datadog

Staff Application Security Engineer

Apply Now

At a Glance

Location
Boston, Massachusetts, USA; New York, New York, USA
Work Regime
hybrid
Posted
2026-04-03T09:33:55-04:00

Key Requirements

Required Skills

PythonRust

Domain Knowledge

  • Engineering
  • Supply Chain

Requirements

Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust

Top 10, web vulnerabilities (

, injection, access control, cryptography),

Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries

Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions

Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams

Compensation & Benefits

New hire stock equity (RSUs) and employee stock purchase plan (ESPP)

Continuous professional development, product training, and career pathing

Intradepartmental mentor and buddy program for in-house networking

An inclusive company culture, ability to join our Community Guilds (Datadog employee resource groups)

Access to Inclusion Talks, our internal panel discussions

Free, global mental health benefits for employees and dependents age 6+

Responsibilities

Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert.

Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals.

Lead threat modeling and risk assessment for high-risk features and platform changes.

Assess and address security risks introduced by agentic development practices and AI-powered product features in production

Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.

Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end