All jobs
D

Director, Security Operations (Security Engineering)

Delivery Hero
Germany· Information Technology September 29, 2026
Browse all Germany jobs
Applying to this role?

Tailor your resume to this exact posting and check it against the ATS — free.

Key skills & keywords for this role

These are the terms most likely to matter to the ATS for this Director, Security Operations (Security Engineering) role at Delivery Hero. Mirror the ones that match your real experience on your resume to improve your match score.

SecurityOperationsglobalresponsethreatincidentdeliverydetectionmonitoringlocalplatformsHero

About the role

As the world’s pioneering local delivery platform, our mission is to deliver an amazing experience, fast, easy, and to your door. We operate in around 65 countries worldwide, powered by tech, designed by people. As one of Europe’s largest tech platforms, headquartered in Berlin, Germany, Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of the MDAX stock market index. We push hard, learn quickly and stay human along the way. It’s this wonderful mix of high performance and real community that makes Delivery Hero a place where ambition and belonging grow side by side. If you’re curious, collaborative and ready to dive deep into meaningful work, you’ll fit right in. We are on the lookout for a Director of Security Operations. Reporting directly to the Chief Information Security Officer (CISO), you will hold full accountability for defining and driving the global strategy for threat detection, security monitoring, threat intelligence, and security incident response across the entire Delivery Hero Group. In this role based out of our global headquarters in Berlin, you will lead our existing operations organization, composed of dedicated CSIRT and SOC teams, while strategically scaling capabilities where needed to safeguard our worldwide entities, platforms, and millions of daily customers. As a Director, you will elevate our Security Operations capability to the next level, moving beyond baseline monitoring toward an intelligence-driven, proactive defense posture. Leveraging cutting-edge technologies like Google SecOps, you will drive modern threat detection engineering, streamline global incident handling workflows, and build resilient response frameworks tailored to the scale and operational complexity of the world’s leading local delivery platform. You will lead, mentor, and optimize a team of security operations professionals, fostering an environment where technical rigor, continuous learning, and rapid response are paramount. By establishing strong partnerships with local CISOs and security leadership across our global entities, you will ensure unified monitoring baselines while maintaining fast, effective crisis response. Your mission: • Lead and Mentor Global Operations: Direct and mentor CSIRT and SOC teams, building a cohesive global operations organization that delivers monitoring and response across all Delivery Hero entities. • Drive Security Operations Maturity: Define the multi-year strategic roadmap for threat detection, incident response, and threat intelligence to systematically reduce organizational risk at a global scale. • Modernize Detection and Response: Optimize our detection pipeline using Google SecOps (SIEM) and advanced telemetry to build high-fidelity detections, minimize noise, and accelerate Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). • High-Level Incident Governance: Act as the ultimate escalation point and incident commander for critical, major security incidents, providing clear leadership, stakeholder communication, and post-incident governance. • Threat Intelligence Integration: Establish robust threat intelligence capabilities that translate global threat actor tactics, techniques, and procedures (TTPs) into proactive detection engineering and strategic defenses. • Global Entity Alignment: Partner closely with local CISOs and local security leads across all Delivery Hero entities to ensure consistent, scalable security monitoring and incident response standards across all global subsidiaries and platforms. • Operational Metrics and Continuous Improvement: Drive data-informed operational reporting within existing resources, evaluating capabilities using frameworks like MITRE ATT&CK to demonstrate measurable risk reduction over time.   • Proven Operations Leadership: A track record of leading Security Operations Centers (SOC) and Incident Response (CSIRT) functions within large-scale, complex enterprise or tech environments. • Deep Incident Response and Threat Hunting Expertise: Extensive experience managing complex, critical security incidents and architecting proactive threat hunting programs. • Modern SIEM and SecOps Proficiency: H ands-on familiarity with modern cloud-native SIEM and SecOps platforms (experience with Google SecOps / Chronicle is a strong plus), including telemetry ingestion, detection-as-code, and automated response playbooks (SOAR). • Global Stakeholder Management: Excellent communication and crisis management skills, with the ability to translate complex technical incidents into actionable risk insights for executive leadership, regional CISOs, and legal partners. • Team Development and Mentorship: Demonstrated success mentoring analysts, optimizing operational workflows, and managing global follow-the-sun or escalation models efficiently. • Metrics-Driven Execution: Experience establishing and driving key security operations metrics (such as MTTD, MTTR, detection coverage against MITRE ATT&CK) to measure performance and continuously mature capability. • Strategic Vision and Execution: Ability to balance immediate operational fire-fighting with long-term strategic improvements to build a resilient, future-proof operations center. Nice to haves: • Large-Scale Platform Experience: Background operating within complex global platforms, food/logistics delivery networks, or multi-tenant cloud ecosystems. • Incident Response and Operations Certifications: High-level credentials such as CISSP, CISM, or advanced GIAC certifications (such as GCIH, GCFA, GNFA). • Cloud-Native Architecture Exposure: Familiarity with monitoring and responding to threats across multi-cloud environments (AWS, GCP). Ensuring you and all our Heroes are looked after, happy, and healthy is always on the menu. Because if you’re in good shape, then we’re in good shape. • Make the most of our hybrid working model and join the team for face-to-face connection and collaboration in our beautiful Be
Apply on Global employers (SmartRecruiters) Posting aggregated by WeZoom · applications happen on the source site.