← Все вакансии/Senior/Datadog
SeniorHybridBoston, Massachusetts, USA; New York, New York, USA

Senior Security Engineer

D
Datadog
Уровень
Senior
Формат
Hybrid
О роли

Описание вакансии

About the role

Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever. We are looking for a Senior Security Engineer who can combine vulnerability-management judgment with hands-on engineering to help us scale and improve our vulnerability lifecycle across Datadog’s multi-cloud products and services.

In this role, you will turn ambiguous security problems into clear solutions, and work with engineering teams to address root causes and develop technical controls that reduce vulnerabilities earlier in the SDLC. You’ll use AI and automation to help scale the overall vulnerability lifecycle across Datadog. You will use data and sound technical judgment to prioritize risk, and partner with security, product, platform, and compliance teams to bring scalable solutions into practice.

Responsibilities
  • Work across the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification.
  • Use AI and automation to build tools, services, and workflows that make security ideas concrete, validate them quickly, and create alignment for scalable implementation.
  • Reduce engineering toil through a “PRs, not tickets” approach, using automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes.
  • Analyze recurring vulnerabilities and remediation failures to identify root causes and opportunities to prevent issues earlier in the SDLC.
  • Partner with SDLC Security, Product Security, platform teams, and engineering teams to balance technical constraints, business impact, and risk; communicate concerns early and pair problems with actionable options.
  • Provide evidence and subject matter expertise for vulnerability management processes and controls for multiple compliance frameworks (SOC2, HIPAA, PCI, FedRAMP, ISO).
Requirements
  • Experience identifying, prioritizing, and driving remediation of vulnerabilities in large software, cloud, or infrastructure environments.
  • Ability to independently solve complex technical problems using one or more programming languages such as Go, Python, or Java.
  • Experience with cloud-native or multi-cloud environments, containers or orchestration platforms, infrastructure as code, and modern software-delivery workflows.
  • Experience reproducing and validating externally reported vulnerabilities.
  • Ability to use data, exploitability, exposure, technical context, and business impact to make and explain risk decisions.
  • Comfortable making progress without a complete specification: break problems down, test assumptions, fail fast, document tradeoffs, and adjust when new information emerges.
  • Use AI-assisted tools thoughtfully, validate their output, and explain the reasoning behind decisions.
  • Influence across security, engineering, product, and compliance teams through clear communication, technical credibility, and solutions that reduce friction.
  • BS/MS/PhD in Computer Science, Engineering, or a related scientific field, or equivalent practical experience.
Conditions
  • New hire stock equity (RSUs) and employee stock purchase plan (ESPP).
  • Continuous professional development, product training, and career pathing.
  • Intradepartmental mentor and buddy program for in-house networking.
  • An inclusive company culture and the ability to join our Community Guilds.
  • Access to Inclusion Talks, our internal panel discussions.
  • Free, global mental health benefits for employees and dependents age 6+.
  • Competitive global benefits.
Стек и навыки

С чем работаем