368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$74k – $186k per year (Estimated)
Location
Remote/Hybrid (Berlin, Germany)
Seniority
Senior · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Delivery Hero is a leading global local delivery platform, headquartered in Berlin, that connects consumers with restaurants, grocery stores, and local retailers. Founded in 2011, the company operates across dozens of countries, providing on-demand food delivery and pioneering "quick commerce" services for household essentials. Through its extensive international network and advanced logistics technology, it facilitates millions of daily deliveries while aiming to provide a fast and seamless experience for customers worldwide.

As the world’s pioneering local delivery platform, our mission is to deliver an amazing experience, fast, easy, and to your door. We operate in around 65 countries worldwide powered by tech, designed by people. As one of Europe’s largest tech platforms, headquartered in Berlin, Germany. Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of the MDAX stock market index. We enable creative minds to deliver solutions that create impact within our ecosystem. We move fast, take action and adapt. No matter where you're from or what you believe in, we build, we deliver, we lead. We are Delivery Hero.

We are looking for a Staff Security Engineer, Global SOC (all genders) to join the Security Engineering domain on our journey to always deliver amazing experiences.

As a Staff Security Engineer within our Global SOC, you will be the technical anchor for our Security Monitoring and Threat Detection capabilities across a high-transaction food delivery and quick-commerce platform handling millions of daily orders. As a business spanning logistics, e-commerce, and FinTech, our environment is highly regulated, in this role you will build and govern the systems that ensure rapid, high-fidelity threat detection in compliance with global frameworks.

You will operate at the intersection of a hands-on technical practitioner and a strategic engineering leader. We are looking for someone with a strong 'builder mindset' who views threat detection as a software engineering discipline. Instead of staring at dashboards, you will architect and define our log pipelines, SIEM & SOAR infrastructure, and implement Detection Engineering methodologies as code. You will develop threat detection use cases, integrate Cyber Threat Intelligence, and build the automated triage workflows that seamlessly escalate validated, high-severity incidents to our CSIRT team for final containment. Ultimately, you will provide a robust, scalable detection platform globally.

Your mission:

  • Detection & Platform Architecture: Architect, implement, strengthen and scale the Security Log Management (on AWS), SIEM and SOAR (Google SecOps) infrastructure. You will own the log ingestion pipelines, ensuring high availability, performance, and optimal retention based on business requirements.

  • Engineering-Led Detection & Automation: Architect, build, and maintain log ingestion pipelines, detection rules (e.g., YARA-L), API integrations, and SOAR workflows & Plugins. You will lead the charge in treating "Detection as Code", ensuring all alerts and automated enrichments are version-controlled, tested, and deployed through CI/CD pipelines.

  • Cyber Threat Intelligence: Establish and integrate CTI capabilities to drive an intelligence-led detection strategy. You will map detections to the MITRE ATT&CK framework and proactively hunt for threats specific to Delivery Hero and its entities.

  • Triage & Escalation Engineering: Design high-fidelity alert workflows. For all security events, you will ensure our automated systems gather, enrich, and seamlessly conduct the right response and containment workflow.

  • Stakeholder Communication: Serve as the primary interface between the Global SOC and Engineering teams, CISOs, and the CSIRT team, translating complex detection & response architectures, log ingestion pipeline requirements into clear technical and business terms.

  • Mentorship & Leadership: Act as a hands-on technical leader and role model, actively mentoring detection engineers and regional security teams to raise the overall technical bar and promote a collective security mindset.

  • Metrics & Strategic Visibility: Maintain a Data-Driven Strategic mindset to define, track, and improve core operational metrics (Log Pipeline Health, Alert Fidelity, True Positive Rates, MTTD) to identify systemic gaps and propose strategic security investments.

  • On-Call: Participate in an on-call rotation focused on maintaining critical SIEM/SOAR infrastructure health, handling high-severity alert triage, and executing emergency escalations to CSIRT.

What you need to be successful:

  • 7+ years of broad cybersecurity experience with a deep understanding of core security fundamentals, coupled with 5+ years of dedicated experience in a SOC or Threat Detection Engineering environment.

  • Security Tool Mastery: Deep operational and architectural expertise with modern SIEM & SOAR platforms (specifically Google SecOps / Chronicle), EDR and Cloud infrastructure (AWS/GCP),

  • Engineering Skills: Proven experience utilizing Git/GitHub, CI/CD pipelines, to deploy rules, manage infrastructure and automation as code.

  • CTI & Triage Workflows: Strong background in operationalizing Cyber Threat Intelligence and building scalable alert triage processes that reduce false positives and prevent alert fatigue.

  • Strategic Leadership: An exceptional communicator with the ability to influence cross-functional stakeholders (Regional Security Teams, Platform Engineering) and simplify complex systems across domains without requiring formal authority.

  • Advanced Threat Detection (Cloud, Identity & EDR): Proven deep operational experience triaging alerts and building high fidelity detections across public cloud environments (AWS/GCP), modern Identity Providers (e.g., Okta, Entra ID, Google Workspace), and EDR platforms (e.g., CrowdStrike, SentinelOne, Defender).

  • AI & Next-Gen Tooling: Experience integrating AI/LLM capabilities and MCP (Model Context Protocol) usage into Threat Detection and SOAR for automated alert triage, payload analysis, or data enrichment (highly regarded skill).

Nice to have:

  • Advanced Cyber Threat Intelligence: Experience building threat intel programs, managing intelligence platforms (e.g., MISP), and translating raw IOCs/TTPs into high-fidelity detection logic.

  • Regulated Environment Expertise: Deep operational understanding of global cybersecurity and privacy frameworks (e.g., PCI-DSS, GDPR, NIS2, DORA, MAS TRM). You know how to implement logging, retention, and audit capabilities that meet strict regulatory compliance requirements.

  • Relevant Technical Certifications: Active or in-progress industry-recognized technical certifications focused on security engineering, cloud architecture, or threat detection (e.g., AWS Certified Security/Solutions Architect, GCIA/GCDA/GMON, CISSP).

Ensuring you and all our Heroes are looked after, happy, and healthy is always on the menu. Because if you’re in good shape, then we’re in good shape.

  • Make the most of our hybrid working model and join the team for face-to-face connection and collaboration in our beautiful Berlin campus 2 days a week

  • We offer 27 days holiday with an extra day on 2nd and 3rd year of service

  • We will support you in developing yourself and your career growth opportunities: 1.000 € Educational Budget, Language Courses, Parental Support and access to the Udemy Business platform to explore a variety of online courses.

  • Get moving and release those wonderful, mind-boosting endorphins: Health Checkups, Meditation, Gym & Bicycle Subsidy

  • Cash. Dough. Cheddar. Whatever you call it, we’ll help you with it: Employee Share Purchase Plan, Sabbatical Bank, Public Transportation Ticket Discount, Life & Accident Insurance, Corporate Pension Plan

  • The power of getting together over some food is unrivaled. Here are a few ways to help you do that. All the yum: Digital Meal Vouchers, Food Vouchers, Corporate Discounts. Courses.

  • Wondering what relocating to Berlin is like? In this article, we’ve put together 10 things you should know about moving to Berlin and how Delivery Hero can support you. You can also visit our relocation hub and check out more information about moving to Berlin.

  • Ready to prepare for your interview? Check out the list of the 5 most common interview questions and answers created in collaboration with our recruiters.

Ready to join our team? If you’re excited to grow, collaborate and be part of the world’s leading delivery platform, we’d love to hear from you. Apply today!

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience. Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience-just let us know with an email to our Inclusion Officer at [email protected] it in your application.

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience. Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience-just let us know with an email to our Inclusion Officer at [email protected].

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience. Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience-just let us know with an email to our Inclusion Officer at [email protected].

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Berlin
In office • Internship • 1+ year exp • Bachelor's Degree • Farmington Hills
Python
Rust
TypeScript
AI/ML
Time Series Forecasting
DevOps
AWS
CI/CD
Git
gRPC
IoT
MQTT
Apply
$25k – $60k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Chennai
Java
PowerShell
Python
TypeScript
JavaScript
Java
Spring Boot
Databases
Amazon Redshift
DynamoDB
Frontend
Angular
DevOps
Amazon EC2
Amazon EKS
Ansible
ArgoCD
AWS
AWS Lambda
Azure
Azure DevOps
Bicep
Chef
CI/CD
CloudFormation
Configuration Management
Docker
GCP
GitLab CI
Jenkins
Kubernetes
Platform Engineering
Puppet
Terraform
Amazon S3
GitLab
IAM
Apply
$45k – $114k per year (Estimated) • Remote • Full-Time • São Paulo • Vitoria-Gasteiz • Fortaleza • Rio de Janeiro • Recife
DevOps
AWS
Azure
Azure DevOps
Bicep
CI/CD
CloudFormation
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
IAM
Incident Management
Jenkins
Kubernetes
Terraform
Apply
$76k – $165k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Canada
PowerShell
SQL
Databases
MS SQL
MySQL
Oracle
PostgreSQL
DevOps
AWS
Azure
CI/CD
Analytics
ETL/ELT
Apply
$120k – $240k per year (Estimated) • Equity • Remote/Hybrid • 5+ years exp • New York
C#
C++
Go
JavaScript
TypeScript
Frontend
React.js
Redux
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
FedRAMP
Apply
$31k – $88k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Barcelona
Python
SQL
AI/ML
Model Context Protocol
DevOps
GCP
Git
GitHub
Management
n8n
Apply
Remote/Hybrid • Full-Time • Budapest
Apply
$73k – $146k per year (Estimated) • Equity • In office • Full-Time • Berlin
Java
Kotlin
Java
Hibernate
Spring Boot
Mobile
JUnit
DevOps
CI/CD
Apply
$147k – $289k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
Web3
Rollup
Apply
$90k – $199k per year (Estimated) • Equity • In office • Full-Time • Berlin
Java
Kotlin
Databases
Apache Kafka
PostgreSQL
DevOps
CI/CD
Cybersecurity
PCI DSS
Apply
Product Engineer 4 hours ago
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
TypeScript
JavaScript
AI/ML
AI Agents
Human-in-the-Loop
Frontend
React.js
Tailwind CSS
Apply
Backend Engineer 4 hours ago
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
TypeScript
Node JS
JavaScript
Node JS
Nest.JS
Prisma
Databases
PostgreSQL
DevOps
Pulumi
Terraform
Apply
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
Node JS
TypeScript
JavaScript
Node JS
Nest.JS
Prisma
Databases
PostgreSQL
Frontend
React.js
Apply
$81k – $178k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Berlin
Design
Adobe Photoshop
Figma
Apply
$73k – $146k per year (Estimated) • Equity • In office • Full-Time • Berlin
Java
Kotlin
Java
Hibernate
Spring Boot
Mobile
JUnit
DevOps
CI/CD
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.