Staff Product Security Engineer

DataRobot, Inc.
Seattle, WA, United States
about 2 months ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Build Automation Burp Suite Cloud Computing Security Cyber Security Information Systems Continuous Integration Python (Programming Language) Linux Containers Tripwire Software Vulnerability Management
+7 more
Software Security Kubernetes Information Technology Software Coding Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

DataRobot delivers AI that maximizes impact and minimizes business risk. Our platform and applications integrate into core business processes so teams can develop, deliver, and govern AI at scale. DataRobot empowers practitioners to deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on DataRobot for AI that makes sense for their business - today and in the future., DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform meets the rigorous demands of our Federal and Commercial customers. This is a highly technical, high-impact role where you will operate at the intersection of engineering, automation, and federal compliance (FedRAMP High / DoD IL5)., You will serve as a subject matter expert for our Federal group, handle high-stakes customer security inquiries, and build automation using Python and Go. This role requires a unique blend of technical expertise, regulatory fluency, and diplomatic communication skills to navigate complex customer conversations., Federal Compliance & Strategy

  • Lead Federal Security: Serve as a primary technical lead for the DataRobot Federal Group, driving the acquisition and maintenance of Authority to Operate (ATO) at FedRAMP High and DoD IL5 levels.
  • Compliance Engineering: Translate complex federal controls (NIST 800-53) into actionable engineering requirements for commercial developers.
  • Audit & Policy Management: Write and maintain security policies (SSPs) and procedures. Develop, track, and remediate Plans of Action and Milestones (POA&Ms) and provide technical evidence during third-party audits.

Security Engineering & Automation

  • Automate Everything: Develop custom automation to manage security tooling and implement “Secure-by-Design” processes in the CI/CD pipeline using Python or Go.
  • Container Security: Identify, design, and implement controls to safeguard our containerized production environments.
  • Tooling Management: Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite).
  • Threat Modeling: Review technical designs for new features, performing threat models to prioritize risks and educate developer teams on secure coding practices.

Customer Trust & Vulnerability Management

  • Customer Engagement: Act as the external face of DataRobot Security. Work directly with customers’ security teams to resolve concerns regarding CVE exposure and architecture.
  • Customer-Centric Communication: Balance business needs with security rigor. You must be able to stand firm on security policies while maintaining strong professional relationships through clear, diplomatic, and solutions-oriented communication.

Requirements

  • Federal Fluency: Deep understanding of the FedRAMP authorization process, NIST 800-53, and DoD Cloud Computing Security Requirements Guide (SRG).
  • Technical Proficiency:
  • Fluent in writing code using Python or Go to build security automation.
  • Must have a deep understanding of Linux containers (internals, security isolation).
  • Familiarity with Kubernetes orchestration is strongly preferred.
  • Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite.
  • Strategic Mindset: Experience determining not just how to fix a bug, but why it happened and how to prevent it systemically.
  • Soft Skills: Strong leadership skills for guiding teams and liaising with various stakeholders.

Requisite Education and Experience:

  • Citizenship:Must be a United States Citizen residing in the United States.
  • 8+ years of experience working in Information Security, with significant time spent in Product Security or AppSec roles.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience).

Benefits & conditions

The talent and dedication of our employees are at the core of DataRobot’s journey to be an iconic company. We strive to attract and retain the best talent by providing competitive pay and benefits with our employees’ well-being at the core. Here’s what your benefits package may include depending on your location and local legal requirements: Medical, Dental & Vision Insurance, Flexible Time Off Program, Paid Holidays, Paid Parental Leave, Global Employee Assistance Program (EAP) and more!

DataRobot Operating Principles:

  • Wow Our Customers
  • Set High Standards
  • Be Better Than Yesterday
  • Be Rigorous
  • Assume Positive Intent
  • Have the Tough Conversations
  • Be Better Together
  • Debate, Decide, Commit
  • Deliver Results
  • Overcommunicate

About the company

DataRobot delivers AI that maximizes impact and minimizes business risk. Our AI applications and platform integrate into core business processes so teams can develop, deliver, and govern AI at scale. DataRobot empowers practitioners to deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on DataRobot for AI that makes sense for their business - today and in the future. For more information, visit our website (http://www.datarobot.com) and connect with us on LinkedIn (https://www.linkedin.com/company/datarobot/) .

DataRobot has become aware of scams involving false offers of DataRobot employment. The scams and false offers use imposter websites, email addresses, text messages, and other fraudulent means. None of these offers are legitimate, and DataRobot’s recruiting process never involves conducting interviews via instant messages, nor requires candidates to purchase products or services, or to process payments on our behalf. Please note that DataRobot does not ask for money in its recruitment process. DataRobot is committed to providing a safe and secure environment for all job applicants. We encourage all job seekers to be vigilant and protect themselves against recruitment scams by verifying the legitimacy of any job offer before providing personal information or paying any fees. Communication from our company will be sent from a verified email address using the @ datarobot.com email domain. If you receive any suspicious emails or messages claiming to be from DataRobot, please do not respond.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes ¡ World Congress 2025

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher ¡ LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter ¡ World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher ¡ LIVE

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn ¡ World Congress 2022

Videos

See all

Related articles

See all