Staff Product Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

DataRobot · 6 hours ago

Staff Product Security Engineer

DataRobot delivers AI that maximizes impact and minimizes business risk. They are seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring their platform meets the rigorous demands of Federal and Commercial customers.

AI InfrastructureEnterprise SoftwareMachine Learning
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Lead Federal Security: Serve as a primary technical lead for the DataRobot Federal Group, driving the acquisition and maintenance of Authority to Operate (ATO) at FedRAMP High and DoD IL5 levels
Compliance Engineering: Translate complex federal controls (NIST 800-53) into actionable engineering requirements for commercial developers
Audit & Policy Management: Write and maintain security policies (SSPs) and procedures. Develop, track, and remediate Plans of Action and Milestones (POA&Ms) and provide technical evidence during third-party audits
Automate Everything: Develop custom automation to manage security tooling and implement "Secure-by-Design" processes in the CI/CD pipeline using Python or Go
Container Security: Identify, design, and implement controls to safeguard our containerized production environments
Tooling Management: Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite)
Threat Modeling: Review technical designs for new features, performing threat models to prioritize risks and educate developer teams on secure coding practices
Customer Engagement: Act as the external face of DataRobot Security. Work directly with customers' security teams to resolve concerns regarding CVE exposure and architecture
Customer-Centric Communication: Balance business needs with security rigor. You must be able to stand firm on security policies while maintaining strong professional relationships through clear, diplomatic, and solutions-oriented communication

Qualification

Federal ComplianceSecurity AutomationPythonGoNIST 800-53Linux ContainersKubernetesSecurity ToolsCustomer EngagementDiplomatic CommunicationLeadership Skills

Required

Must be a United States Citizen residing in the United States
8+ years of experience working in Information Security, with significant time spent in Product Security or AppSec roles
Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience)
Deep understanding of the FedRAMP authorization process, NIST 800-53, and DoD Cloud Computing Security Requirements Guide (SRG)
Fluent in writing code using Python or Go to build security automation
Must have a deep understanding of Linux containers (internals, security isolation)
Strong leadership skills for guiding teams and liaising with various stakeholders

Preferred

Familiarity with Kubernetes orchestration is strongly preferred
Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite
Experience determining not just how to fix a bug, but why it happened and how to prevent it systemically

Benefits

Medical, Dental & Vision Insurance
Flexible Time Off Program
Paid Holidays
Paid Parental Leave
Global Employee Assistance Program (EAP)

Company

DataRobot

company-logo
DataRobot provides AI technology and ROI enablement services to global enterprises.

Funding

Current Stage
Late Stage
Total Funding
$1.05B
Key Investors
Snowflake VenturesAltimeter CapitalSapphire Ventures
2021-06-27Series G· $300M
2020-12-09Series F· $50M
2020-11-17Series F· $270M

Leadership Team

leader-logo
Debanjan Saha
Chief Executive Officer
linkedin
leader-logo
Brian Brown
Chief Financial and Legal Officer
linkedin
Company data provided by crunchbase