6 months ago
Base Salary
$234k - $300k/yr
Responsibilities
- Define and drive application security standards and secure-by-default solutions as the AppSec subject matter expert.
- Build scalable security tooling, automation, and security observability to support threat detection with actionable signals.
- Lead threat modeling and risk assessments for high-risk features and platform changes.
- Assess and address security risks from agentic development practices and AI-powered production features.
- Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.
- Identify systemic security risks and lead complex, multi-team remediation efforts end to end.
- Partner with Cloud & Infrastructure Security and other teams on cross-domain security problems.
- Shape the AppSec roadmap and make investment recommendations.
- Serve as the AppSec point of contact for engineering leadership and complex security problems.
- Invest in the growth of AppSec engineers on the team.
Requirements
- Software engineering background with hands-on code review experience and proficiency in Go, Python, or Rust, with Go preferred.
- Strong knowledge of OWASP Top 10, web vulnerabilities including XSS, injection, access control, and cryptography, as well as SAST and DAST.
- Working knowledge of API security, including authentication flows, authorization patterns, and input validation at API boundaries.
- Experience leading threat modeling for complex, multi-team systems and translating results into architectural decisions.
- Experience implementing secure-by-default frameworks and integrating security into core platforms with product managers and engineering teams.
- Track record of translating business risk into security investment priorities and communicating tradeoffs to executive audiences.
- Familiarity with software supply chain security, including dependency management, artifact integrity, and build pipeline trust.
- Demonstrated ability to mentor and elevate engineers through design reviews, mentorship, and high-quality documentation.
- Proven ability to gain buy-in from technical and non-technical stakeholders and communicate complex tradeoffs clearly.
- Current knowledge of security best practices, emerging threats, and the security tooling landscape.
Benefits
- New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
- Continuous professional development, product training, and career pathing
- Intradepartmental mentor and buddy program
- Inclusive company culture and access to Community Guilds
- Access to Inclusion Talks
- Free global mental health benefits for employees and dependents age 6+
- Healthcare, dental, parental planning, mental health benefits, 401(k) plan and match, paid time off, fitness reimbursements, and discounted employee stock purchase plan
- Hybrid work arrangement indicated
About Datadog
Datadog builds a SaaS observability and security platform that monitors infrastructure, applications, logs, and services for engineering and DevOps teams. Its products include infrastructure monitoring, APM, log management, real user monitoring, and cloud security, sold via subscriptions and used across cloud-native and hybrid environments. Founded in 2010 and headquartered in New York City, Datadog is a public company trading on NASDAQ under the ticker DDOG.
