Jobs / United States / Datadog INC
Staff Application Security Engineer
Datadog INC · 🇺🇸 Boston, Massachusetts, USA; Connecticut, USA, Remote; Delaware, USA, Remote; District of Columbia, USA, Remote; Maryland, USA, Remote; Massachusetts, USA, Remote; New Jersey, USA, Remote; New York, New York, USA; New York, USA, Remote; Rhode Island, USA, Remote · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 64 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 14 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Datadog INC paid sponsored hires in similar roles22 certified filings for “Senior Software Engineer” (Software Developers) in NY: $205k–$245k, median $225k. Most were filed at wage level IV (73%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Datadog INC
The US Department of Labor certified 64 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 14 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Datadog INC →
About the role
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently. You're the person others come to when they don't know how to make something secure, and you reliably have an answer. You'll be a point of contact for our most complex security programs, often spanning multiple teams and multiple quarters. The role requires both depth (going very deep on specific problems when needed) and breadth (recognizing patterns across systems and drawing connections that others miss). Partnering closely with teams inside and outside the security org is key to success. You'll help shape the AppSec roadmap and make the case for where investment should go. We use our own platform. Logs, Dashboards, Service Catalog, and APM aren't just things we sell: they're tools the AppSec team uses to build security services, measure adoption of secure defaults, and communicate risk across the organization. AI is also part of the picture. Engineering at Datadog increasingly uses agentic tooling throughout the development lifecycle, and many of the products we ship to customers now include AI-powered features. Both create new attack surfaces, and defining our strategy for addressing them is part of this role. If using Datadog to observe Datadog's own security posture, building impactful tooling, and shaping how we secure AI-powered systems sounds like the right kind of problem, this role is worth a close look. What You’ll Do: • Define and drive security standards and secure-by-default solutions, serving as the Application Security subject matter expert. • Build security tooling and automation that scales security practices across engineering teams, and implement robust security observability to support our threat detection team with meaningful, actionable security signals. • Lead threat modeling and risk assessment for high-risk features and platform changes. • Assess and address security risks introduced by agentic development practices and AI-powered product features in production • Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews. • Identify systemic security risks; lead complex, multi-team remediation efforts end-to-end • Partner with Cloud & Infrastructure Security and other teams across the org on cross-domain problems; be the AppSec point of contact on complex cross-domain problems • Serve as the AppSec subject matter expert across Datadog; be the person engineering leadership calls when they need clarity on a hard security problem • Deeply invest in the growth of AppSec engineers on the team Who You Are: • Software engineering background with hands-on code review experience; Go (preferred), Python, or Rust • Demonstrated ability to level up the engineers around you: through design reviews, mentorship, and the quality of your documentation • Solid grounding in OWASP Top 10, web vulnerabilities ( XSS , injection, access control, cryptography), SAST , and DAST • Working knowledge of API security: authentication flows, authorization patterns, and input validation at API boundaries • Track record of leading threat modeling on complex, multi-team systems and translating outcomes into architectural decisions • Experience implementing secure-by-default frameworks and integrating security into core platforms alongside product managers and engineering teams • Able to translate business risk into security investment priorities and communicate tradeoffs clearly to executive audiences • Familiarity with software supply chain security: dependency