Skip to main content

Staff Security Engineer, GSOC

Delivery Hero

BerlinOn-siteFull-Time3d ago

Description

Company Description

As the world’s pioneering local delivery platform, our mission is to deliver an amazing experience, fast, easy, and to your door. We operate in around 65 countries worldwide powered by tech, designed by people. As one of Europe’s largest tech platforms, headquartered in Berlin, Germany. Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of the MDAX stock market index. We enable creative minds to deliver solutions that create impact within our ecosystem. We move fast, take action and adapt. No matter where you're from or what you believe in, we build, we deliver, we lead. We are Delivery Hero.

Job Description

We are looking for a Staff Security Engineer, Global SOC (all genders) to join the Security Engineering domain on our journey to always deliver amazing experiences.

As a Staff Security Engineer within our Global SOC, you will be the technical anchor for our Security Monitoring and Threat Detection capabilities across a high-transaction food delivery and quick-commerce platform handling millions of daily orders. As a business spanning logistics, e-commerce, and FinTech, our environment is highly regulated, in this role you will build and govern the systems that ensure rapid, high-fidelity threat detection in compliance with global frameworks.

You will operate at the intersection of a hands-on technical practitioner and a strategic engineering leader. We are looking for someone with a strong 'builder mindset' who views threat detection as a software engineering discipline. Instead of staring at dashboards, you will architect and define our log pipelines, SIEM & SOAR infrastructure, and implement Detection Engineering methodologies as code. You will develop threat detection use cases, integrate Cyber Threat Intelligence, and build the automated triage workflows that seamlessly escalate validated, high-severity incidents to our CSIRT team for final containment. Ultimately, you will provide a robust, scalable detection platform globally.

Your mission:

  • Detection & Platform Architecture: Architect, implement, strengthen and scale the Security Log Management (on AWS), SIEM and SOAR (Google SecOps) infrastructure. You will own the log ingestion pipelines, ensuring high availability, performance, and optimal retention based on business requirements.
  • Engineering-Led Detection & Automation: Architect, build, and maintain log ingestion pipelines, detection rules (e.g., YARA-L), API integrations, and SOAR workflows & Plugins. You will lead the charge in treating "Detection as Code", ensuring all alerts and automated enrichments are version-controlled, tested, and deployed through CI/CD pipelines.
  • Cyber Threat Intelligence: Establish and integrate CTI capabilities to drive an intelligence-led detection strategy. You will map detections to the MITRE ATT&CK framework and proactively hunt for threats specific to Delivery Hero and its entities.
  • Triage & Escalation Engineering: Design high-fidelity alert workflows. For all security events, you will ensure our automated systems gather, enrich, and seamlessly conduct the right response and containment workflow.
  • Stakeholder Communication: Serve as the primary interface between the Global SOC and Engineering teams, CISOs, and the CSIRT team, translating complex detection & response architectures, log ingestion pipeline requirements into clear technical and business terms.
  • Mentorship & Leadership: Act as a hands-on technical leader and role model, actively mentoring detection engineers and regional security teams to raise the overall technical bar and promote a collective security mindset.
  • Metrics & Strategic Visibility: Maintain a Data-Driven Strategic mindset to define, track, and improve core operational metrics (Log Pipeline Health, Alert Fidelity, True Positive Rates, MTTD) to identify systemic gaps and propose strategic security investments.
  • On-Call: Participate in an

More jobs in Berlin