companyDatabricks logo

Product Security Engineer

DatabricksUnited States
Remote Full-time $161.5K/yr - $261.3K/yr

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Experience

Qualifications

What We Look For:2-4 years of experience with threat modeling and the ability to identify design flaws from data flow diagrams. Familiarity with at least two of the following domains: Web Security, Cloud Security, Systems Security, and Applied Cryptography. Proficiency in programming languages such as Python, Java, Scala, or JavaScript, with the ability to analyze code to detect security vulnerabilities. Experience in scripting and automation related to exploits. Fuzzing skills are a valuable asset. Strong skills in exploit writing are highly desirable.

About the job

RDQ326R24 - This role can be based remotely anywhere in the United States.

The Product Security Team at Databricks is dedicated to enhancing the Security Development Lifecycle (SDLC) for all code developed, whether for customer use or internal support. Our goal is to proactively reduce the risk of introducing vulnerabilities into production environments and to minimize the impact of vulnerabilities identified by external sources on Databricks services.

As a key individual contributor within our product security team, you will take charge of managing SDLC functions for various features and products. Your responsibilities will encompass security design reviews, threat modeling, manual code analysis, exploit writing, and the creation of exploit chains. Additionally, you will provide support for incident response (IR) and vulnerability response programs when vulnerabilities are reported or incidents arise. Collaboration with our global team, spread across the US and EMEA, will be essential in your role.

Your Impact:

  • Comprehensive SDLC support for new product features developed by engineering and non-engineering teams, including threat modeling, design reviews, and manual code assessments.
  • Collaboration with other security teams to assist with incident response and vulnerability management as required.
  • Utilization of SAST tools to evaluate findings, discern false positives, and document legitimate issues.
  • Engagement with DAST tools and automation for efficient assessments and defect reporting.
  • Maintenance and enhancement of the automation framework to accommodate various security compliance standards such as FedRamp, PCI, and HIPAA.
  • Adoption of a risk management perspective in prioritizing security initiatives.
  • Contribution to the development and implementation of security processes to enhance productivity within the product security organization and the overall SDLC.

About Databricks

Databricks is a cutting-edge technology company that focuses on simplifying and improving data analytics and machine learning through its unified platform. We are committed to fostering a culture of innovation and collaboration, empowering our employees to excel in their roles and drive impactful results.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.