Keeper Security

Senior Datadog Security & Observability Engineer

Keeper Security
Apply
2 months ago
Remote, United StatesSenior

Responsibilities

  • Own and continuously improve Datadog Cloud SIEM, security monitoring, and observability across production and corporate environments
  • Design, build, and maintain detection and telemetry capabilities across Datadog, SentinelOne, Wiz, and related security platforms
  • Develop, test, and tune high-fidelity Datadog detection rules aligned with attack scenarios and adversary behaviors
  • Reduce false positives and alert noise while improving detection accuracy
  • Design and maintain Datadog log pipelines, processors, parsing rules, facets, indexes, archives, and retention strategies
  • Implement scalable, version-controlled, and testable detection-as-code practices
  • Define and enforce logging, telemetry, and instrumentation standards across cloud infrastructure, applications, endpoints, and identity systems
  • Build and optimize log ingestion, parsing, normalization, enrichment, and routing workflows
  • Automate onboarding of telemetry sources and improve visibility across production and corporate environments
  • Correlate signals across Datadog, endpoint detection and response, cloud, identity, and security platforms
  • Partner with Security Operations to improve triage workflows, incident response readiness, and escalation quality
  • Build and optimize Datadog dashboards, monitors, analytics, and reporting for Security, SRE, and Engineering teams
  • Map detection coverage against MITRE ATT&CK and identify telemetry and detection gaps
  • Evolve detection use cases based on threat intelligence, threat hunting, and emerging risks
  • Collaborate with cloud, infrastructure, product, and compliance teams to strengthen secure logging and observability
  • Use AI-assisted tools such as Claude and ChatGPT for query development, detection engineering, investigations, automation, and documentation

Requirements

  • 5+ years of experience in detection engineering, SIEM engineering, security engineering, security observability, or a related technical role
  • Deep hands-on production experience administering and engineering Datadog in complex cloud environments
  • Strong experience with Datadog Cloud SIEM, Log Management, Security Monitoring, dashboards, monitors, and alerting
  • Experience designing and maintaining Datadog log pipelines, processors, parsing rules, facets, indexes, and retention strategies
  • Experience building, testing, and tuning Datadog detection rules, correlation logic, and investigation workflows
  • Strong understanding of security telemetry across cloud, endpoint, identity, and application environments
  • Experience with log parsing, normalization, enrichment, and pipeline management
  • Strong knowledge of AWS and cloud-native infrastructure
  • Proficiency with scripting or automation using Python, PowerShell, or similar languages
  • Experience using Datadog APIs, Terraform, or similar infrastructure-as-code tools
  • Solid understanding of modern detection strategies, attacker behaviors, and the MITRE ATT&CK framework
  • Ability to troubleshoot complex issues across logs, metrics, traces, infrastructure, and application telemetry
  • Strong communication and cross-functional collaboration skills
  • Ability and willingness to use AI-assisted tools effectively for query development, detection analysis, troubleshooting, automation, and documentation
  • Preferred experience with SentinelOne, Wiz, or related cloud and endpoint security platforms
  • Preferred experience with Datadog Application Performance Monitoring, Infrastructure Monitoring, distributed tracing, or synthetic monitoring
  • Preferred experience optimizing Datadog ingestion volume, indexing, retention, and platform cost
  • Preferred experience with SOAR, workflow automation, or response orchestration
  • Familiarity with Sigma or other detection-as-code frameworks
  • Experience operating Datadog across large-scale, multi-account, or multi-region AWS environments is preferred
  • Experience in high-scale SaaS, cloud-native, or security product environments is preferred
  • Familiarity with zero-trust architectures, identity-centric security, and privileged access management is preferred
  • Bachelor’s degree in Computer Science, Engineering, or a related field

Benefits

  • 100% remote from select locations, with a hybrid schedule option for candidates in the El Dorado Hills, California or Chicago, Illinois metro areas
  • Medical, dental, and vision insurance, including domestic partnerships
  • Employer-paid life insurance and supplemental life insurance for employees, spouses, and children
  • Voluntary short- and long-term disability insurance
  • Roth or traditional 401(k)
  • Generous paid time off, including paid bereavement and jury duty leave
  • Above-market annual bonuses

Tech Stack

DatadogPowerShellPythonTerraform

Categories

Keeper Security

About Keeper Security

501-1,000 employees

Keeper Security builds a cloud-based, zero-knowledge platform for password management, secrets management, privileged access management and secure remote connections for individuals and organizations. The privately held company, founded in 2011 and headquartered in Chicago, sells its KeeperPAM suite as subscription software, is published in 23 languages and sold in over 150 countries, and supports integrations with common identity providers and enterprise tech stacks.

Contact me