
Staff Application Security Engineer
Job description
About the role
Staff Application Security Engineer, Application Security
This page describes the role of Staff Application Security Engineer within the Application Security organization at Datadog. The position is responsible for establishing and maintaining the technical foundation for application security across the company. Success in this role requires a unique blend of deep technical expertise and broad strategic influence.
In this capacity, you are the authoritative voice for application security strategy. You define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and implement independently. Your expertise is the default resource that other teams rely on when facing complex security challenges. You provide definitive answers and direction, enabling other groups to move securely without constant centralized oversight.
You will be a central point of contact for the organization's most intricate security initiatives. These programs often involve multiple departments and extend across several quarters. The role demands both profound depth on specialized subjects and the breadth to identify patterns across disparate systems. You will work closely with product, infrastructure, and other non-security teams. A core part of this position is shaping the AppSec roadmap and articulating the rationale for security investments.
Datadog's platform, including its logs, dashboards, service catalog, and APM, is not merely a product offering. It is a primary tool used by the AppSec team to build security services, measure the adoption of secure defaults, and communicate risk throughout the organization. also, the evolving AI landscape is integral to this role. Engineering at Datadog increasingly utilizes agentic tooling, and many customer-facing products now incorporate AI-powered features. This progression creates new attack surfaces, and defining the strategic response to these emerging risks is a fundamental component of the job.
This role is ideal for individuals who are excited by using Datadog to monitor its own security posture, building impactful internal tooling, and shaping the security of AI-powered systems.
Key Responsibilities
Your daily work will focus on several critical domains. You will define and drive security standards and secure-by-default solutions, acting as the primary Application Security subject matter expert. This involves building and implementing security tooling and automation that scales secure practices across all engineering teams. You will also establish robust security observability to support the threat detection team with meaningful, actionable security signals.
You will lead architectural risk analysis for high-impact features and platform changes. This includes assessing and addressing security risks introduced by agentic development practices and AI-powered product features deployed in production environments. A key function is partnering with engineering teams to prioritize and remediate critical threats, defining API security standards, and conducting design and code reviews.
You will identify systemic security risks and lead complex, multi-team remediation efforts from start to finish. This requires close collaboration with Cloud & Infrastructure Security and other departments on cross-domain security challenges. You will serve as the AppSec point of contact for complex issues and be the resource that engineering leadership calls upon for clarity on difficult security problems. Investing in the professional growth of other AppSec engineers is also a core responsibility.
Qualifications and Expectations
The ideal candidate possesses a software engineering background with substantial experience reviewing code in production systems. You must demonstrate a comprehensive understanding of web security, including the OWASP Top 10 and common web vulnerabilities. A solid grasp of modern authentication, authorization, and secure API design patterns is essential.
You have a proven ability to elevate the capabilities of engineers around you. This is achieved through thorough design reviews, effective mentorship, and the clarity of your documentation. You can communicate risk effectively to both technical teams and executive leadership. Practical experience applying security controls in cloud-native, containerized environments is required.
Preferred Qualifications
While not mandatory, experience with the Datadog platform or other observability tools is highly beneficial.
Required Skills and Tools
Proficiency in Go, Python, or Rust is expected. Familiarity with Datadog APM, Logs, Service Catalog, and Cloud & Infrastructure Security is integral to the position.
Practical Information
Please confirm all details on the official application page. This includes location-based requirements and compensation, which range from $170,000 to $230,000 per year, depending on location and qualifications. The engagement type is Full-time. Specific locations include Boston, Massachusetts; other areas in Connecticut, Delaware, District of Columbia, Maryland, Massachusetts, New Jersey, New York, and Rhode Island; and remote options.