About Datadog
We're on a mission to build the best platform in the world for engineers to understand and scale their systems, applications, and teams. We operate at high scale with trillions of data points per day, enabling seamless collaboration and problem-solving among Dev, Ops, and Security teams for tens of thousands of companies globally. Our engineering culture values pragmatism, honesty, and simplicity to solve hard problems the right way.
The Team
The Datadog Security Libraries team owns the customer-side integrations behind our run-time security products App & API Protection, Workload Protection, and Code Security. Our libraries let customers automatically manage application security risk with continuous, real-time monitoring of vulnerabilities and threats against their web applications, serverless applications, and APIs, in production. Automatically integrated with Application Performance Monitoring (APM) distributed tracing and code-level context, our software empowers development, operations, and security teams to build and run secure applications.
As a polyglot team we ship and maintain the security capabilities of Datadog's tracing libraries across .NET, Java, Go, Node.js, Python, Ruby, and PHP, on top of a shared C++ core and a set of HTTP proxy integrations (primarily Envoy, NGINX, and HAProxy). Our code runs inside thousands of production applications around the world. Recent work spans exploit prevention (RASP) and WAF detections, API Security, code security (IAST and SCA), and AI-assisted ("agentic") onboarding, always measured by real product outcomes and operational telemetry.
The Opportunity
We're looking for a senior, polyglot engineer to contribute across several of our security libraries, with .NET or Java expertise. You'll design and build security integrations and detection features, take them from prototype to production-hardened, and own them operationally as they instrument thousands of applications.
As a senior engineer within a product team, we also expect a strong sense of product engineering: you connect the libraries you build to customer adoption and security value, and you help decide what's worth building.
What You'll Do
- Design, build, and own security integrations and detections (WAF, RASP/exploit prevention, API Security, IAST, SCA) across multiple libraries, with .NET and/or Java as your primary focus.
- Take projects from prototype to deployed, correct, operable, and maintainable, writing code that safely instruments thousands of applications in production.
- Own your systems operationally: monitor production telemetry (e.g., WAF/RASP timeouts, performance and cost), debug challenging cross-system issues, and drive down customer-facing problems.
- Shape the roadmap: help define the OKRs for the systems you own, break features into components other engineers can build in parallel, and drive designs and RFCs to alignment across our security library teams.
- Partner with product management, backend, and frontend teams to turn product ideas, new detections, agentic onboarding, API security, into capabilities customers actually adopt.
- Mentor teammates and act as a force multiplier: raise the bar on code quality and testing, and make the whole team more effective than you'd be on your own.
- Represent Datadog in the relevant language and security communities.
What We're Looking For
- You are an expert in at least one of .NET (C#) or Java, and you're a polyglot who can contribute idiomatically across other libraries when needed with the support of their main maintainers. For each language you use, you write clean, correct, well-tested, performant, idiomatic code.
- You have strong software-engineering fundamentals: you consistently ship modular, maintainable code with little guidance, and you leave code in substantially better shape than you found it.
- You have a product-engineering mindset: you care about user experience and product outcomes as much as the code, weigh technical trade-offs against customer impact, and help decide what to build, not just how.
- You have experience building and shipping libraries or SDKs consumed by other developers, and you understand packaging, versioning, and backward compatibility.
- You care about performance and cost, in both time and space, and you have experience measuring and optimizing to that end.
- You are operationally mature: you take full accountability for what you ship in production, even when others work on it.
- You communicate clearly in writing and in person, you drive alignment through RFCs and informal collaboration, give bad news early, and give constructive, empathetic feedback to peers.
- You have a BS/MS/PhD in a STEM field or equivalent experience.
Bonus Points
- Deep expertise across .NET or Java, including familiarity with language runtime internals and instrumentation, the JVM, bytecode instrumentation and Java agents; or the CLR/JIT/GC, IL rewriting, and DiagnosticSource/EventPipe in .NET.
- A track record of shipping across several of our languages (Go, Node.js, Python, Ruby, PHP, C/C++).
- An application security background: WAF, RASP, SAST/IAST/SCA, threat detection, or secure-by-design practices.
- Experience with auto-instrumentation, APM/distributed tracing, or code telemetry and introspection.
- A history of maintaining open-source projects, with public projects or published packages (e.g., NuGet, Maven).
- Experience with AI-assisted developer tooling or agentic workflows.
- A developer-experience or customer-support sensibility.