Remote Job Description

The Information Security team is looking for an Application Security Engineer to work on securing DoorDash’s products running within its cloud computing environment. You will be a part of our inclusive, collaborative team responsible for building a safe and reliable delivery network. On the Security team we need to protect all of our customers, as well as the logistics engine itself. It’s no simple task, but it wouldn’t be interesting if it was!

About the Team

Come help us build the world's most trusted on-demand, logistics engine for delivery! We're building a team of great minds to help us secure and maintain a 24x7, no downtime, global infrastructure system that powers DoorDash’s multi-sided marketplace of consumers, merchants, and drivers.

You're excited about this opportunity because you will…

  • Work directly with engineering and security leaders to enact security strategies for DoorDash’s applications.
  • Be hands-on and perform manual and automated code reviews to identify vulnerabilities in APIs, microservices and mobile apps (Android and iOS).
  • Conduct regular application security assessments.
  • Define, document and implement security standards, guidelines and procedures for secure operations.
  • As part of architectural and design review committees, provide actionable feedback in engineering design reviews.
  • Manage the lifecycle of application vulnerabilities, from identification to remediation and reporting and metrics.
  • Integrate and manage security tools into the CI/CD process.
  • Ensure applications running within the cloud environment honor the requirements of information security policy and standards for segmentation and configuration.
  • Develop and implement secure network and process controls for Kubernetes environments.
  • Manage the lifecycle of application vulnerabilities, from identification to remediation and reporting and metrics.
  • Develop tools and automated tests for improving our Security efficiency.
We're excited about you because… 

  • 5+ years of experience as an application engineer or an information security discipline.
  • Deep understanding of each OWASP top 10 vulnerability, microservices security and design.
  • You are interested in analyzing code, architecture and design from a security perspective
  • Well versed with scripting languages (e.g., python) and other programming languages (e.g., java). Kotlin experience is a plus.
  • Experience with implementing and managing CI/CD pipeline security
  • Breadth of technical experience across various application security areas running in large production environments.
  • Exceptional analytical and investigative abilities with hands-on experience leading root cause analysis.
  • Experience solving complex, systemic issues that require creative thinking and solutions.
  • Demonstrated track record of driving improvements to a company’s security posture.
  • Excellent verbal and written communication skills - you can explain security design with respect to cloud infrastructure to security and engineering personnel. 
  • Internal Bug Bounty program management experience is a plus. 
  • GWEB, GSSP, SSP or other industry certifications are a plus.
About DoorDash

At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started with door-to-door delivery, and we are looking for team members who can help us go from a company that is known for delivering food to a company that people turn to for any and all goods.

DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more.