineer, Protective Services

The Detection Engineer, Protective Services joins the Global Safety and Security team to identify threats against executives, their families, and supporting operations. This role involves building technical capabilities to detect risks across identities, endpoints, cloud environments, marketplace activity, physical access events, and open-source information. You will build, test, deploy, and tune production detections and supporting pipelines using source-controlled engineering practices. Key responsibilities include correlating signals from enterprise telemetry and OSINT to separate meaningful risk from noise. You will use SQL, Python, or Go to write maintainable code and may utilize machine learning or LLM-based techniques. The role requires applying statistical methods and frameworks like MITRE ATT&CK or D3FEND to solve complex security problems, ensuring timely, actionable intelligence is provided to the Protective Services team.

What you'll do

  • Build, test, deploy, and maintain production detections and supporting pipelines using source-controlled engineering practices.
  • Translate threat intelligence and observed behaviors into production detections that surface meaningful risk and provide actionable context.
  • Correlate signals across enterprise telemetry, marketplace activity, physical security events, and open-source information to identify threats.
  • Apply rules, statistical methods, machine learning, and LLM-based techniques to improve detection quality and prioritization.
  • Investigate detections by querying data, validating hypotheses, and assessing confidence and potential impact in partnership with Protective Services.
  • Continuously improve detection logic, tooling, and workflows based on outcomes from investigations and false positives.
  • Contribute to technical reviews, documentation, and automation to strengthen the reliability of the detection function.
  • Participate in an on-call rotation and support major investigations by communicating the limitations of available signals.

What we're looking for

  • 3+ years of experience in detection engineering, threat hunting, incident response, security operations engineering, technical threat intelligence, or software engineering.
  • Experience contributing to production detection pipelines using source control, testing, review, deployment, and monitoring practices.
  • Proficiency in SQL or a security query language and the ability to write maintainable code in Python, Go, or another relevant language.
  • Strong analytical skills to explore unfamiliar datasets, troubleshoot across systems, and turn threat information into testable detection hypotheses.
  • Experience triaging alerts, correlating signals across data sources, and communicating evidence-based findings.
  • Experience building detections or conducting investigations using security, behavioral, or other relevant telemetry.
  • Familiarity with frameworks such as MITRE ATT&CK or D3FEND for organizing detection coverage and identifying gaps.
  • Bachelor’s degree or equivalent practical experience.
  • Experience with Snowflake, Cortex, or Google SecOps (preferred).

More like this

Similar roles

Senior Detection Engineer, Protective Services

DoorDash, Inc

Remote (Hartford, CT) 4 days ago $159,800–$235,000
Python Go SQL SPL KQL Detection-as-Code Snowflake Cortex Google SecOps MITRE ATT&CK D3FEND Machine Learning OSINT Distributed Systems
7+ yrs exp Remote

Senior Detection Engineer

DoorDash, Inc

Remote 51 days ago $159,800–$235,000
Detection Engineering Python Go SQL SPL KQL Snowflake Google SecOps Cortex MITRE ATT&CK D3FEND Detection-as-Code Threat Intelligence Risk-based Analytics Distributed Systems
7+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote (Ontario, Canada) +3 47 days ago $196,000–$207,000
Detection-as-Code SOAR Python Golang AWS Azure GCP CI/CD Threat Hunting TTPs MacOS Version Control Machine Learning Zero Trust
6+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote 47 days ago $230,000–$242,500
Detection-as-Code SOAR Python Golang AWS Azure GCP CI/CD Threat Hunting TTPs MacOS Version Control Machine Learning Cloud-Native
6+ yrs exp Remote

Senior Security Engineer, Detection Engineering

Nvidia

Remote (CA) +2 31 days ago
Splunk Microsoft Sentinel Defender CrowdStrike Python SQL KQL SPL Git CI/CD Kubernetes Detection-as-Code SIEM Threat Hunting Incident Response Cloud Security Identity Telemetry Endpoint Data
8+ yrs exp Remote