DataRobot delivers AI that maximizes impact and minimizes business risk. Our platform and applications integrate into core business processes so teams can develop, deliver, and govern AI at scale.
DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform meets the rigorous demands of our Federal and Commercial customers. This highly technical, high‑impact role will operate at the intersection of engineering, automation, and federal compliance (FedRAMP High / DoD IL5).
Key Responsibilities
- Federal Compliance & Strategy Lead
- Serve as primary technical lead for the DataRobot Federal Group, driving acquisition and maintenance of Authority to Operate (ATO) at FedRAMP High and DoD IL5 levels.
- Translate complex federal controls (NIST 800‑53) into actionable engineering requirements for commercial developers.
- Audit & Policy Management
- Write and maintain security policies (SSPs) and procedures.
- Develop, track, and remediate Plans of Action & Milestones (POA&Ms) and provide technical evidence during third‑party audits.
- Security Engineering & Automation
- Develop custom automation to manage security tooling and implement "Secure-by-Design" processes in the CI/CD pipeline using Python or Go.
- Identify, design, and implement controls to safeguard containerized production environments.
- Deploy and manage security testing tools such as Semgrep, Trivy, and Burp Suite.
- Perform threat modeling to prioritize risks and educate developer teams on secure coding practices.
- Customer Trust & Vulnerability Management
- Act as the external face of DataRobot Security, engaging with customers’ security teams to resolve CVE exposure and architectural concerns.
- Balance business needs with security rigor, maintaining strong professional relationships through clear, diplomatic communication.
Skills & Experience
- Deep understanding of FedRAMP authorization process, NIST 800‑53, and DoD Cloud Computing Security Requirements Guide (SRG).
- Fluent in writing code in Python or Go to build security automation.
- Deep understanding of Linux container internals and security isolation; familiarity with Kubernetes orchestration is strongly preferred.
- Hands‑on experience with security tools such as Semgrep, Trivy, and Burp Suite.
- Strategic mindset to address root causes and systemically prevent issues.
- Strong leadership skills for guiding teams and liaising with stakeholders.
Education & Experience
- Must be a United States Citizen residing in the United States.
- 8+ years of experience in Information Security, with significant time in Product Security or Application Security roles.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience).
Benefits
- Competitive pay and benefits.
- Medical, Dental, and Vision Insurance.
- Flexible Time Off Program.
- Paid Holidays and Paid Parental Leave.
- Global Employee Assistance Program (EAP).
- Other benefits as per location and legal requirements.
Equal Employment Opportunity
DataRobot is proud to be an Equal Employment Opportunity and affirmative action employer. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, gender identity, age, veteran status, disability status, or any other protected characteristic. We are committed to providing reasonable accommodations for applicants with physical or mental disabilities. Please see the United States Department of Labor’s EEO poster and EEO poster supplement for additional information.