RDQ127R264 This role is open to remote candidates within the U.S., with a preference for those based in the San Francisco/ Bay Area or Seattle/Bellevue. U.S. citizenship is required. Databricks is seeking an exceptional and strategic Sr. Staff Security Engineer, Incident Response to join our Incident Response team. This pivotal role will provide decisions that have a direct impact on the long-term success of Databricks' security posture, creating solutions that enable potential future opportunities without a known path. You will play a key role in developing multi-year technology strategy for complete and critical areas of the business, encompassing multiple systems and teams, consistently delivering large-scale projects that meet company goals. The Incident Response team's mission is to rapidly, efficiently, and standardly respond to security threats, incidents, and investigations to protect our customers, employees, and enterprise data. We leverage Databricks' own platform for near-real-time log analytics, alerting, and forensics, embracing a "Security for Databricks on Databricks" philosophy. As an Sr. Staff Security Engineer, you will tackle the most technical SIRTs, drive complex, open-ended problems with no obvious path to success, act as a multiplier by enabling systems, authoring tools, or introducing policies that elevate the entire organization's productivity. The impact you will have: Strategic Impact & Technical Vision: Drive or influence the organization’s direction and roadmap, leading internal conversations about major technology areas and inspiring adoption. Provide decisions with direct, long-term impact on Databricks' success. Incident Leadership & Crisis Management: Lead complex investigations and impact analysis, performing crisis management using the Incident Management System (IMS). Engage with various stakeholders and communicate findings to executive leadership, ensuring successful navigation of major security incidents with minimal business impact. Advanced Threat Management: Exhibit expert knowledge in all cloud vendors used by Databricks (AWS, Azure, GCP), deeply understanding the entire architecture of major business components and articulating their security and risk limits. Drive the establishment of a cutting-edge threat detection and response program, significantly reducing Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to security incidents. Technical Innovation & Automation: Architect scalable and organized frameworks for security automation and orchestration, including pre-investigation analysis and triage of alerts. Understand trends and directions of the security industry within your domain and architect large-scale designs consistent with organizational and company goals. Problem Solving: Demonstrate the ability to fix difficult and company-impactful problems wherever they lie, even if outside your comfort zone. Possess a full understanding of what malicious activity looks like in each cloud layer (network, storage, compute), understanding existing logs and correlating from multiple sources during an investigation. Cross-Functional Collaboration & Mentorship: Serve as a role model and mentor to every technical member of the team. Identify areas where Databricks can share effectively with the outside world, guiding content creation and communication via presentations and blogs. Work across departments, integrating security practices into various aspects of the organization and product development lifecycle.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed