empty

Senior Software Engineer - SDLC Security (New York)

Datadog

Job Description

Posted on: 
February 10, 2025

Summary and company overview

Senior Software Engineer - SDLC Security

We are looking for a Software Engineer for the SDLC Security team to help secure our supply chain and ensure that all internal and client-facing software we build at Datadog has verifiable integrity and trustworthiness.

You’ll join at an ideal time to make a big impact as the need for robust supply chain security is higher than it’s ever been. Datadog as a platform is growing fast and is used very widely, and the continued and exciting expansion of our product portfolio requires agile thinkers with a deep grounding in security fundamentals. You’ll be involved in every step of securing our supply chain and the platforms that enable CI-CD at Datadog—modeling risks for existing and new areas, designing solutions that mitigate threats to ourselves and our customers, and writing mission critical software that secures our software from source all the way to runtime.

At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them.

Responsibilities

  • Analyze and enhance Datadog’s software supply chain security posture, including build-pipeline security, delivery mechanisms, and key and configuration management
  • Design and implement custom heuristics for dependency health and safety, as well as the policies that govern their usage
  • Help implement and fine-tune static application security testing (SAST) tools with a focus on high-fidelity, low-friction pre-commit and PR-level scanning.
  • Reduce the attack surface of Datadog's client-facing software by mitigating build and supply chain risks.
  • Build provable integrity mechanisms throughout the entire supply chain, working from source management systems out through to node level configuration in Datadog’s compute
  • Represent Datadog in the open source software supply chain security community

Job Requirements

Required Qualifications:

  • Proven track record of designing and coding systems that help secure the software supply chain and SDLC systems, and are leveraged by multiple teams
  • Expertise in key management solutions and cryptographic methodologies (Vault, KMS)
  • You are fluent in one or more modern coding languages (Python, Go, etc.)
  • You are able to work closely with engineering and DevOps teams to integrate security seamlessly into the development process.
  • You are familiar with securing cloud environments (e.g., AWS, GCP, Azure) and Kubernetes based development
  • You want to work in an environment with exciting challenges and opportunities to make an impact.

Preferred Qualifications:

  • Passionate about building products that engineers love and believe in the true outcome of DevSecOps
  • Familiar with continuous security scanning and fine-tuning SAST rules and methodology
  • Knowledgeable of security frameworks such as slsa.dev, TUF, in-toto etc
  • Known as a subject matter expert in the binary protection and/or integrity fields

Additional commentary

Datadog values people from all walks of life. We understand not everyone will meet all the above qualifications on day one. That's okay. If you’re passionate about technology and want to grow your skills, we encourage you to apply.

Benefits and Growth:

  • New hire stock equity (RSUs) and employee stock purchase plan (ESPP)
  • Continuous professional development, product training, and career pathing
  • Intradepartmental mentor and buddy program for in-house networking
  • An inclusive company culture, ability to join our Community Guilds (Datadog employee resource groups)
  • Access to Inclusion Talks, our internal panel discussions
  • Free, global mental health benefits for employees and dependents age 6+
  • Competitive global benefits

Benefits and Growth listed above may vary based on the country of your employment and the nature of your employment with Datadog.

Summary and company overview

Senior Software Engineer - SDLC Security

We are looking for a Software Engineer for the SDLC Security team to help secure our supply chain and ensure that all internal and client-facing software we build at Datadog has verifiable integrity and trustworthiness.

You’ll join at an ideal time to make a big impact as the need for robust supply chain security is higher than it’s ever been. Datadog as a platform is growing fast and is used very widely, and the continued and exciting expansion of our product portfolio requires agile thinkers with a deep grounding in security fundamentals. You’ll be involved in every step of securing our supply chain and the platforms that enable CI-CD at Datadog—modeling risks for existing and new areas, designing solutions that mitigate threats to ourselves and our customers, and writing mission critical software that secures our software from source all the way to runtime.

At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them.

Apply now