Security Engineer II - Vulnerability Lifecycle

Datadog Datadog · Enterprise · New York, NY · Security

Security Engineer II focused on the vulnerability management lifecycle, aiming to improve efficiency through automation and an AI-first approach. The role involves reducing engineering toil, developing automation for detection and remediation, collaborating with various teams to shift left on vulnerabilities, and developing metrics for leadership. It also requires providing expertise for compliance frameworks like SOC2, HIPAA, PCI, FedRAMP, and ISO.

What you'd actually do

  1. Reduce engineering toil related to vulnerability remediation through a “PRs, not tickets” approach.
  2. Develop and operate automation to increase detection coverage and remediate root cause issues
  3. Work with critical partners like SDLC Security, Product Security, and a wide range of engineering teams to “shift left” and reduce upstream vulnerabilities entering our ecosystem.
  4. Improve the efficiency of our overall vulnerability management lifecycle through thoughtful use of automation and AI.
  5. Develop metrics and reporting to provide leadership with an accurate view of overall vulnerability risk.

Skills

Required

  • vulnerability management
  • cloud security posture management
  • SDLC management
  • communication skills
  • cross-functional collaboration
  • Golang
  • Python
  • Java

Nice to have

  • ITAR-controlled projects

What the JD emphasized

  • AI-first approach
  • automation and AI