Datadog
Denver, CO
Cloud Security Engineer
Feb 2026 — Present- Designed and shipped a Go risk-classification service that scores 2,000 production storage buckets on public exposure, encryption, versioning, IAM policy, blast radius, and data sensitivity, producing a ranked shortlist that enables downstream content-scanning at appropriate volumes.
- Drove the service’s production bring-up end to end, provisioning credentials, service accounts, and infrastructure via Terraform, authorizing the workload identity domain, and registering its deployment pipeline from staging through production.
- Built the notification and persistence layer of an automated remediation pipeline that routes Cloud Security Management findings to owning teams in Slack, opens Jira issues, and writes resolution status back to the originating finding, replacing manual triage with an auditable workflow across 100+ teams.
- Codified the remediation system as Terraform modules and migrated it onto a Bazel-managed IaC setup, scoping workflow execution to least-privilege principals.
- Developed Terraform modules generating SCP and RCP based guardrails across 50+ AWS accounts, reducing misconfiguration and standardizing access control through IAM, CloudTrail, and Datadog integrations.
Technical Support Engineer (concurrent)
May 2024 — Present- Support Datadog’s Log Management, Cloud Security, and Cloud Integrations products, specializing in Cloud SIEM and Cloud Security Posture Management.
- Replicate and resolve 95% of complex customer issues in sandboxed environments, delivering actionable insights that improve customer satisfaction.
- Serve as primary subject matter expert and mentor for Security and Log products, and as trusted technical advisor to enterprise customers, driving adoption and translating feedback into product improvements.