Staff Application Security Engineer
Overview
As Staff Application Security Engineer, you set technical direction for security at scale and define frameworks used by engineering teams company-wide. You’ll drive secure-by-default practices, build scalable security tooling, and serve as the go-to AppSec expert for complex programs spanning multiple teams. You’ll shape the AppSec roadmap, balance risk with business needs, and address AI- and agentic-development risks in production. This role offers the chance to influence across domains and collaborate with leadership to advance a security-first culture.
Compensation / BenefitsNew hire stock equity (RSUs) and ESPPContinuous professional development and career pathingMentor and buddy programInclusive culture and employee resource groupsInclusion Talks and internal panel discussionsMental health benefits for employees and dependents
ResponsibilitiesDefine and drive security standards and secure-by-default solutions as the AppSec SMEDevelop security tooling and automation to scale security practices across engineering teamsImplement robust security observability to provide actionable signals to threat-detection effortsLead threat modeling and risk assessment for high-risk features and platform changesAssess and address security risks introduced by agentic development and AI-powered featuresPartner with engineering to prioritize and remediate threats, define API security standards, and conduct code reviewsIdentify systemic security risks and lead cross-team remediation initiatives end-to-endCollaborate with Cloud & Infrastructure Security and other teams on cross-domain problems as AppSec leadServe as AppSec SME across Datadog and guide leadership on hard security problemsInvest in the growth and development of AppSec engineers on the team
Key requirementsSoftware engineering background with hands-on code review experience in Go, Python, or RustAbility to level up engineers via design reviews, mentorship, and clear documentationStrong knowledge of OWASP Top 10, web vulnerabilities, SAST, and DASTWorking knowledge of API security: auth flows, authorization patterns, input validation at API boundariesTrack record leading threat modeling on complex, multi-team systems and translating outcomes into architectureExperience implementing secure-by-default frameworks and integrating security into core platforms with product managers and engineersAbility to translate business risk into security investments and communicate tradeoffs to executivesFamiliarity with software supply chain security: dependency management, artifact integrity, and build pipeline trustBias toward action and adoption of solutions, not just findingsProven ability to gain buy-in from technical and non-technical stakeholderscross-functional collaborationmentorship and coachingclear communication to diverse audiencesGo, Python, or RustOWASP Top 10, web vulnerabilitiesSAST and DAST