Datadog
Staff Application Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 5 days ago · Added 5 days ago
First listed 5 days ago and still open.
Salary
$244k to $305k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Boston, Massachusetts, USA; Connecticut, USA, Remote; Delaware, USA, Remote; District of Columbia, USA, Remote; Maryland, USA, Remote; Massachusetts, USA, Remote; New Jersey, USA, Remote; New York, New York, USA; New York, USA, Remote; Rhode Island, USA, Remote, Boston, Massachusetts, USA; Connecticut, USA, Remote; Delaware, USA, Remote; District of Columbia, USA, Remote; Maryland, Boston, New York"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently. You're the person others come to when they don't know how to make something secure, and you reliably have an answer.
You'll be a point of contact for our most complex security programs, often spanning multiple teams and multiple quarters. The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss). Partnering closely with teams inside and outside the security org is key to success. You'll help shape the AppSec roadmap and make the case for where investment should go.
We use our own platform. Logs, Dashboards, Service Catalog, and APM aren't just things we sell: they're tools the AppSec team uses to build security services, measure adoption of secure defaults, and communicate risk across the organization.
AI is also part of the picture. Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle, and many of the products we ship to customers now include AI-powered features. Both create new attack surfaces, and defining our strategy for addressing them is part of this role.
If using Datadog to observe Datadog's own security posture, building impactful tooling, and shaping how we secure AI-powered systems sounds like the right kind of problem, this role is worth a close look.
What You’ll Do:
Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert.
Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals.
Lead threat modeling and risk assessment for high-risk features and platform changes.
Assess and address security risks introduced by agentic development practices and AI-powered product features in production
Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.
Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end
Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems
Serve as the AppSec subject matter expert across Datadog; be the person engineering leadership calls when they need clarity on a hard security problem
Deeply invest in the growth of AppSec engineers on the team
Who You Are:
Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust
Demonstrated ability to level up the engineers around you: through design reviews, mentorship, and the quality of your documentation
Solid grounding in OWASP Top 10, web vulnerabilities ( XSS , injection, access control, cryptography), SAST , and DAST
Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries
Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions
Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams
Able to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences
Familiarity with software supply chain security: dependency management, artifact integrity, and build pipeline trust
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
- ·Continuous professional development, product training, and career pathing
- ·Intradepartmental mentor and buddy program for in-house networking
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Datadog, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$244k to $305k per year · You'll be taken to the employer's careers page.