SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Deliveroo is seeking a Senior Corporate Security Engineer to lead the design and operation of security controls protecting internal networks, workforce identities, endpoints, and corporate systems across global operations (US, EU, APAC).
In this role, you will operate with high autonomy, defining technical direction and making architectural decisions for complex security initiatives. You will balance risk reduction with usability, ensuring controls are robust without impeding employee productivity.
Key responsibilities include:
- Architecture & Control Implementation: Design, deploy, and maintain core corporate security controls including phishing-resistant MFA, Just-In-Time (JIT) access, role-based access control (RBAC), zero-trust architectures, device and identity bound proofing, and modern network isolation.
- Tooling Ownership: Serve as technical owner for corporate security systems, managing deployments, configurations, and API integrations across the environment.
- Technical Leadership: Lead technical strategy for Endpoint Device trust, Data Loss Prevention, Intellectual Property storage, and SaaS application security aligned to CIS Critical Security Controls and NIST Cybersecurity Framework.
- Automation & Engineering: Write scripts and build tools to automate security workflows, incident response tasks, and audit evidence collection for compliance.
- Cross-Functional Collaboration: Work with IT and business operations to integrate security tools into workflows and guide teams to adopt secure baselines.
- Mentorship: Mentor junior and mid-level engineers and help improve team engineering standards.
Required qualifications: Bachelor's degree in Computer Science, Cybersecurity, or IT (or equivalent); 5+ years in Security Engineering, Corporate Security, or Detection & Response; hands-on IAM platform administration (Okta, Google Workspace); deep Google Workspace experience; practical cloud platform experience (AWS, GCP); Infrastructure-as-code experience (Terraform); modern authentication standards implementation (FIDO2, WebAuthn, SAML, OAuth 2.0, OpenID Connect); endpoint security experience (macOS, Windows, Linux, MDM, EDR/XDR); SIEM/SOAR platform operation; vulnerability management and patch governance; production-quality automation scripting; demonstrated cross-functional technical leadership.
Desirable: SASE or Zero Trust Network Access platforms; Kubernetes and Docker deployment; DLP and SaaS security governance; advanced detection engineering; ISO 27001 or SOC 2 audit support; relevant certifications (CISSP, CISM, GIAC).