Staff Application Security Engineer

Datadog · Boston, Massachusetts, USA; Connecticut, USA, Remote; Delaware, USA, Remote; District of Columbia, USA, Remote; Maryland, USA, Remote; Massachusetts, USA, Remote; New Jersey, USA, Remote; New York, New York, USA; New York, USA, Remote; Rhode Island, USA, Remote · Security · listed April 3, 2026

The shape of it

Seniority
Staff
Where
Hybrid
Stated pay
$244,000 – $305,000 USD
Requirements listed
11
Length
1,426 words

In the posting’s own words

As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently. You're the person others come to when they don't know how to make something secure, and you reliably have an answer.

What it asks for · 11

  • Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust
  • Demonstrated ability to level up the engineers around you: through design reviews, mentorship, and the quality of your documentation
  • Solid grounding in OWASP Top 10, web vulnerabilities ( XSS , injection, access control, cryptography), SAST , and DAST
  • Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries
  • Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions
  • Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams
  • Able to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences
  • Familiarity with software supply chain security: dependency management, artifact integrity, and build pipeline trust
  • Bias toward implementing solutions and driving adoption, not just surfacing findings
  • Proven track record of winning buy-in from technical and non-technical stakeholders; able to communicate complex tradeoffs clearly to engineers, product managers, and leadership
  • Current on security best practices, emerging threats, and the tooling landscape

What the job covers

  • Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert.
  • Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals.
  • Lead threat modeling and risk assessment for high-risk features and platform changes.
  • Assess and address security risks introduced by agentic development practices and AI-powered product features in production
  • Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.
  • Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end
  • Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems
  • Serve as the AppSec subject matter expert across Datadog; be the person engineering leadership calls when they need clarity on a hard security problem
  • Deeply invest in the growth of AppSec engineers on the team

Tools and skills named

Security & compliance
  • Security40×
  • Threat modeling4×
  • Cryptography2×
Cloud & infra
  • Datadog8×
  • Observability2×
Ways of working
  • Code review4×
  • Mentorship2×
  • Technical writing2×
Languages
  • Go2×
  • Python2×
  • Rust2×
Operations & finance
  • Supply chain2×
Product & design
  • Roadmap

Words the posting leans on

  • security40×
  • engineering12×
  • threat10×
  • complex9×
  • risk9×
  • appsec8×
  • problems8×
  • engineers7×
  • product7×
  • practices6×
  • reviews6×
  • tooling6×
  • communicate5×
  • define5×
  • features5×
  • platform5×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Datadog

every open role at Datadog

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Datadog on August 24, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.