Enable job alerts via email!

Staff Security Engineer, Product Security

DoorDash

United States

Remote

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a leading company as a Staff Security Engineer in the Information Security team. You will protect customer applications and systems within a cloud environment, collaborating with engineering leaders to develop security strategies. This remote role offers the chance to work on challenging and rewarding projects, ensuring a safe application platform for users.

Qualifications

  • 8+ years of experience in security or product security engineering.
  • Proficiency in identifying and remediating OWASP top 10 vulnerabilities.
  • Experience managing bug bounty programs is a plus.

Responsibilities

  • Collaborate with engineering and security leaders to develop security strategies.
  • Implement security measures and services to protect the platform.
  • Conduct regular security assessments of applications.

Skills

Security Engineering
Analytical Skills
Communication

Tools

Python
Java
Golang

Job description

About the Team

Join us in building the world's most trusted on-demand logistics engine for delivery! We are assembling a team of talented individuals to secure and maintain a 24x7, global infrastructure system that powers DoorDash’s multi-sided marketplace involving consumers, merchants, and drivers.

About the Role

The Information Security team seeks a Staff Security Engineer, Product Security, to safeguard DoorDash’s platform within its cloud environment. You will be part of an inclusive, collaborative team dedicated to creating a safe and reliable application platform. Your role involves protecting all customer applications, systems, and business logic. It’s challenging but rewarding work!

This is a remote position reporting directly to the Senior Manager of the Product Security Engineering team.

Key Responsibilities
  • Collaborate with engineering and security leaders to develop security strategies for DoorDash’s platform.
  • Plan and execute a strategic security roadmap.
  • Implement security measures and services to protect the platform and applications.
  • Perform manual and automated code reviews to identify vulnerabilities in APIs, microservices, and mobile apps (Android and iOS).
  • Conduct regular security assessments of applications.
  • Define, document, and enforce security standards, guidelines, and procedures.
  • Provide security feedback during architectural and design reviews.
  • Manage the lifecycle of vulnerabilities from detection to remediation, including reporting and metrics.
  • Integrate security tools into the CI/CD pipeline.
  • Ensure applications in the cloud comply with security policies and standards, including segmentation and configuration.
  • Develop and enforce secure network and process controls for Kubernetes environments.
  • Create tools and automated tests to enhance security efficiency.
Qualifications
  • 8+ years of experience in security or product security engineering.
  • Strong understanding of authorization and authentication frameworks.
  • Hands-on experience in building and deploying secure microservices.
  • Proficiency in identifying and remediating OWASP top 10 vulnerabilities.
  • Interest in analyzing code, architecture, and design from a security perspective.
  • Proficiency in scripting languages (e.g., Python) and programming languages (e.g., Java); Golang experience is a plus.
  • Experience in security observability, attack path identification, and defense mechanisms.
  • Experience with CI/CD pipeline security management.
  • Knowledge of supply chain security (third-party, package integrity, etc.).
  • Experience in payments security or fintech is desirable.
  • Broad technical experience across application security in large environments.
  • Strong analytical, investigative, and root cause analysis skills.
  • Proven ability to solve complex systemic issues creatively.
  • Track record of improving security posture.
  • Excellent communication skills for explaining security concepts to diverse audiences.
  • Experience managing bug bounty programs is a plus.
  • Relevant industry certifications (e.g., GWEB, GSSP, SSP) are a plus.

We aim to fill this position by 7/6/2025.

Note: This role is remote, and applicants in NYC or associated with NYC offices should be aware of specific hiring tools and policies, including Covey Scout usage and nondiscrimination policies.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Software Product Security Engineer

Mindware INC

Remote

USD 110,000 - 234,000

6 days ago
Be an early applicant

Product Engineer II New New York City, New York

Garner Health Technology, Inc.

New York

Remote

USD 135,000 - 165,000

2 days ago
Be an early applicant

Product Engineer II

Garner Health

New York

Remote

USD 135,000 - 165,000

3 days ago
Be an early applicant

Staff Security Engineer, Product Security Risk & Metrics

GitLab

Remote

USD 90,000 - 150,000

11 days ago

FedRamp Product Security Engineer

Red Hat

District of Columbia

Remote

USD 105,000 - 170,000

7 days ago
Be an early applicant

Staff Software Engineer, Data Products

P2P

Remote

USD 120,000 - 180,000

7 days ago
Be an early applicant

Staff Product Security Engineer

DataDirect Networks

Remote

USD 100,000 - 150,000

10 days ago

FedRamp Product Security Engineer

Red Hat

Remote

USD 105,000 - 170,000

10 days ago

Product SecOps Engineer II (Sean)

Medtronic

Minneapolis

Remote

USD 96,000 - 146,000

21 days ago