> Markdown version of [/jobs/ext/534087-security-engineer-2-cyber-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/534087-security-engineer-2-cyber-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer 2 - Cyber Threat Intelligence - **Company:** Datadog - **Location:** New York, NY, United States - **Salary:** $140,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Apple Mac Systems, Cloud Engineering, Static Program Analysis, Linux, Reverse Engineering, Software Engineering, Datadog, Cybercrime - **Published:** June 5, 2026 - **Apply:** https://careers.datadoghq.com/detail/7982345/?gh_jid=7982345 ## About the Role * Experienced in writing and presenting operational and technical intelligence for threat detection, response, and security stakeholders. * Skilled in partnering with detection and response teams to support investigations, improve response playbooks, and prioritize detection opportunities based on adversary tactics, techniques, and procedures (TTPs). * Familiar with information-sharing communities and able to apply sound judgment when handling and operationalizing TLP-designated intelligence. * Experienced in identifying and responding to large-scale emerging threats, including supply chain compromises, industry-wide campaigns, and exploitation of newly disclosed vulnerabilities. * Experienced in dynamic/static analysis of Linux and MacOS malware and in tracking cloud-native cybercrime and nation-state threat actors. * Proficient in developing threat intelligence tooling and automation through software development and scripting. Nice to Have: * Experience presenting at security conferences and publishing threat research. * Experience with malware reverse engineering. To conform to US export control regulations, candidates should be eligible for any required authorizations from the US government. This job is available in various departments within our company; to conform to US export control regulations, some of these roles may require candidates to be eligible for any required authorizations from the US government. ## Description As a Security Engineer 2 on the Cyber Threat Intelligence team, you will help Datadog stay ahead of evolving threats by identifying, analyzing, and operationalizing intelligence on threat actors, campaigns, and emerging threats. Working within Security Engineering, you will partner closely with security teams to translate intelligence into actionable security improvements across the company. You will serve as a subject matter expert on how the cyber threat landscape intersects with Datadog and contribute to intelligence-led decision making during both steady-state operations and active security incidents. This role provides opportunities to influence detection, response, and security strategy through technical analysis, collaboration, and intelligence-driven initiatives. At Datadog, we place value in our office culture - the relationships and collaboration it builds and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do: * Develop and maintain tooling that automates the collection, processing, analysis, and dissemination of threat intelligence. * Assess emerging vulnerabilities, threat activity, and security events to help stakeholders understand potential impact to Datadog. * Conduct threat hunting and infrastructure analysis to identify adversary activity relevant to Datadog and improve defensive controls. * Partner with security teams to operationalize intelligence into detections, investigations, and response workflows. * Coordinate with information-sharing communities to gather, evaluate, and disseminate actionable intelligence. * Produce technical briefings, threat reports, and intelligence products for security and engineering stakeholders. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)