Senior Datadog Security & Observability Engineer
Description
Keeper is hiring a talented Senior DataDog Engineer to join our DevOps team. This can be a 100% remote position from select locations with an opportunity to work a hybrid schedule for candidates based in the El Dorado Hills, CA or Chicago, IL metro area.
Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations globally. Keeper is published in 23 languages and sold in over 150 countries. Join one of the fastest-growing cybersecurity companies and help scale the Datadog platform that supports Keeper’s security visibility, detection maturity and operational readiness.
About Keeper
Keeper Security is one of the fastest-growing cybersecurity software companies that protects thousands of organizations and millions of people in over 150 countries. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Its core offering, KeeperPAM®, is an AI-enabled, cloud-native platform that protects all users, devices and infrastructure from cyber attacks. Recognized for its innovation in the Gartner Magic Quadrant for Privileged Access Management (PAM), Keeper secures passwords and passkeys, infrastructure secrets, remote connections and endpoints with role-based enforcement policies, least privilege and just-in-time access. Learn why Keeper is trusted by leading organizations to defend against modern adversaries at KeeperSecurity.com.
About the Job
This is a Datadog-first security engineering role focused on detection engineering, SIEM operations and security observability across Keeper’s production and corporate environments. The ideal candidate has deep, hands-on experience administering and scaling Datadog, including Cloud SIEM, log management, security monitoring, dashboards, monitors and telemetry pipelines. Reporting to the Director of IT and Security, this role will partner closely with Security Operations, Infrastructure, SRE and Engineering teams to ensure logs, metrics, traces and endpoint signals are actionable, scalable and aligned to real-world threat scenarios. General SIEM experience without substantial production experience in Datadog will not be sufficient for this role.
Responsibilities
Own and continuously improve Datadog Cloud SIEM, security monitoring and observability capabilities across production and corporate environments
Design, build and maintain detection and telemetry capabilities across Datadog, SentinelOne, Wiz and related security platforms
Develop, test and tune high-fidelity Datadog detection rules aligned to real-world attack scenarios and adversary behaviors
Improve alert quality by reducing false positives, eliminating noise and increasing detection accuracy
Design and maintain Datadog log pipelines, processors, parsing rules, facets, indexes, archives and retention strategies
Implement and mature detection-as-code practices for scalable, version-controlled and testable rule management
Define and enforce logging, telemetry and instrumentation standards across cloud infrastructure, applications, endpoints and identity systems
Build and optimize log ingestion, parsing, normalization, enrichment and routing workflows
Automate onboarding of new telemetry sources and improve visibility across production and corporate environments
Correlate signals across Datadog, EDR, cloud, identity and security platforms to improve detection depth and investigation quality
Partner with Security Operations to improve triage workflows, incident response readiness and escalation quality
Build Datadog dashboards, monitors, analytics and reporting that support operational decision-making across Security, SRE and Engineering
Map and maintain detection coverage against MITRE ATT&CK and identify telemetry and detection gaps
Perform detection gap assessments and evolve use cases based on threat intelligence, threat hunting and emerging risks
Collaborate with cloud, infrastructure, product and compliance teams to strengthen secure logging and observability patterns throughout the software development lifecycle
Use AI-assisted tools such as Claude, ChatGPT or similar platforms to support query development, detection engineering, investigations, automation and technical documentation
Requirements
5+ years of experience in detection engineering, SIEM engineering, security engineering, security observability or a related technical role
Deep, hands-on production experience administering and engineering Datadog in complex cloud environments
Strong experience with Datadog Cloud SIEM, Log Management, Security Monitoring, dashboards, monitors and alerting
Experience designing and maintaining Datadog log pipelines, processors, parsing rules, facets, indexes and retention strategies
Experience building, testing and tuning detection rules, correlation logic and investigation workflows in Datadog
Strong understanding of security telemetry across cloud, endpoint, identity and application environments
Experience with log parsing, normalization, enrichment and pipeline management
Strong knowledge of AWS and cloud-native infrastructure
Proficiency with scripting or automation using Python, PowerShell or similar languages
Experience using Datadog APIs, Terraform or similar infrastructure-as-code tools to automate configuration and platform management
Solid understanding of modern detection strategies, attacker behaviors and the MITRE ATT&CK framework
Ability to troubleshoot complex issues across logs, metrics, traces, infrastructure and application telemetry
Strong communication skills and the ability to collaborate across Security Operations, Engineering, Infrastructure and SRE teams
Ability and willingness to use AI-assisted tools effectively to improve query development, detection analysis, troubleshooting, automation and documentation
Preferred Qualifications
Experience with SentinelOne, Wiz or related cloud and endpoint security platforms
Experience with Datadog Application Performance Monitoring, Infrastructure Monitoring, distributed tracing or synthetic monitoring
Experience optimizing Datadog ingestion volume, indexing, retention and platform cost
Experience with SOAR, workflow automation or response orchestration
Familiarity with Sigma or other detection-as-code frameworks
Experience operating Datadog across large-scale, multi-account or multi-region AWS environments
Experience in high-scale SaaS, cloud-native or security product environments
Familiarity with zero-trust architectures, identity-centric security and privileged access management
Bachelor’s degree in Computer Science, Engineering, or related field
Benefits
Medical, Dental & Vision (inclusive of domestic partnerships)
Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
Voluntary Short/Long Term Disability Insurance
401K (Roth/Traditional)
A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
Above market annual bonuses
Keeper Security, Inc. is an equal opportunity employer and participant in the U.S. Federal E-Verify program. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Classification: Exempt