security
Posted 2 weeks agoStaff Application Security Engineer
at Datadoghq
Boston, United StatesHybrid
Responsibilities
- Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert. •
- Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals. •
- Lead threat modeling and risk assessment for high-risk features and platform changes. •
- Assess and address security risks introduced by agentic development practices and AI-powered product features in production •
- Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end •
- Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions •
- Proven track record of winning buy-in from technical and non-technical stakeholders; able to communicate complex tradeoffs clearly to engineers, product managers, and leadership •
Requirements
- AI is also part of the picture.
- Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle, and many of the products we ship to customers now include AI-powered features.
- If using Datadog to observe Datadog's own security posture, building impactful tooling, and shaping how we secure AI-powered systems sounds like the right kind of problem, this role is worth a close look. What You’ll Do: •
- Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust •
- Demonstrated ability to level up the engineers around you: through design reviews, mentorship, and the quality of your documentation •
- Solid grounding in OWASP Top 10, web vulnerabilities ( XSS , injection, access control, cryptography), SAST , and DAST •
- Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries •
- Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams •
- Familiarity with software supply chain security: dependency management, artifact integrity, and build pipeline trust •
- Datadog is the leading observability and security platform for the AI era, providing businesses with unified visibility across the technology stack to manage complexity at scale.
- It brings applications, infrastructure, data, models, and security into one place, using AI to detect and resolve issues before they impact customers.
- Trusted globally by Fortune 500 companies and high-growth AI leaders, Datadog enables businesses to move faster with clarity and confidence.
- Learn more about #DatadogLife on Instagram , LinkedIn, and Datadog Learning Center.
Benefits
- New hire stock equity (RSUs) and employee stock purchase plan (ESPP) •
- Datadog offers a competitive salary and equity package, and may include variable compensation.
- Actual compensation is based on factors such as the candidate's skills, qualifications, and experience.
- benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan.
- The reasonably estimated yearly salary for this role at Datadog is: $244,000 — $305,000 USD
Additional details
- You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently.
- You're the person others come to when they don't know how to make something secure, and you reliably have an answer.
- You'll be a point of contact for our most complex security programs, often spanning multiple teams and multiple quarters.
- The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss).
- Partnering closely with teams inside and outside the security org is key to success.
- You'll help shape the AppSec roadmap and make the case for where investment should go.
- Logs, Dashboards, Service Catalog, and APM aren't just things we sell: they're tools the AppSec team uses to build security services, measure adoption of secure defaults, and communicate risk across the organization.
- Both create new attack surfaces, and defining our strategy for addressing them is part of this role.
- Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews. •
- Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems •