Staff Application Security Engineer

Datadog Datadog · Enterprise · Boston, MA +1 · Security

Staff Application Security Engineer responsible for defining and driving security standards, building security tooling and automation, leading threat modeling, and assessing/addressing security risks introduced by agentic development practices and AI-powered product features. The role involves partnering with engineering teams, identifying systemic security risks, and ensuring secure-by-default solutions at scale within an enterprise environment that uses AI extensively.

What you'd actually do

  1. Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert.
  2. Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals.
  3. Lead threat modeling and risk assessment for high-risk features and platform changes.
  4. Assess and address security risks introduced by agentic development practices and AI-powered product features in production
  5. Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.

Skills

Required

  • Software engineering background
  • hands-on code review experience
  • OWASP Top 10
  • web vulnerabilities (XSS, injection, access control, cryptography)
  • SAST
  • DAST
  • API security
  • threat modeling
  • secure-by-default frameworks
  • integrating security into core platforms
  • software supply chain security
  • winning buy-in from technical and non-technical stakeholders
  • communicating complex tradeoffs clearly

Nice to have

  • Go (preferred)
  • Python
  • Rust

What the JD emphasized

  • set technical direction
  • complex security programs
  • complex, multi-team remediation efforts end-to-end
  • complex cross-domain problems
  • clarity on a hard security problem

Other signals

  • AI-powered features
  • agentic tooling
  • attack surfaces
  • secure AI systems