Security Engineer, Insider Threat
Core
Conduct investigations into anomalous events and behaviors posing risk to the company, while designing detection capabilities to scale insider threat response.
Role type
Senior IC insider threat security engineer
Builds
Detection use cases, playbooks, and automated investigation workflows for the DoorDash delivery network
Domain
Cybersecurity / Insider Threat / Data Security
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Insider threat investigations, incident response, SIEM/SOAR platforms, UEBA, UAM, DLP tools, SQL querying, log parsing, scripting/automation, version control (Git), cross-functional collaboration
Preferred skills
Federal law enforcement experience, agentic/AI-assisted workflow development, training and awareness program design
Technologies
SIEM, SOAR, UEBA, UAM, DLP, SQL, Git
Responsibilities
Investigate anomalous activity for potential insider risk, develop detections to proactively identify similar behaviors at scale, create and maintain a use case library, establish standard operating procedures for investigation collaboration, prepare investigative reports for leadership, maintain chain-of-evidence and engage with external law enforcement
Seniority
Mid-Senior, hands-on IC