Staff Application Security Engineer

Datadog

Not Interested
Bookmark
Report This Job

profile Job Location:

Boston, NH - USA

profile Monthly Salary: Not Disclosed
Posted on: 8 days ago
Vacancies: 1 Vacancy

Job Summary

As a Staff Application Security Engineer at Datadog youll set technical direction for how we approach application security at scale. Youll define the frameworks methodologies and architectural patterns that engineering teams across Datadog adopt and apply independently. Youre the person others come to when they dont know how to make something secure and you reliably have an answer.

Youll be a point of contact for our most complex security programs often spanning multiple teams and multiple quarters. The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss). Partnering closely with teams inside and outside the security org is key to success. Youll help shape the AppSec roadmap and make the case for where investment should go.

We use our own platform. Logs Dashboards Service Catalog and APM arent just things we sell: theyre tools the AppSec team uses to build security services measure adoption of secure defaults and communicate risk across the organization.

AI is also part of the picture. Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle and many of the products we ship to customers now include AI-powered features. Both create new attack surfaces and defining our strategy for addressing them is part of this role.

If using Datadog to observe Datadogs own security posture building impactful tooling and shaping how we secure AI-powered systems sounds like the right kind of problem this role is worth a close look.

What Youll Do:

  • Define and drive security standards and secure-by-default solutions serving as the Application Security subject matter expert.

  • Build security tooling and automation that scales security practices across engineering teams and implement robust security observability to support our threat detection team with meaningful actionable security signals.

  • Lead threat modeling and risk assessment for high-risk features and platform changes.

  • Assess and address security risks introduced by agentic development practices and AI-powered product features in production

  • Partner with engineering teams to prioritize and remediate critical threats define API security standards and conduct security code reviews.

  • Identify systemic security risks; lead complex multi-team remediation efforts end-to-end

  • Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems

  • Serve as the AppSec subject matter expert across Datadog; be the person engineering leadership calls when they need clarity on a hard security problem

  • Deeply invest in the growth of AppSec engineers on the team

Who You Are:

  • Software engineering background with hands-on code review experience; Go (preferred) Python or Rust

  • Demonstrated ability to level up the engineers around you: through design reviews mentorship and the quality of your documentation

  • Solid grounding in OWASP Top 10 web vulnerabilities (XSS injection access control cryptography) SAST and DAST

  • Working knowledge of API security: authentication flows authorization patterns and input validation at API boundaries

  • Track record of leading threat modeling on complex multi-team systems and translating outcomes into architectural decisions

  • Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams

  • Able to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences

  • Familiarity with software supply chain security: dependency management artifact integrity and build pipeline trust

  • Bias toward implementing solutions and driving adoption not just surfacing findings

  • Proven track record of winning buy-in from technical and non-technical stakeholders; able to communicate complex tradeoffs clearly to engineers product managers and leadership

  • Current on security best practices emerging threats and the tooling landscape

Datadog values people from all walks of life. We understand not everyone will meet all the above qualifications on day one. Thats okay. If youre passionate about technology and want to grow your skills we encourage you to apply.

Benefits and Growth:

  • New hire stock equity (RSUs) and employee stock purchase plan (ESPP)

  • Continuous professional development product training and career pathing

  • Intradepartmental mentor and buddy program for in-house networking

  • An inclusive company culture ability to join our Community Guilds (Datadog employee resource groups)

  • Access to Inclusion Talks our internal panel discussions

  • Free global mental health benefits for employees and dependents age 6

  • Competitive global benefits

Benefits and Growth listed above may vary based on the country of your employment and the nature of your employment with Datadog.

#LI-Hybrid


Required Experience:

Staff IC

As a Staff Application Security Engineer at Datadog youll set technical direction for how we approach application security at scale. Youll define the frameworks methodologies and architectural patterns that engineering teams across Datadog adopt and apply independently. Youre the person others come ...
View more view more

About Company

Company Logo

See inside any stack, any app, at any scale, anywhere.

View Profile View Profile