Senior Datadog Security – Observability Engineer
Posted 8hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Datadog engineer scaling detection engineering and security observability for Keeper Security’s cybersecurity platform. Building SIEM rules, telemetry pipelines, dashboards, and monitoring across AWS environments.
Responsibilities:
- Own and continuously improve Datadog Cloud SIEM, security monitoring and observability capabilities across production and corporate environments
- Design, build and maintain detection and telemetry capabilities across Datadog, SentinelOne, Wiz and related security platforms
- Develop, test and tune high-fidelity Datadog detection rules aligned to real-world attack scenarios and adversary behaviors
- Improve alert quality by reducing false positives, eliminating noise and increasing detection accuracy
- Design and maintain Datadog log pipelines, processors, parsing rules, facets, indexes, archives and retention strategies
- Implement and mature detection-as-code practices for scalable, version-controlled and testable rule management
- Define and enforce logging, telemetry and instrumentation standards across cloud infrastructure, applications, endpoints and identity systems
- Build and optimize log ingestion, parsing, normalization, enrichment and routing workflows
- Automate onboarding of new telemetry sources and improve visibility across production and corporate environments
- Correlate signals across Datadog, EDR, cloud, identity and security platforms to improve detection depth and investigation quality
- Partner with Security Operations to improve triage workflows, incident response readiness and escalation quality
- Build Datadog dashboards, monitors, analytics and reporting that support operational decision-making across Security, SRE and Engineering
- Map and maintain detection coverage against MITRE ATT&CK and identify telemetry and detection gaps
- Perform detection gap assessments and evolve use cases based on threat intelligence, threat hunting and emerging risks
- Collaborate with cloud, infrastructure, product and compliance teams to strengthen secure logging and observability patterns throughout the software development lifecycle
- Use AI-assisted tools such as Claude, ChatGPT or similar platforms to support query development, detection engineering, investigations, automation and technical documentation
Requirements:
- 5+ years of experience in detection engineering, SIEM engineering, security engineering, security observability or a related technical role
- Deep, hands-on production experience administering and engineering Datadog in complex cloud environments
- Strong experience with Datadog Cloud SIEM, Log Management, Security Monitoring, dashboards, monitors and alerting
- Experience designing and maintaining Datadog log pipelines, processors, parsing rules, facets, indexes and retention strategies
- Experience building, testing and tuning detection rules, correlation logic and investigation workflows in Datadog
- Strong understanding of security telemetry across cloud, endpoint, identity and application environments
- Experience with log parsing, normalization, enrichment and pipeline management
- Strong knowledge of AWS and cloud-native infrastructure
- Proficiency with scripting or automation using Python, PowerShell or similar languages
- Experience using Datadog APIs, Terraform or similar infrastructure-as-code tools to automate configuration and platform management
- Solid understanding of modern detection strategies, attacker behaviors and the MITRE ATT&CK framework
- Ability to troubleshoot complex issues across logs, metrics, traces, infrastructure and application telemetry
- Strong communication skills and the ability to collaborate across Security Operations, Engineering, Infrastructure and SRE teams
- Ability and willingness to use AI-assisted tools effectively to improve query development, detection analysis, troubleshooting, automation and documentation
- Preferred: Experience with SentinelOne, Wiz or related cloud and endpoint security platforms
- Preferred: Experience with Datadog Application Performance Monitoring, Infrastructure Monitoring, distributed tracing or synthetic monitoring
- Preferred: Experience optimizing Datadog ingestion volume, indexing, retention and platform cost
- Preferred: Experience with SOAR, workflow automation or response orchestration
- Preferred: Familiarity with Sigma or other detection-as-code frameworks
- Preferred: Experience operating Datadog across large-scale, multi-account or multi-region AWS environments
- Preferred: Experience in high-scale SaaS, cloud-native or security product environments
- Preferred: Familiarity with zero-trust architectures, identity-centric security and privileged access management
- Preferred: Bachelor’s degree in Computer Science, Engineering, or related field
Benefits:
- Medical, Dental & Vision (inclusive of domestic partnerships)
- Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
- Voluntary Short/Long Term Disability Insurance
- 401K (Roth/Traditional)
- A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
- Above market annual bonuses


















