Deliveroo operates a three-sided marketplace connecting consumers, restaurants and grocers, and riders across 10 markets worldwide. Since 2013, the platform has scaled to approximately 160,000 restaurant and grocery partners, with a delivery target under 30 minutes. That scale means a high-throughput attack surface: payment data flowing through the platform, PII across consumer and partner accounts, real-time location data on riders and orders, and API-driven integrations with thousands of third-party merchants.
The company's core technical infrastructure runs on machine learning and logistics optimization. The Frank algorithm handles dynamic routing and restaurant preparation time predictions, while Editions (delivery-only kitchen sites) and Hop (rapid grocery delivery sites) extend the operational footprint with additional data flows and physical infrastructure. For a security team, this translates into threats spanning application-layer exploitation on the consumer app, fraud and account takeover at scale, supply chain risk through merchant and rider integrations, and the operational technology layer of the Hop and Editions sites.
Security work here cuts across cloud-native application security, API security for a dense microservices architecture, fraud detection that interfaces with ML pipelines, and infrastructure hardening across multiple geographic deployments. The founder's origin as the company's first rider signals an operationally grounded culture - useful context for a security org that likely has to speak the language of logistics and real-time systems, not just traditional InfoSec frameworks.





