Skip to content
← Back to job listings

Staff Product Security Engineer

DataRobot · Boston, United States

External listingfull-time22 days ago

About The Role

Join DataRobot as a Staff Product Security Engineer, where you will drive security innovation and ensure our platform meets the rigorous demands of our Federal and Commercial customers. This highly technical role requires expertise in federal compliance, security engineering, automation, and customer engagement. You will serve as a subject matter expert for our Federal group, handle high-stakes customer security inquiries, and build automation using Python and Go.

  • Lead Federal Security efforts, driving the acquisition and maintenance of Authority to Operate (ATO) at FedRAMP High and DoD IL5 levels.
  • Translate complex federal controls (NIST 800-53) into actionable engineering requirements for commercial developers, and write and maintain security policies (SSPs) and procedures.
  • Develop custom automation to manage security tooling and implement "Secure-by-Design" processes in the CI/CD pipeline using Python or Go.
  • This role requires a unique blend of technical expertise, regulatory fluency, and diplomatic communication skills to navigate complex customer conversations
  • Federal Fluency: Deep understanding of the FedRAMP authorization process, NIST 800-53, and DoD Cloud Computing Security Requirements Guide (SRG)
  • Strategic Mindset: Experience determining not just how to fix a bug, but why it happened and how to prevent it systemically
  • Citizenship: Must be a United States Citizen residing in the United States
  • Soft Skills: Strong leadership skills for guiding teams and liaising with various stakeholders
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience)
  • Familiarity with Kubernetes orchestration is strongly preferred
  • 8+ years of experience working in Information Security, with significant time spent in Product Security or AppSec roles
  • Must have a deep understanding of Linux containers (internals, security isolation)
  • Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite
  • Fluent in writing code using Python or Go to build security automation
  • Even if you do not check every box we’d love to have a conversation with you and see if you might be a great fit

This is an external listing. JobSpring does not represent or verify the employer. Report this listing