Staff Product Security Engineer

DataRobot
Boston, San Francisco, Seattle
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 8+ yearsEducation: bachelorsSkills: ["Leadership","Diplomatic communication","Stakeholder management","Strategic mindset","Threat modeling"]

Drive product security for DataRobot’s Federal and Commercial customers by owning FedRAMP High and DoD IL5 Authority to Operate efforts. Translate NIST 800-53 controls into engineering requirements, maintain SSPs and POA&Ms, and provide evidence during third-party audits. Build secure-by-design automation in CI/CD using Python or Go, strengthen container and Kubernetes security, and use tools like Semgrep, Trivy, and Burp Suite while engaging customers on vulnerabilities and CVE exposure.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
DataRobot
DataRobot
1 month ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 hours agoStatus: Live

Job Summary

Drive product security for DataRobot’s Federal and Commercial customers by owning FedRAMP High and DoD IL5 Authority to Operate efforts. Translate NIST 800-53 controls into engineering requirements, maintain SSPs and POA&Ms, and provide evidence during third-party audits. Build secure-by-design automation in CI/CD using Python or Go, strengthen container and Kubernetes security, and use tools like Semgrep, Trivy, and Burp Suite while engaging customers on vulnerabilities and CVE exposure.
Location: Boston, San Francisco, Seattle
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Serve as primary technical lead for the Federal Group to acquire and maintain Authority to Operate (ATO) at FedRAMP High and DoD IL5 levels.
  • •Translate NIST 800-53 controls into actionable engineering requirements for commercial developers.
  • •Write and maintain security policies (SSPs) and procedures, manage POA&Ms, and provide technical evidence during third-party audits.
  • •Automate secure-by-design processes in CI/CD using Python or Go, including tooling management for SAST, DAST, and SCA.
  • •Identify and implement container security controls and perform threat modeling to prioritize risks and educate developer teams.

Pay and Benefits

Perks:Health InsuranceDentalVisionFlexible TimePaid HolidaysParental LeaveEap

Key Requirements

  • •Must be a United States Citizen residing in the United States.
  • •8+ years of experience in information security with significant time in Product Security or AppSec roles.
  • •Deep understanding of FedRAMP authorization, NIST 800-53, and DoD Cloud Computing Security Requirements Guide (SRG).
  • •Fluent writing code in Python or Go to build security automation.
  • •Deep understanding of Linux containers and hands-on experience with security tooling (e.g., Semgrep, Trivy, Burp Suite).
Experience:8+ yearsFederal complianceProduct securityAppSec
Education:Bachelor's in Computer Science, Cybersecurity, Information Systems, or related field
Skills:LeadershipDiplomatic communicationStakeholder managementStrategic mindsetThreat modeling
Tech Stack:PythonGoCI/CDLinux containersKubernetesSemgrepTrivyBurp SuiteSASTDASTSCA

Eligibility

Nationality:US National

Company Brief

DataRobot
Provides an enterprise AI platform that automates and accelerates the end-to-end data science lifecycle, enabling organizations to build, deploy, and manage machine learning models at scale for business decisioning and predictive analytics.
Industry: AI & Machine Learning
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Boston, United States
Founded: 2012
WebsiteLinkedIn