Skip to content
DatadogDatadog

Security Engineer 2 - Cyber Threat Intelligence

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

About the job

What You’ll Do

  • Develop and maintain tooling that automates the collection, processing, analysis, and dissemination of threat intelligence.
  • Assess emerging vulnerabilities, threat activity, and security events to help stakeholders understand potential impact to Datadog.
  • Conduct threat hunting and infrastructure analysis to identify adversary activity relevant to Datadog and improve defensive controls.
  • Partner with security teams to operationalize intelligence into detections, investigations, and response workflows.
  • Coordinate with information-sharing communities to gather, evaluate, and disseminate actionable intelligence.
  • Produce technical briefings, threat reports, and intelligence products for security and engineering stakeholders.

Who You Are

  • Experienced in writing and presenting operational and technical intelligence for threat detection, response, and security stakeholders.
  • Skilled in partnering with detection and response teams to support investigations, improve response playbooks, and prioritize detection opportunities based on adversary tactics, techniques, and procedures (TTPs).
  • Familiar with information-sharing communities and able to apply sound judgment when handling and operationalizing TLP-designated intelligence.
  • Experienced in identifying and responding to large-scale emerging threats, including supply chain compromises, industry-wide campaigns, and exploitation of newly disclosed vulnerabilities.
  • Experienced in dynamic/static analysis of Linux and MacOS malware and in tracking cloud-native cybercrime and nation-state threat actors.
  • Proficient in developing threat intelligence tooling and automation through software development and scripting.

Nice to Have

  • Experience presenting at security conferences and publishing threat research.
  • Experience with malware reverse engineering.

Skills

Threat Intelligence, Threat Hunting, Malware Analysis, Linux Malware Analysis, Macos Malware Analysis, Scripting, Software Development, Ttp Analysis, Threat Reporting, Information Sharing Communities

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.