
L5 Lead Security Operations Centre Specialist
Job description
About the role
The is a pivotal position within our global Information Security organization, driving the security posture of our mission to transform how people shop and eat. This role represents a unique opportunity to own the strategic direction and operational excellence of our Security Operations Centre (SOC) capabilities across DoorDash, Deliveroo, and Wolt. You will be responsible for shaping the security narrative through proactive defense, intelligent automation, and decisive incident leadership. The position requires a deep commitment to safeguarding our ecosystem, protecting the data of millions of customers, riders, and partners daily. You will act as the technical authority and operational leader for your shift, ensuring that security operations are resilient, efficient, and aligned with business objectives. This role is fundamental to our ability to innovate at speed while maintaining the highest standards of security and trust.
Key facts
What you'll do
- Lead a team of SOC specialists and analysts, balancing deep technical investigations with the total ownership of your assigned shift to ensure continuous coverage.
- Act as the primary decision-maker for critical security incidents, exercising ownership over escalations and outcomes while mentoring team members on performance and career development.
- Operate effectively within a 24/7 global security operations centre model, demonstrating reliability for scheduled night and weekend shifts to maintain our security posture.
- Lead the comprehensive triage and investigation of complex security alerts, including sophisticated phishing campaigns, malware infections, network-based attacks, security hygiene failures, and privacy-related incidents, adhering to strict service level agreements.
- Architect and lead the continuous improvement of operational documentation, processes, and playbooks to standardize responses and enhance team efficiency.
- Design, build, and manage autonomous AI-driven runbooks to automate and massively scale our alert triage and initial response capabilities.
- Lead the end-to-end incident response process for major events, ensuring thorough root cause analysis and the effective translation of lessons learned into concrete, continuous security improvements.
- Champion the design, development, and rigorous review of advanced threat-detection use-cases focused on identifying subtle signs of suspicious activity across our complex cloud environments.
- Synthesize intelligence from emerging threats and post-incident activity to actively feed into the broader risk framework of the organization.
- Provide expert support for wider security incident investigations by collaborating closely with Threat Intelligence and Incident Response & Digital Forensics specialists.
- Maintain a proactive stance by constantly researching and integrating current security trends, advisories, academic publications, and evolving threat intelligence into daily operations.
- Utilize metrics and key performance indicators not just for reporting but to drive strategic optimization of our security posture and identify areas for proactive investment.
- Partner with the team to develop, deliver, and refine engaging cybersecurity awareness programs for employees, placing a strong emphasis on secure incident reporting and the adoption of best-in-class security practices.
Requirements
- Possess 7-9 years of hands-on SOC experience, with a demonstrable history of acting as a technical lead and successfully managing shift operations in a high-pressure environment.
- Show proven experience in architecting and building robust threat detection capabilities within a fast-moving, cloud-centric organizational landscape.
- Bring hands-on, practical experience with core security technologies including AWS security configuration, Security Orchestration Automation and Response (SOAR) platforms, Endpoint Detection and Response / Extended Detection and Response (EDR/XDR) solutions, and Splunk for data analysis.
- Demonstrate practical experience in the full lifecycle of defensive security solutions, from ideation and configuration through to technical project management and implementation.
- Exhibit a steadfast commitment to continuous improvement, consistently leveraging direct feedback to elevate both personal capabilities and the overall performance of the security team.
- Operate as an exceptional collaborative team player, fostering a culture of knowledge-sharing and mutual support across the security function.
- Hold a working knowledge of critical security compliance standards and frameworks such as ISO 27001, the General Data Protection Regulation (GDPR), the Network and Information Systems 2 Directive (NIS2), and the Payment Card Industry Data Security Standard (PCI-DSS).
- Thrive in the ability to work effectively both as a self-driven individual contributor and as a collaborative team member, maintaining composure and clarity under the intense pressure of high-impact incidents.
- Excel in communication, possessing the capability to articulate complex technical details clearly and effectively to both technical security peers and non-technical stakeholders during and after significant incident activity.
- Demonstrate flexibility and coordination skills to work in close alignment with security teams based in the United States, the United Kingdom, and the European Union as operational requirements dictate.
Nice to have
- Preferred experience with specific security tooling or methodologies relevant to large-scale cloud platforms.
Practical notes
This role requires shift work, including nights and weekends, and may involve coordination with international teams.