
Staff Application Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Connecticut, +6 more states.
• Establish and advance security standards along with secure-by-default solutions, acting as the subject matter expert in Application Security.
• Develop security tools and automation to scale security practices throughout engineering teams, while implementing effective security observability to provide our threat detection team with significant, actionable security insights.
• Oversee threat modeling and risk assessments for high-risk features and platform modifications.
• Evaluate and mitigate security risks posed by agentic development methodologies and AI-driven product features in production environments.
• Collaborate with engineering teams to prioritize and address critical threats, establish API security standards, and perform security code reviews.
• Detect systemic security vulnerabilities; lead intricate, multi-team remediation initiatives from start to finish.
• Work together with Cloud & Infrastructure Security and other departments on cross-domain issues; serve as the AppSec point of contact for complicated cross-domain challenges.
• Act as the AppSec subject matter expert within Datadog; be the go-to person for engineering leadership when they seek clarity on complex security issues.
• Invest significantly in the development of AppSec engineers on the team.
• Background in software engineering with practical experience in code review; familiarity with Go (preferred), Python, or Rust.
• Proven capability to elevate the skills of the engineers around you through design reviews, mentorship, and high-quality documentation.
• Strong understanding of OWASP Top 10, web vulnerabilities (XSS, injection, access control, cryptography), SAST, and DAST.
• Working knowledge of API security, including authentication flows, authorization patterns, and input validation at API boundaries.
• Experience leading threat modeling efforts on complex, multi-team systems and converting outcomes into architectural decisions.
• Proven ability to implement secure-by-default frameworks and integrate security into core platforms in collaboration with product managers and engineering teams.
• Skilled in translating business risks into security investment priorities and clearly communicating trade-offs to executive audiences.
• Familiarity with software supply chain security, including dependency management, artifact integrity, and build pipeline trust.
• Proactive in implementing solutions and promoting adoption, rather than merely identifying issues.
• Documented success in gaining support from both technical and non-technical stakeholders; adept at articulating complex trade-offs to engineers, product managers, and leadership.
• Up-to-date on security best practices, emerging threats, and the current tooling landscape.
• New hire stock equity (RSUs) and employee stock purchase plan (ESPP).
• Continuous professional development opportunities, product training, and career advancement pathways.
• Intradepartmental mentoring and buddy program for networking within the organization.
• A welcoming company culture with the opportunity to join our Community Guilds (Datadog employee resource groups).
• Access to Inclusion Talks, our internal panel discussions.
• Complimentary global mental health benefits for employees and dependents aged 6 and above.
• Competitive global benefits package.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.