CybersecurityJobs.io
← Back to all jobs

Job Description

Datadog offers a collaborative, growth-focused culture with strong development opportunities, stock-based compensation, and comprehensive benefits. This hybrid Staff Application Security Engineer role in New York, NY carries a salary range of USD 244,000 to 305,000 per year. The position emphasizes designing secure-by-default solutions, building scalable security tooling, and mentoring AppSec engineers, all within an inclusive environment that supports continuous learning and well-being.

Benefits

  • New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
  • Continuous professional development, product training, and career pathing
  • Intradepartmental mentor and buddy program for in-house networking
  • Inclusive culture with access to Community Guilds (employee resource groups)
  • Inclusion Talks and internal panel discussions
  • Free global mental health benefits for employees and dependents age 6+
  • Competitive global benefits

Responsibilities

  • Define and drive secure-by-default security standards, serving as the Application Security subject matter expert
  • Build security tooling and automation to scale security practices across engineering teams, and implement robust security observability to support threat detection with meaningful signals
  • Lead threat modeling and risk assessments for high-risk features and platform changes
  • Assess and address security risks from agentic development practices and AI-powered product features in production
  • Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews
  • Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end
  • Collaborate with Cloud & Infrastructure Security and other teams on cross-domain problems; serve as the AppSec point of contact on complex cross-domain issues
  • Serve as the AppSec subject matter expert across Datadog; provide clarity on hard security problems for engineering leadership
  • Invest in the growth of AppSec engineers on the team

Requirements

  • Software engineering background with hands-on code review experience; Go preferred, with Python or Rust
  • Proven ability to elevate engineers through design reviews, mentorship, and high-quality documentation
  • Solid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control, cryptography), SAST, and DAST
  • Working knowledge of API security, including authentication flows, authorization patterns, and input validation at API boundaries
  • Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions
  • Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams
  • Ability to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences
  • Familiarity with software supply chain security: dependency management, artifact integrity, and build pipeline trust
  • Bias toward implementing solutions and driving adoption, not just surfacing findings
  • Proven track record of winning buy-in from technical and non-technical stakeholders; able to communicate complex tradeoffs to engineers, product managers, and leadership
  • Current on security best practices, emerging threats, and the tooling landscape

Technologies

  • Go
  • Python
  • Rust

Similar Jobs