Senior Application Security Engineer

Datadog Datadog · Enterprise · New York, NY · Security

Senior Application Security Engineer responsible for building scalable, platform-level security controls to enforce production security invariants across Datadog's infrastructure and developer workflows, with a focus on identity, access, and isolation for AI-driven and agentic workloads.

What you'd actually do

  1. Design and implement secure-by-default platform controls, improving the security of our APIs and services.
  2. Build and evolve security systems and enforcement layers (e.g., gateways, middleware, policy engines) that operate at scale across distributed systems
  3. Define and standardize security patterns that can be broadly adopted across services, reducing the need for custom implementations
  4. Integrate security controls into developer workflows, infrastructure, and platform abstractions to drive high adoption
  5. Identify recurring security risks and translate them into reusable, enforced platform primitives

Skills

Required

  • software engineering
  • building distributed systems
  • designing and implementing security controls or systems
  • built shared infrastructure, internal platforms, libraries, frameworks, or enforcement mechanisms
  • understanding of modern systems handling identity, communication, and trust boundaries
  • operating in ambiguous environments
  • working across new problem spaces
  • pragmatic security decisions
  • design and implement solutions that prevent them at scale

Nice to have

  • zero trust architectures
  • service-to-service security models
  • policy-based systems
  • large-scale access control models
  • working with untrusted or non-deterministic workloads
  • sandboxing
  • agent-based systems
  • using observability and telemetry to drive security insights and adoption

What the JD emphasized

  • AI-driven workloads
  • agentic workloads
  • secure behavior the default
  • enforcing security by construction
  • identity, access, and isolation