About the job
RDQ326R24 - This role can be based remotely anywhere in the United States.
The Product Security Team at Databricks is dedicated to enhancing the Security Development Lifecycle (SDLC) for all code developed, whether for customer use or internal support. Our goal is to proactively reduce the risk of introducing vulnerabilities into production environments and to minimize the impact of vulnerabilities identified by external sources on Databricks services.
As a key individual contributor within our product security team, you will take charge of managing SDLC functions for various features and products. Your responsibilities will encompass security design reviews, threat modeling, manual code analysis, exploit writing, and the creation of exploit chains. Additionally, you will provide support for incident response (IR) and vulnerability response programs when vulnerabilities are reported or incidents arise. Collaboration with our global team, spread across the US and EMEA, will be essential in your role.
Your Impact:
- Comprehensive SDLC support for new product features developed by engineering and non-engineering teams, including threat modeling, design reviews, and manual code assessments.
- Collaboration with other security teams to assist with incident response and vulnerability management as required.
- Utilization of SAST tools to evaluate findings, discern false positives, and document legitimate issues.
- Engagement with DAST tools and automation for efficient assessments and defect reporting.
- Maintenance and enhancement of the automation framework to accommodate various security compliance standards such as FedRamp, PCI, and HIPAA.
- Adoption of a risk management perspective in prioritizing security initiatives.
- Contribution to the development and implementation of security processes to enhance productivity within the product security organization and the overall SDLC.

