SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Application Security Engineer

Datadog - Boston, MA, United States - Hybrid - posted 2026-04-03

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

As a Staff Application Security Engineer at Datadog, you will set technical direction for application security across the organization. You'll define frameworks, methodologies, and architectural patterns that engineering teams adopt independently, serving as the go-to expert when teams face complex security challenges. You'll be a point of contact for the most complex security programs, often spanning multiple teams and quarters. The role demands both technical depth—diving deep on specific problems—and breadth to recognize patterns across systems and draw connections others miss. Close partnership with teams inside and outside the security organization is essential. Key responsibilities include defining and driving security standards and secure-by-default solutions; building security tooling and automation that scales practices across engineering teams; implementing robust security observability to support threat detection; leading threat modeling and risk assessment for high-risk features; assessing security risks from agentic development practices and AI-powered product features; partnering with engineering teams to prioritize and remediate critical threats; identifying systemic security risks and leading multi-team remediation efforts; serving as the AppSec point of contact on complex cross-domain problems; and investing deeply in the growth of AppSec engineers on the team. You'll leverage Datadog's own platform—Logs, Dashboards, Service Catalog, and APM—to build security services, measure adoption of secure defaults, and communicate risk. AI is increasingly part of the picture: engineering uses agentic tooling throughout the development lifecycle, and many products now include AI-powered features, creating new attack surfaces that require strategic security approaches. Required qualifications include a software engineering background with hands-on code review experience in Go (preferred), Python, or Rust; demonstrated ability to level up engineers through design reviews, mentorship, and documentation; solid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control, cryptography), SAST, and DAST; working knowledge of API security including authentication flows, authorization patterns, and input validation; track record of leading threat modeling on complex multi-team systems and translating outcomes into architectural decisions; experience implementing secure-by-default frameworks and integrating security into core platforms; and ability to translate business risk into security investment priorities.

Similar roles