> Markdown version of [/jobs/ext/2710652-security-engineer-red-team](https://www.wearedevelopers.com/jobs/ext/2710652-security-engineer-red-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Red Team - **Company:** DOORDASH, INC. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $159,800.0 - $235,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Cyber Security, Python (Programming Language), Windows PowerShell, Phishing, Red Team (Cyber Security), Rust (Programming Language), Cloud Platform System, Mitre Att&ck, Malware, Kotlin, Multiplatform, Golang - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-red-team-doordash-usa-8074178 ## About the Role * 5+ years of experience in Red Teaming and Purple Teaming * You are passionate about offensive security and care about improving your craft every day * You think like an adversary. You have deep, experiential knowledge of APT and insider threat TTPs, not just theoretical familiarity * Experience partnering with cross-functional teams to secure diverse environments, providing feedback loops that articulate business risks and generate actionable intelligence * You've run full-scope operations across multi-platform and cloud environments, and you know how to build the malware and tooling to support them * Strong knowledge of one of Python, Golang, Rust, Kotlin, Java, or Powershell * Experience using and developing tooling, methodologies and scalable infrastructure to support red team engagements capabilities (e.g. command and control frameworks, phishing environment, exploits) * Experience with Command and Control (C2) frameworks * Experience with Defense Evasion to bypass security tooling (e.g. Endpoint Detection and Response) * Excellent understanding of information security operations related frameworks and standards (e.g., MITRE Att&ck) * Experience providing technical leadership and guidance, and thinking strategically and analytically to solve problems * Excellent communication, presentation, and stakeholder management skills * Engages with a people-first approach, is able to facilitate a conversation rather than dictate it, and is empathetic to divergent viewpoints ## Description The Senior Security Engineer, Red Team will be responsible for conducting threat intelligence-informed adversary emulations to simulate real-world cyber attacks and proactively identify security improvement opportunities in the DoorDash environment. This role will work closely with cross-functional teams across the company and assess the security posture of DoorDash's critical assets and products. This role operates with the necessary freedom and accountability to complete full-scope Red Team operations against any valuable objectives in the company, providing a crucial feedback loop for all efforts in upholding customer trust., * Plan and execute realistic adversary simulations using curated threat intelligence to assess security opportunities, and detection and response capabilities * Hunt for vulnerabilities across AI systems, payment infrastructure, autonomous delivery hardware, and emerging technologies before adversaries do * Exercise range of expertise to include cyber, insider, and fraud Red Team testing scenarios. * Build custom tools, exploits, and payloads tailored to DoorDash's unique and evolving tech stack * Partner with Blue Teams to escalate emerging threats and develop proactive detection or defensive strategies * Advise leadership on emerging threats and shape the security strategy for one of the world's most complex logistics platforms, We're committed to growing and empowering a more inclusive community within our company, industry, and cities. That's why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel. Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on "protected categories," we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce - people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non-discrimination. Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation. If you need any accommodations, please inform your recruiting contact upon initial connection. Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only We used Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provided Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound from August 21, 2023, through December 21, 2023. We resumed using Covey Scout for Inbound again on June 29, 2024, and ceased using Covey Scout for Inbound on April 30, 2026. ## Related Videos - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why Kotlin is the better Java and how you can start using it](https://www.wearedevelopers.com/videos/661-why-kotlin-is-the-better-java-and-how-you-can-start-using-it) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)