Enterprise Security Engineer at DoorDash USA.
About the role Enterprise Security serves DoorDash, Wolt, and Deliveroo as the central team responsible for employee-focused protection. We design secure-by-default controls and self-service tooling so that the safe option is also the simple option. Success requires close collaboration with IT, Legal, Privacy, and Engineering to safeguard people, devices, and data without impeding workflow. The role involves owning security operations and automation within a fast-paced, globally distributed environment that is expanding into AI-assisted workflows. You will be expected to act as a technical owner and a pragmatic enabler, ensuring security controls are understood, adopted, and continuously improved by the business. This position is critical in bridging the gap between risk management and delivering features that keep the business moving securely. You will be measured by your ability to reduce friction while increasing resilience across the enterprise technology landscape. The work demands curiosity, clear communication, and a bias toward action to solve complex problems at scale.
Key facts Location: United States - Remote Engagement: Full-time
What you\'ll do
- Execute operational security workflows for the enterprise identity and endpoint landscape across DoorDash, Wolt, and Deliveroo.
- Configure and maintain an enterprise security stack that includes endpoint detection and response, zero-trust access, identity-aware proxies, browser security, and data loss prevention.
- Author and iterate on automation scripts using Python or Go to streamline repetitive security tasks and accelerate incident response activities.
- Apply AI-assisted coding techniques to generate, review, and validate security tooling outputs before promoting changes into production environments.
- Monitor SaaS environments to detect and remediate shadow IT and OAuth token sprawl while enforcing secure-by-default configurations.
- Perform high-risk application reviews to identify weaknesses and recommend mitigations that align with business needs and regulatory expectations.
- Partner with IT, Legal, Privacy, and Engineering teams to coordinate change management and support infrastructure-as-code initiatives for secure deployments.
- Implement and manage mobile device security for macOS, Windows, and Linux endpoints to ensure consistent protection across all workforce devices.
- Leverage cloud expertise on major platforms such as AWS or GCP to implement and monitor security controls that scale globally.
- Contribute to security community efforts through internal documentation, knowledge sharing, and collaboration on open source or public tools where appropriate.
- Support participation in security audits, including ISO 27001 and SOC 2, by providing technical evidence and process insights.
- Evaluate and integrate specialized security platforms such as Tailscale, Google IAP, GitHub enterprise controls, Palo Alto Cortex, and Chrome Enterprise.
- Operate and tune SaaS Security Posture Management and CASB tools to maintain visibility and control over third-party integrations.
- Define and manage DLP controls, focusing on capabilities natively provided by major SaaS platforms to prevent data exfiltration.
Requirements
- Hold a Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience that demonstrates relevant knowledge.
- Possess 2 to 5 years of hands-on experience in security engineering, enterprise security, or IT security roles with a proven track record.
- Demonstrate hands-on administration of identity platforms, specifically Okta, including user lifecycle management and security policies.
- Show fluency in modern authentication and authorization protocols, including SAML, OAuth 2.0, OpenID Connect, and FIDO2.
- Have practical experience operating EDR/XDR platforms to detect and respond to threats across endpoints.
- Exhibit experience managing mobile device management for macOS, Windows, and Linux in enterprise environments.
- Hold demonstrated experience on at least one major cloud platform, such as AWS or GCP, including core services and security features.
- Write production-grade automation in Python or Go, with the ability to integrate scripts into existing operational workflows.
- Communicate effectively in writing to coordinate with cross-functional teams and document security procedures.
- Understand enterprise security concepts such as zero trust, least privilege, and secure-by-default design principles.
- Familiarity with infrastructure-as-code practices, using tools applied to security operations, is required for consistent and repeatable deployments.
- Have the ability to interpret security findings and translate them into actionable recommendations for technical and non-technical audiences.
- Maintain a strong attention to detail and the discipline to follow through on complex, multi-step security tasks in a fast-moving environment.
- Be comfortable working autonomously and collaboratively in a globally distributed team that spans multiple time zones.
Nice to have
- Hands-on work with platforms and tools such as Tailscale, Google IAP, GitHub enterprise controls, Palo Alto Cortex, or Chrome Enterprise.
- Exposure to SaaS Security Posture Management, CASB solutions, or OAuth-scope governance frameworks.
- Experience operating data loss prevention controls, particularly those natively provided by major SaaS platforms.
- Familiarity with infrastructure-as-code tools like Terraform when applied to security operations and compliance workflows.
- Experience supporting ISO 27001 or SOC 2 audit processes and contributing evidence for control assessments.
- Contributions to the security community through blog posts, conference talks, bug bounty participation, or open source projects.
- Relevant certifications such as CISSP Associate or GIAC, which demonstrate a commitment to professional growth in security.
Practical notes - Engagement: Full-time - Location: United States - Remote