Senior Security Engineer, Vulnerability Management

Datadog · Boston, Massachusetts, USA; New York, New York, USA · Security · listed September 2, 2026

The shape of it

Seniority
Senior
Where
Hybrid
Requirements listed
9
Length
901 words

In the posting’s own words

Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever. We are looking for a Senior Security Engineer who can combine vulnerability-management judgment with hands-on engineering to help us scale and improve our vulnerability lifecycle across Datadog’s multi-cloud products and services.

What it asks for · 9

  • You have experience identifying, prioritizing, and driving remediation of vulnerabilities in large software, cloud, or infrastructure environments.
  • You can independently solve complex technical problems using one or more programming languages such as Go, Python, or Java.
  • You have experience with cloud-native or multi-cloud environments, containers or orchestration platforms, infrastructure as code, and modern software-delivery workflows.
  • You have experience reproducing and validating externally reported vulnerabilities.
  • You use data, exploitability, exposure, technical context, and business impact to make and explain risk decisions.
  • You are comfortable making progress without a complete specification: you break problems down, test assumptions, fail fast, document tradeoffs, and adjust when new information emerges.
  • You use AI-assisted tools thoughtfully, validate their output, and can explain the reasoning behind your decisions.
  • You influence across security, engineering, product, and compliance teams through clear communication, technical credibility, and solutions that reduce friction.
  • You have a BS/MS/PhD in Computer Science, Engineering, or a related scientific field, or equivalent practical experience

What the job covers

  • Work across the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification.
  • Use AI and automation to build tools, services, and workflows that make security ideas concrete, validate them quickly, and create alignment for scalable implementation.
  • Reduce engineering toil through a “PRs, not tickets” approach, using automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes.
  • Analyze recurring vulnerabilities and remediation failures to identify root causes and opportunities to prevent issues earlier in the SDLC.
  • Partner with SDLC Security, Product Security, platform teams, and engineering teams to balance technical constraints, business impact, and risk; communicate concerns early and pair problems with actionable options.
  • Provide evidence and subject matter expertise for vulnerability management processes and controls for multiple compliance frameworks (SOC2, HIPAA, PCI, FedRAMP, ISO)

Degree language

  • You have a BS/MS/PhD in Computer Science, Engineering, or a related scientific field, or equivalent practical experience

Tools and skills named

Security & compliance
  • Security8×
  • HIPAA
  • PCI
  • SOC 2
Cloud & infra
  • Datadog5×
Languages
  • Go
  • Java
  • Python
Operations & finance
  • Supply chain

Words the posting leans on

  • security8×
  • engineering6×
  • technical6×
  • vulnerability6×
  • vulnerabilities5×
  • experience4×
  • problems4×
  • product4×
  • automation3×
  • compliance3×
  • platform3×
  • reduce3×
  • remediation3×
  • risk3×
  • sdlc3×
  • software3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Datadog

every open role at Datadog

How this page was made

An automated read of a public job posting, fetched September 3, 2026 and last changed by Datadog on September 2, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.