Senior Corporate Security Engineer
Security Engineer · Senior · Full Time
Opens Deliveroo's application page
Role
What you'll do.
As a Senior Corporate Security Engineer at Deliveroo, you'll lead the design and operation of enterprise security controls protecting internal networks, workforce identities, endpoints, and corporate systems across global operations spanning US, EU, and APAC regions. This role focuses on Identity and Access Management (IAM), Endpoint Detection and Response (EDR), network security, logging and detection engineering, and secure SaaS enablement, requiring deep expertise in zero-trust architectures, modern authentication standards, and security automation. You'll operate with high autonomy, making architectural decisions and delivering complex security initiatives end-to-end while balancing risk reduction with employee productivity.
Responsibilities
- Architecture & Control Implementation: Design, deploy, and maintain core corporate security controls including phishing-resistant multi-factor authentication (MFA), Just-In-Time (JIT) access management, strict role-based access control (RBAC), zero-trust network architectures, device and identity bound proofing mechanisms, and modern network isolation strategies. Lead the technical implementation of these controls to reduce attack surface and enforce principle of least privilege across the organization.
- Tooling Ownership & Platform Management: Serve as the technical owner for a broad suite of corporate security systems including identity platforms, endpoint detection and response (EDR), data loss prevention (DLP), and security information and event management (SIEM) tools. Manage deployments, configurations, API integrations, and lifecycle maintenance for security tools across the corporate environment, ensuring optimal performance and security posture.
- Technical Leadership & Strategic Direction: Lead and implement the technical strategy for endpoint device trust, data loss prevention, intellectual property storage, SaaS application security, and wider corporate security technical controls. Define architectural decisions, establish technical standards aligned to CIS Critical Security Controls and NIST Cybersecurity Framework, and drive maturation of security capabilities across the organization.
- Security Automation & Engineering: Write production-quality automation scripts and build tools to streamline security workflows, incident response tasks, and audit evidence collection for compliance and regulatory requirements. Leverage infrastructure-as-code practices to automate security control deployment and configuration management, reducing manual operational overhead.
- Cross-Functional Collaboration & Integration: Partner with IT operations, business operations, legal, privacy, and engineering teams to integrate security tools and practices into everyday organizational workflows. Guide non-security teams through adoption of secure baselines such as CIS Benchmarks, ensure compliance with recognized security frameworks, and embed security-by-default principles across the business.
- Technical Mentorship & Team Development: Mentor junior and mid-level security engineers, cultivate technical excellence within the security team, and establish engineering best practices. Communicate complex security concepts clearly to non-technical stakeholders, improve team engineering standards, and foster a culture of continuous learning and security awareness.
- Incident Response & Detection Engineering: Lead incident response activities and implement detection engineering practices using SIEM and SOAR platforms. Tune detection logic, develop playbooks, and establish logging strategies to identify and respond to security threats effectively across corporate systems and endpoints.
- Vulnerability & Patch Management: Establish and oversee vulnerability management programs and patch governance processes. Coordinate vulnerability remediation efforts, manage patch deployment cycles across diverse environments including cloud platforms, and ensure systems remain protected against known threats.
Qualifications
What we look for.
Technical
Identity and Access Management (IAM) Administration
Hands-on experience administering enterprise IAM platforms such as Okta, GoogleWorkspace, or similar solutions. Proficiency in configuring identity providers, managing user provisioning and deprovisioning, implementing access policies, and integrating IAM systems with corporate applications and cloud infrastructure.
GoogleWorkspace Platform Expertise
Deep, practical hands-on experience with GoogleWorkspace products including Gmail, Drive, Docs, Meet, and associated security controls. Proficiency in administration, user management, security policies, data loss prevention configuration, and integration with third-party security tools.
Cloud Platform Administration
Practical hands-on experience with major cloud platforms, particularly Amazon Web Services (AWS) and Google Cloud Platform (GCP). Ability to configure cloud security controls, manage IAM roles and policies, deploy infrastructure securely, and understand cloud security best practices and compliance implications.
Infrastructure-as-Code (IaC)
Relevant and practical experience with Infrastructure-as-Code tools such as Terraform, CloudFormation, or Ansible. Ability to define, version control, and automate infrastructure deployment and configuration management, particularly for security controls and corporate systems.
Modern Authentication Standards
Experience implementing and managing modern authentication standards including FIDO2, WebAuthn, SAML, OAuth 2.0, and OpenID Connect. Understanding of passwordless authentication, multi-factor authentication mechanisms, and best practices for secure identity verification and session management.
Endpoint Security & Device Management
Practical hands-on experience securing macOS, Windows, and Linux endpoints using mobile device management (MDM) platforms and endpoint detection and response (EDR) or extended detection and response (XDR) tooling. Ability to deploy endpoint security configurations, monitor device compliance, and respond to endpoint-level security incidents.
SIEM & SOAR Operations
Experience operating Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) platforms. Proficiency in tuning detection logic, creating monitoring rules, developing response playbooks, and correlating security events to identify threats and facilitate incident response.
Vulnerability Management & Patch Governance
Practical experience implementing vulnerability management programs and patch governance processes. Understanding of vulnerability scanning, risk assessment methodologies, patch deployment strategies, and remediation workflows across diverse infrastructure including on-premises and cloud environments.
Production-Quality Scripting & Automation
Ability to write production-quality automation scripts in languages such as Python, Bash, PowerShell, or Go. Experience building tools for security automation, incident response orchestration, audit evidence collection, and integration between security platforms and corporate systems.
Zero-Trust Architecture & Network Security
Understanding and practical implementation experience with zero-trust security models, network segmentation, and modern network isolation techniques. Knowledge of secure access service edge (SASE), software-defined perimeter concepts, and network security controls including firewalls, proxies, and network access controls.
Education
Bachelor's Degree in Computer Science, Cybersecurity, or Information Technology
Formal education in Computer Science, Cybersecurity, Information Technology, or related field. Alternatively, equivalent practical experience in security engineering, systems administration, or related technical disciplines can substitute for formal degree requirements.
Experience
5+ Years Security Engineering Experience
Minimum five years of hands-on experience in Security Engineering, Corporate Security, Detection and Response, or related cybersecurity field. Experience should demonstrate progressive responsibility, technical depth, and successful delivery of complex security initiatives across enterprise environments.
Cross-Functional Technical Leadership
Demonstrated experience leading cross-functional technical initiatives involving coordination with IT operations, business teams, security teams, and third-party vendors. Proven ability to align technical solutions with business objectives and drive adoption across diverse stakeholder groups.
Enterprise Security Operations
Background in operating and maintaining security controls, platforms, and tools in enterprise environments. Experience managing global security operations, supporting multiple geographic regions, and implementing security best practices at scale across diverse organizational structures.
Skills
Required
IAM Platform Administration
Okta, GoogleWorkspace, Azure AD, or similar enterprise identity platforms
Endpoint Detection & Response (EDR)
Hands-on configuration and management of EDR/XDR solutions for security monitoring
Cloud Security (AWS/GCP)
Practical experience securing cloud infrastructure and managing cloud security controls
SIEM/SOAR Platforms
Splunk, Datadog, Elastic, or other SIEM/SOAR tools for logging and detection engineering
Authentication Technologies
FIDO2, WebAuthn, SAML, OAuth 2.0, OpenID Connect implementation and management
Infrastructure-as-Code
Terraform, CloudFormation, Ansible, or other IaC tools for automation and standardization
Security Scripting & Automation
Python, Bash, PowerShell scripting for security workflows and incident response automation
Device Management & MDM
Mobile device management and endpoint configuration for macOS, Windows, and Linux systems
Vulnerability Management
Vulnerability scanning tools, patch management, and risk assessment methodologies
Zero-Trust Architecture
Understanding and implementation of zero-trust security models and network segmentation
Preferred
SASE / Zero Trust Network Access
Nice to haveExperience implementing Secure Access Service Edge (SASE) or zero-trust network access platforms for modern corporate security
Container & Orchestration Security
Nice to haveHands-on experience deploying and securing applications in Kubernetes (K8s) and Docker container environments
Data Loss Prevention (DLP)
Nice to haveImplementation and management of DLP solutions for protecting sensitive corporate data and intellectual property
Advanced Detection Engineering
Nice to haveExpertise in developing sophisticated detection rules, threat hunting, and SOAR playbook development for advanced incident response
Compliance & Audit Support
Nice to haveExperience supporting ISO 27001 or SOC 2 audits, demonstrating knowledge of security compliance frameworks and audit evidence collection
Professional Security Certifications
Nice to haveIndustry-recognized certifications such as CISSP, CISM, GIAC, or CEH demonstrating advanced security knowledge and continuous professional development
SaaS Security Governance
Nice to haveExperience implementing security controls and governance for SaaS application environments, including access management and data protection
API Security
Nice to haveUnderstanding of API security best practices, secure API design, and integration security for platform-to-platform communications
Compensation
Pay and benefits.
Base·GBP 120,000 – 180,000
Full posting
Original listing.
Why Deliveroo
Our mission is to transform the way you shop and eat, bringing the neighbourhood to your door by connecting consumers, restaurants, shops and riders. We are transforming the way the world eats and shops by making access to food and products more convenient and enjoyable. We give people the opportunity to buy what they want, as they want it, when and where they want it.
We are a technology-driven company at the forefront of the most rapidly expanding industry in the world. We are still a small team, making a very large impact, looking to answer some of the most interesting questions out there. We move fast, value autonomy and ownership, and we are always looking for new ideas.
About the Role
As a Senior Corporate Security Engineer, you will lead the design and operation of security controls that protect our internal networks, workforce identities, endpoints and corporate systems. You will be working globally with security teams across US, EU and APAC, delivering against our goals and objectives - reducing risk and maturing controls.
As a Senior, you will operate with a high degree of autonomy. You will define technical direction, make architectural decisions, and deliver complex security initiatives end-to-end. You will be expected to balance risk reduction with usability, ensuring controls are robust without impeding employee productivity.
This role focuses on Identity and Access Management (IAM), Endpoint security (EDR), Network Security, logging and detection engineering, and secure SaaS enablement. You will work closely with IT, Legal, Privacy, Engineering and business stakeholders to embed security as a default practice across the organisation.
Security controls will be aligned to recognised frameworks such as the CIS Critical Security Controls and the NIST Cybersecurity Framework (CSF).
Key Responsibilities
Architecture & Control Implementation: Design, deploy, and maintain core corporate security controls, including phishing-resistant MFA, Just-In-Time (JIT) access, strict role-based access control (RBAC), zero-trust architectures, device and identity bound proofing and modern network isolation.
Tooling Ownership: Serve as the technical owner for a broad suite of corporate security systems, managing deployments, configurations, and API integrations for tools across the corporate environment.
Technical Leadership: Lead and implement the technical strategy for Endpoint Device trust, Data Loss Prevention, Intellectual property storage, and SaaS application security. Alongside wider corporate security technical controls.
Automation & Engineering: Write scripts and build tools to automate security workflows, incident response tasks, and audit evidence collection for compliance.
Cross-Functional Collaboration: Work with IT and business operations to integrate security tools into everyday workflows. Guide non-security teams to adopt secure baselines (e.g., CIS Benchmarks) as standard practice.
Mentorship: Mentor junior and mid-level engineers, explain technical concepts clearly to non-technical staff, and help improve the team's engineering standards.
Minimum Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
5+ years’ experience in Security Engineering, Corporate Security, Detection & Response, or a related field.
Hands-on experience administering IAM platforms (e.g. Okta, GoogleWorkspace).
Deep hands-on experience with GoogleWorkspace products
Practical hands-on experience with Cloud platforms (e.g AWS, GCP)
Relevant and practical experience with Infrastructure-as-code (e.g Terraform)
Experience implementing modern authentication standards (FIDO2, WebAuthn, SAML, OAuth 2.0, OpenID Connect).
Practical experience securing macOS, Windows and Linux endpoints using MDM and EDR/XDR tooling.
Experience operating SIEM and/or SOAR platforms and tuning detection logic.
Experience with vulnerability management and patch governance.
Ability to write production-quality automation scripts.
Demonstrated experience leading cross-functional technical initiatives.
Desirable Skills
Experience with SASE or Zero Trust Network Access platforms.
Hands on experience deploying applications into K8 and Docker environments
Data Loss Prevention (DLP) and SaaS security governance.
Advanced detection engineering or SOAR playbook development.
Experience supporting ISO 27001 or SOC 2 audits.
Relevant certifications (e.g. CISSP, CISM, GIAC).
Workplace & Benefits
At Deliveroo we know that people are the heart of the business and we prioritise their welfare. Benefits differ by country, but we offer many benefits in areas including healthcare, well-being, parental leave, pensions, and generous annual leave allowances, including time off to support a charitable cause of your choice. Benefits are country-specific, please ask your recruiter for more information.
Diversity
At Deliveroo, we believe a great workplace is one that represents the world we live in and how beautifully diverse it can be. That means we have no judgement when it comes to any one of the things that make you who you are - your gender, race, sexuality, religion or a secret aversion to coriander. All you need is a passion for (most) food and a desire to be part of one of the fastest-growing businesses in a rapidly growing industry.
We are committed to diversity, equity and inclusion in all aspects of our hiring process. We recognise that some candidates may require adjustments to apply for a position or fairly participate in the interview process. If you require any adjustments, please don't hesitate to let us know. We will make every effort to provide the necessary adjustments to ensure you have an equitable opportunity to succeed.
Redirects to Deliveroo's application page.
Other roles
More at Deliveroo.
Staff Software Engineer - Full-Stack
Staff
Senior Platform Engineer - Developer Platform
Senior
Senior Manager of Engineering, Brand Ads and Promotions
Manager
Senior Software Engineer, GenAI Platform
Senior
Senior DevOps Engineer
Senior