About the job
The Product Security Team at Databricks is dedicated to seamlessly integrating security throughout the Software Development Lifecycle (SDLC). Our primary goal is to ensure that all code written for customer use or internal support is rigorously examined to minimize the introduction of new vulnerabilities and reduce the impact of those identified externally on Databricks Services.
As a Senior Staff Product Security Engineer, you will play a pivotal role as an individual contributor on our product security team, overseeing SDLC functions for various features and products at Databricks. Your responsibilities will encompass security design reviews, threat modeling, manual code assessments, exploit development, and incident response support. You will collaborate with a globally distributed team across the US and EMEA.
Your Contributions Will Include:
- Providing comprehensive SDLC support for new product features developed by engineering and non-engineering teams, including threat modeling and design reviews.
- Collaborating with other security teams to assist with incident response and vulnerability management as needed.
- Utilizing SAST tools to identify and assess false positives and document legitimate security issues.
- Engaging with DAST tools and automating processes for continuous assessment and defect tracking.
- Enhancing the automation framework to support compliance with various security standards such as FedRamp, PCI, and HIPAA.
- Adopting a risk management approach to prioritize security measures effectively.
- Assisting in the development and implementation of security processes that enhance the productivity of the product security organization and the SDLC.
What We Seek:
- 5-10 years of experience with threat modeling and the ability to identify design flaws based on data flow diagrams.
- A strong foundation in at least two of the following areas: web security, cloud security, systems security, and applied cryptography.
- Proficiency in programming languages such as Python, Java, Scala, or JavaScript, with the capability to analyze code for security vulnerabilities.
- Expertise in scripting and automation for exploit development.
- Fuzzing experience is a plus.
- Strong skills in exploit writing are highly desirable.
