Principal Engineer, Product Security
DoorDashAbout the role
About the Team
At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Security is integral to the success of the business, as we secure the data and protect the privacy of our business and various stakeholders. The Product Security team is responsible for ensuring the security of DoorDash’s platform. You will be a part of our inclusive, collaborative team responsible for building a safe and reliable application platform.
About the Role
The Information Security team is looking for a Principal Engineer, Product Security who will lead planning, development, and execution on Product Security initiatives which secure DoorDash’s platform. The Principal Engineer, Product Security should have a “builder mindset” and be responsible for becoming an expert at our business and solving unique security challenges as we launch new products across each of our business verticals. This role will provide strategic direction to more junior engineers and lead our Security Partnership model working closely with our Product and Engineering teams for each business vertical. This critical role is responsible for enhancing the organization's security posture by advising on security strategies and solutions to solve challenges facing each vertical and work with more junior engineers to ship them into the product.
You will report into the Head of Product Security, under the Chief Information Security Officer.
You’re excited about this opportunity because you will…
- Set and own strategic roadmaps for security partner pods and work directly with product, engineering and security leaders to enact security strategies for DoorDash’s platform.
- Prioritize customer experience and security design to prevent an adverse impact to the customers, merchants, and dashers from security flaws
- Advise and mentor other security engineers to build and deploy security measures and services to secure DoorDash platform and its applications across our verticals.
- Provide senior consultation and build solutions for complex security challenges impacting DoorDash Products balancing business needs with security objectives
- Be hands-on and perform manual and automated code reviews to identify vulnerabilities in APIs, microservices and mobile apps (Android and iOS).
- Conduct regular application security assessments.
- Define, document and implement security standards, guidelines and procedures for secure operations.
- As part of architectural and design review committees, provide actionable feedback in engineering design reviews.
- Manage the lifecycle of application vulnerabilities, from identification to remediation and reporting and metrics.
- Integrate and manage security tools into the CI/CD process.
- Ensure applications running within the cloud environment honor the requirements of information security policy and standards for segmentation and configuration.
- Develop and implement secure network and process controls for Kubernetes environments.
- Develop tools and automated tests for improving our Security efficiency.
We’re excited about you because…
- 10+ years of experience as a security or product security engineer
- Experience working with Global teams managing a diverse portfolio of products
- Experience partnering with engineering, product, fraud, and others to secure diverse environments
- Experience providing technical leadership and guidance, and thinking strategically and analytically to solve problems
- Excellent communication, presentation, and stakeholder management skills
- Lead with a people-first approach, able to facilitate a conversation rather than dictate it, and is empathetic to divergent viewpoints
- Expert understanding of authorization and authentication framework and technologies.
- Expert knowledge and hands on experience to build and deploy secured microservices.
- Hands on experience on understanding, identifying and remediating each OWASP top 10 vulnerabilities and similar.
- You are interested in analyzing code, architecture and design from a security perspective
- Well versed with scripting languages (e.g., python) and other programming languages (e.g., java). Golang experience is a plus.
- Experience in building asset inventory for security observability to identify attack paths and defense mechanisms.
- Experience with implementing and managing CI/CD pipeline security
- Knowledge of supply chain security (third party, artifactory, package integrity, etc.)
- Experience in building security solutions for products that need to maintain HIPAA and PCI or other fintech products
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s