Sr. Manager, Security — Continuous Monitoring v 2.0

DatabricksRemote - California, CA
$182,900 - $314,250Remote

About The Position

Databricks is looking for a Senior Manager to lead the Continuous Monitoring (ConMon) team. This team builds and operates the engineering infrastructure that keeps Databricks' security control posture visible, measurable, and defensible at all times. The role involves owning the engineering function that measures whether Databricks' security controls are working across cloud infrastructure, identity, SaaS, and enterprise systems, and turning that measurement into a reliable output for the Security organization and its auditors. This includes demonstrating control posture against frameworks like SOC 2, ISO 27001, FedRAMP, PCI DSS, and emerging AI governance requirements. The role requires technical depth to review the team's work and judgment to prioritize controls where measurement reduces risk. Responsibilities include growing and developing the team, setting vision and strategy, advocating for resources, and building partnerships across various departments.

Requirements

  • 2+ years of prior management experience leading Engineering or Security engineering teams.
  • Typically 12+ years of experience, or an advanced degree plus 8 years, preferably focused on security engineering, security posture monitoring, or compliance automation.
  • Sufficient technical depth to review the work of the team: can read and critique Python automation, evaluate an integration architecture, and assess whether a monitoring approach will hold up in production.
  • Solid understanding of security controls and where they fail in practice — identity and access, configuration management, logging coverage, vulnerability management, and data protection — enough to judge whether a given measurement is telling you anything useful.
  • Solid cloud security knowledge across at least one major platform (AWS, Azure, GCP) — IAM, audit logging, CSPM concepts, and cloud-native security services.
  • Working knowledge of compliance frameworks (SOC 2, ISO 27001, FedRAMP, or equivalent) at a level sufficient to assess whether a control monitoring design will satisfy an auditor.
  • Previous experience building security posture monitoring or compliance automation at scale, with attention to accuracy, coverage, and cost tradeoffs (experience with Databricks is preferred).
  • Focused on defining and driving efficiencies and improvements within the team; accountable for defining and achieving targets (e.g. OKRs, KPIs).
  • Makes effective priority decisions on resourcing and alignment within the team.
  • Strong communicator across technical, GRC, and executive audiences — can explain automation architecture to auditors and compliance requirements to engineers.

Nice To Haves

  • Experience with cloud security posture management (CSPM/SSPM) platforms at an architecture level.
  • Experience with FedRAMP continuous monitoring programs at a leadership level.
  • Hands-on background with GRC automation platforms (Vanta, Drata, ServiceNow GRC, Archer, or equivalent) at an implementation or architecture level.
  • Experience building automated monitoring for AI system controls and AI governance frameworks.
  • Track record of building or scaling a security measurement or compliance engineering function from early-stage to mature operations.
  • Background in security operations, detection engineering, or security architecture that informs which controls are worth measuring.
  • Experience with front-end development.
  • CISSP, CISM, CISA, or equivalent certifications.

Responsibilities

  • Hire strong Security Software Engineers who bring genuine engineering skill to compliance automation.
  • Support engineers in their career development with clear, specific feedback; develop senior ICs into technical leaders and grow the next generation of security engineering managers.
  • Set and hold a high bar for engineering quality: code review standards, reliability and observability expectations for automation pipelines, and documentation that remains useful across audit cycles and team changes.
  • Build a team that combines GRC domain knowledge with software engineering discipline, and hire for both.
  • Own the strategy and roadmap for Databricks' continuous monitoring platform — control state collection at cloud scale, continuous posture assessment, security and GRC tooling integration, and remediation tracking.
  • Define what the program measures and why: prioritize the controls whose failure would matter most to Databricks' security posture, rather than defaulting to the set a given framework happens to enumerate.
  • Ensure coverage keeps pace with the business — new cloud environments, new products and services, new certifications and regulatory obligations, and AI governance controls that current tooling does not yet assess.
  • Reduce manual evidence collection systematically; set and track targets for automated control coverage, freshness, and audit burden on Engineering teams.
  • Own the accuracy of the team's output, including false positive rates; findings should be reliable enough that control owners act on them without re-verification.
  • Own the security posture dashboards, metrics, and reporting that give Security and GRC leadership an accurate, timely view of control health across the company.
  • Define the metrics the program reports on — control coverage, drift, time-to-remediate, and where the organization is exposed — and build the reporting that leadership uses to make security investment and prioritization decisions.
  • Present the team's findings to senior leadership: control gaps and drift, their risk implications, and the effort required to remediate them.
  • Make the same measurement data serve both audiences: evidence an auditor will accept, and signal the company can act on.
  • Establish productive working relationships with GRC (SAC, SAF, Governance, Risk Management, TPRM), Enterprise Security, Product Security, Security Operations, IT, Legal, and Engineering leadership — the teams who own the controls, the evidence, and the remediation.
  • Partner with Enterprise Security and Product Security so control measurement reflects how systems are actually built and configured, and feed coverage gaps back to the teams who own those controls.
  • Partner with SAC and SAF to ensure monitoring output meets auditor and 3PAO evidence standards, and with Governance to keep control monitoring aligned to policy as standards evolve.
  • Coordinate with Risk Management and Security Operations on metric definitions and reporting boundaries so the organization gets one coherent picture of control health rather than three overlapping ones.
  • Coordinate execution across teams to unblock cross-cutting initiatives: telemetry gaps in Engineering-owned systems, GRC platform migrations, and multi-quarter automation programs.
  • Make effective priority and resourcing decisions within the team; be accountable for defining and achieving the team's OKRs and KPIs.
  • Lead build-vs.-buy evaluations for CSPM, SSPM, GRC automation, and security posture tooling; assess platforms on integration capability, measurement fidelity, maintenance cost, and fit with existing pipelines, and make the recommendation to Security and GRC leadership.
  • Keep the program's operating costs defensible — cloud spend, tooling, and the engineering time monitoring consumes — and be able to explain the tradeoff between monitoring coverage and what it costs to run at scale.
  • Track what the program will need to measure next — changes in Databricks' architecture and threat exposure, new SOC 2 criteria, FedRAMP continuous monitoring changes, and AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) — and translate them into roadmap decisions early enough to build for them.

Benefits

  • Eligibility for annual performance bonus
  • Equity
  • Comprehensive benefits and perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service