Senior Application Security Engineer

Datadog · Paris, France · Security · listed September 25, 2026

The shape of it

Seniority
Senior
Experience asked
5+ years
Where
Hybrid
Requirements listed
6
Length
785 words

In the posting’s own words

As a Senior Security Engineer within Application Security at Datadog, you will help secure emerging application architectures where established security patterns may not yet exist, including agentic applications, LLM-enabled products, protocol-driven tool use, and untrusted execution environments. You will establish and validate security models, requirements, and controls while partnering with product and platform teams to develop secure-by-default approaches. Your work will address evolving trust boundaries, agent identity, data access, tool permissions, and runtime behavior through threat modeling, security solutions, and practical implementation. You will have the opportunity to shape how Datadog safely supports new application paradigms and address emerging security risks before they become systemic.

What it asks for · 6

  • You have 5+ years of experience in software engineering or development in a collaborative environment, with Go, Rust, or Python experience preferred.
  • You have experience in security and/or infrastructure/platform engineering, with exposure to distributed systems, application platforms, or agent-based architectures.
  • You have designed or implemented security controls within application infrastructure, such as authentication, authorization, API security, zero-trust networking, workload protection, sandboxing, or runtime hardening.
  • You understand common application security vulnerabilities and mitigation techniques, including those relevant to LLM applications and agentic systems; familiarity with LLM frameworks and protocols such as MCP or A2A is a plus.
  • You bring strong problem-solving skills and can work independently and collaboratively in ambiguous or rapidly evolving problem spaces.
  • You have successfully driven security initiatives with engineering and leadership stakeholders and are committed to staying current with security practices, emerging technologies, and evolving threats.

What the job covers

  • Define security models, requirements, and guardrails for emerging application architectures where established patterns are incomplete or do not yet exist.
  • Design, implement, and validate practical security controls that reduce risk in emerging architectures and high-risk system behaviors.
  • Shape how emerging systems authenticate, authorize actions, isolate workloads, and access data, applying least-privilege principles throughout.
  • Partner with product, platform, Infrastructure Security, and other engineering teams to identify security gaps and embed secure-by-default requirements from early design through production.
  • Lead threat modeling and security assessments for new and existing products, focusing on evolving threats, unfamiliar trust boundaries, and new interaction patterns.
  • Prioritize and drive remediation of emerging security risks, including continuous security testing where it provides durable coverage, and refine security approaches as architectures and threats evolve.

Tools and skills named

Security & compliance
  • Security20×
  • Threat modeling2×
Cloud & infra
  • Datadog4×
  • Distributed systems
Languages
  • Go
  • Python
  • Rust
Models & research
  • LLM3×
Ways of working
  • Testing

Words the posting leans on

  • security20×
  • emerging7×
  • architectures5×
  • threats5×
  • engineering4×
  • evolving4×
  • experience4×
  • product4×
  • systems4×
  • patterns3×
  • platform3×
  • access2×
  • address2×
  • agentic2×
  • applications2×
  • approaches2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Datadog

every open role at Datadog →

How this page was made

An automated read of a public job posting, fetched September 25, 2026 and last changed by Datadog on September 25, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.