资深应用安全工程师
Staff Application Security Engineer
作为Datadog的资深应用安全工程师,你将制定我们在大规模应用安全方面的技术方向。你将定义框架、方法论和架构模式,供Datadog各工程团队独立采用和应用。当其他人不知道如何使某物安全时,他们会来找你,而你总能给出可靠的解决方案。
你将是我们最复杂安全项目的联系人,通常涉及多个团队和多个季度。该职位需要深度(在需要时深入研究特定问题)和广度(识别系统间的模式并发现他人忽略的关联)。与安全组织内外的团队紧密合作是成功的关键。你将帮助制定应用安全路线图,并说明投资应投向何处。
我们使用自己的平台。日志、仪表盘、服务目录和APM不只是我们销售的产品:它们是应用安全团队用来构建安全服务、衡量安全默认设置的采用情况以及在整个组织中传达风险的工具。
AI也是其中的一部分。Datadog的工程越来越多地在开发周期中使用代理工具,我们为客户提供许多产品现在都包含AI驱动的功能。这两者都创造了新的攻击面,而制定应对策略是该职位的一部分。
如果使用Datadog来观察Datadog自身的安全态势,构建有影响力的技术工具,并塑造我们如何保护AI驱动的系统听起来像是一个合适的挑战,那么这个职位值得仔细考虑。
你将负责:
- 定义并推动安全标准和默认安全的解决方案,作为应用安全领域的专家。
- 构建可扩展的安全工具和自动化,将安全实践推广到各个工程团队,并实施强大的安全可观测性,以支持我们的威胁检测团队获取有意义且可操作的安全信号。
- 领导高风险功能和平台变更的威胁建模和风险评估。
- 评估并解决由代理开发实践和AI驱动的产品功能在生产环境中引入的安全风险。
- 与工程团队合作,优先处理并修复关键威胁,定义API安全标准,并进行安全代码审查。
- 识别系统性安全风险;全程领导复杂的多团队修复工作。
- 与云和基础设施安全团队合作
查看英文原文
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently. You're the person others come to when they don't know how to make something secure, and you reliably have an answer.
You'll be a point of contact for our most complex security programs, often spanning multiple teams and multiple quarters. The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss). Partnering closely with teams inside and outside the security org is key to success. You'll help shape the AppSec roadmap and make the case for where investment should go.
We use our own platform. Logs, Dashboards, Service Catalog, and APM aren't just things we sell: they're tools the AppSec team uses to build security services, measure adoption of secure defaults, and communicate risk across the organization.
AI is also part of the picture. Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle, and many of the products we ship to customers now include AI-powered features. Both create new attack surfaces, and defining our strategy for addressing them is part of this role.
If using Datadog to observe Datadog's own security posture, building impactful tooling, and shaping how we secure AI-powered systems sounds like the right kind of problem, this role is worth a close look.
What You’ll Do:
- Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert.
- Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals.
- Lead threat modeling and risk assessment for high-risk features and platform changes.
- Assess and address security risks introduced by agentic development practices and AI-powered product features in production
- Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.
- Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end
- Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems
- Serve as the AppSec subject matter expert across Datadog; be the person engineering leadership calls when they need clarity on a hard security problem
- Deeply invest in the growth of AppSec engineers on the team
Who You Are:
- Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust
- Demonstrated ability to level up the engineers around you: through design reviews, mentorship, and the quality of your documentation
- Solid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control, cryptography), SAST, and DAST
- Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries
- Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions
- Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams
- Able to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences
- Familiarity with software supply chain security: dependency management, artifact integrity, and build pipeline trust
- Bias toward implementing solutions and driving adoption, not just surfacing findings
- Proven track record of winning buy-in from technical and non-technical stakeholders; able to communicate complex tradeoffs clearly to engineers, product managers, and leadership
- Current on security best practices, emerging threats, and the tooling landscape
Datadog values people from all walks of life. We understand not everyone will meet all the above qualifications on day one. That's okay. If you’re passionate about technology and want to grow your skills, we encourage you to apply.
Benefits and Growth:
- New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
- Continuous professional development, product training, and career pathing
- Intradepartmental mentor and buddy program for in-house networking
- An inclusive company culture, ability to join our Community Guilds (Datadog employee resource groups)
- Access to Inclusion Talks, our internal panel discussions
- Free, global mental health benefits for employees and dependents age 6+
- Competitive global benefits
Benefits and Growth listed above may vary based on the country of your employment and the nature of your employment with Datadog.
#LI-Hybrid
Datadog offers a competitive salary and equity package, and may include variable compensation. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Datadog offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan.
The reasonably estimated yearly salary for this role at Datadog is:
$244,000—$305,000 USD
About Datadog:
Datadog is the leading observability and security platform for the AI era, providing businesses with unified visibility across the technology stack to manage complexity at scale. It brings applications, infrastructure, data, models, and security into one place, using AI to detect and resolve issues before they impact customers. Trusted globally by Fortune 500 companies and high-growth AI leaders, Datadog enables businesses to move faster with clarity and confidence. Learn more about #DatadogLife on Instagram, LinkedIn, and Datadog Learning Center.
Equal Opportunity at Datadog:
Datadog is proud to offer equal employment opportunity to everyone regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, and other characteristics protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Here are our Candidate Legal Notices for your reference.
Datadog endeavors to make our Careers Page accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please complete this form. This form is for accommodation requests only and cannot be used to inquire about the status of applications.
Privacy and AI Guidelines:
Any information you submit to Datadog as part of your application will be processed in accordance with Datadog’s Applicant and Candidate Privacy Notice. For information on our AI policy, please visit Interviewing at Datadog AI Guidelines.