The opportunity
Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever.
What you'll do
Work across the vulnerability lifecycle from detection and impact assessment: through risk-based prioritization, remediation, and verification.
Use AI and automation to build tools, services, and workflows that make: security ideas concrete, validate them quickly, and create alignment for scalable implementation.
Reduce engineering toil through a “PRs, not tickets” approach, using: automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes.
Analyze recurring vulnerabilities and remediation failures to identify root: causes and opportunities to prevent issues earlier in the SDLC.
Partner with SDLC Security, Product Security, platform teams, and engineering: teams to balance technical constraints, business impact, and risk; communicate concerns early and pair problems with actionable options.
Provide evidence and subject matter expertise for vulnerability management: processes and controls for multiple compliance frameworks (SOC2, HIPAA, PCI, FedRAMP, ISO)
What they're looking for
- You have experience identifying, prioritizing, and driving remediation of: vulnerabilities in large software, cloud, or infrastructure environments.
- You can independently solve complex technical problems using one or more: programming languages such as Go, Python, or Java.
- You have experience with cloud-native or multi-cloud environments, containers: or orchestration platforms, infrastructure as code, and modern software-delivery workflows.
- You have experience reproducing and validating externally reported vulnerabilities.
- You use data, exploitability, exposure, technical context, and business: impact to make and explain risk decisions.
- You are comfortable making progress without a complete specification: you break problems down, test assumptions, fail fast, document tradeoffs, and adjust when new information emerges.
- You use AI-assisted tools thoughtfully, validate their output, and can: explain the reasoning behind your decisions.
- You influence across security, engineering, product, and compliance teams: through clear communication, technical credibility, and solutions that reduce friction.