Job
- Level
- Lead
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security, Test/QA
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will develop a global security operations strategy, lead CSIRT and SOC teams, optimize incident response workflows, and integrate threat intelligence to enhance the security posture.
Job Technologies
Your role in the team
- We are on the lookout for a Director of Security Operations. Reporting directly to the Chief Information Security Officer (CISO), you will hold full accountability for defining and driving the global strategy for threat detection, security monitoring, threat intelligence, and security incident response across the entire Delivery Hero Group.
- In this role based out of our global headquarters in Berlin, you will lead our existing operations organization, composed of dedicated CSIRT and SOC teams, while strategically scaling capabilities where needed to safeguard our worldwide entities, platforms, and millions of daily customers.
- As a Director, you will elevate our Security Operations capability to the next level, moving beyond baseline monitoring toward an intelligence-driven, proactive defense posture.
- Leveraging cutting-edge technologies like Google SecOps, you will drive modern threat detection engineering, streamline global incident handling workflows, and build resilient response frameworks tailored to the scale and operational complexity of the world's leading local delivery platform.
- You will lead, mentor, and optimize a team of security operations professionals, fostering an environment where technical rigor, continuous learning, and rapid response are paramount.
- By establishing strong partnerships with local CISOs and security leadership across our global entities, you will ensure unified monitoring baselines while maintaining fast, effective crisis response.
- Lead and Mentor Global Operations: Direct and mentor CSIRT and SOC teams, building a cohesive global operations organization that delivers monitoring and response across all Delivery Hero entities.
- Drive Security Operations Maturity: Define the multi-year strategic roadmap for threat detection, incident response, and threat intelligence to systematically reduce organizational risk at a global scale.
- Modernize Detection and Response: Optimize our detection pipeline using Google SecOps (SIEM) and advanced telemetry to build high-fidelity detections, minimize noise, and accelerate Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- High-Level Incident Governance: Act as the ultimate escalation point and incident commander for critical, major security incidents, providing clear leadership, stakeholder communication, and post-incident governance.
- Threat Intelligence Integration: Establish robust threat intelligence capabilities that translate global threat actor tactics, techniques, and procedures (TTPs) into proactive detection engineering and strategic defenses.
- Global Entity Alignment: Collaborate closely with local CISOs and security leads across all Delivery Hero entities to ensure consistent, scalable security monitoring and incident response standards across all global subsidiaries and platforms.
- Operational Metrics and Continuous Improvement: Drive data-informed operational reporting within existing resources, evaluating capabilities using frameworks like MITRE ATT&CK to demonstrate measurable risk reduction over time.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Proven Operations Leadership: A track record of leading Security Operations Centers (SOC) and Incident Response (CSIRT) functions within large-scale, complex enterprise or tech environments.
- Global Stakeholder Management: Excellent communication and crisis management skills, with the ability to translate complex technical incidents into actionable risk insights for executive leadership, regional CISOs, and legal partners.
- Team Development and Mentorship: Demonstrated success in mentoring analysts, optimizing operational workflows, and managing global follow-the-sun or escalation models efficiently.
- Strategic Vision and Execution: Ability to balance immediate operational fire-fighting with long-term strategic improvements to build a resilient, future-proof operations center.
Experience
- Deep Incident Response and Threat Hunting Expertise: Extensive experience managing complex, critical security incidents and architecting proactive threat hunting programs.
- Modern SIEM and SecOps Proficiency: Hands-on familiarity with modern cloud-native SIEM and SecOps platforms (experience with Google SecOps / Chronicle is a strong plus), including telemetry ingestion, detection-as-code, and automated response playbooks (SOAR).
- Metrics-Driven Execution: Experience establishing and driving key security operations metrics (such as MTTD, MTTR, detection coverage against MITRE ATT&CK) to measure performance and continuously mature capability.
This text has been machine translated. Show original
What we offer
- Nutzen Sie unser hybrides Arbeitsmodell optimal und kommen Sie zweimal pro Woche für persönliche Begegnungen und Zusammenarbeit auf unseren schönen Berliner Campus.
- We offer 27 days of holiday with an additional day in the 2nd and 3rd year of service.
- Get moving and release those wonderful, mind-boosting endorphins: Health Checkups, Meditation, Yoga, Gym.
- Cash. Dough. Cheddar. Whatever you call it, we'll help you with it: Employee Share Purchase Plan, Sabbatical Bank, Public Transportation Ticket Discount, Life & Accident Insurance, Corporate Pension Plan.
- Look up and go for it. We will support you in developing yourself and your career: €1,000 educational budget, language courses, parental support.
- The power of getting together over some food is unrivaled. Here are a few ways to help you do that. All the yum: Digital Meal Vouchers, Food Vouchers, Online Canteen, Corporate Discounts.
This text has been machine translated. Show original
Benefits
Food & Drink
Work-Life-Integration
Health, Fitness & Fun
Topics You Will Work On
Job Locations
About Your Employer
Delivery Hero SE
What started as an ambitious idea is now the leading local delivery company. Delivery Hero is present in around 50 countries across four continents and is on a mission to deliver anything, straight to customers’ doors.
Description
- Founding Year
- 2011
- Language
- English
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Trade
Employer reviews
by devworkplaces.com
Total
(1 Review)3.2
Career Growth
3.2Culture
3.2Engineering
2.7Workingconditions
3.8