About the job
The Product Security Team at Databricks is dedicated to enhancing the Security Development Lifecycle (SDLC) processes for all code developed for customer use and internal support. Our goal is to minimize the introduction of vulnerabilities in production and to effectively manage the impact of externally identified vulnerabilities on Databricks Services.
As a key individual contributor on our product security team, you will oversee SDLC functions for various features and products. Your responsibilities will encompass security design reviews, threat modeling, manual code reviews, and exploit development. Additionally, you will provide support for Incident Response (IR) and Vulnerability Response Programs (VRP) in the event of vulnerability reports or security incidents. Collaborating with a diverse global team across the US and EMEA, you will play a critical role in maintaining our security posture.
Your Impact:
- Deliver comprehensive SDLC support for new product features developed by both engineering and non-engineering teams, including threat modeling, design reviews, and manual code assessments.
- Collaborate with other security teams to assist with incident and vulnerability management as required.
- Utilize Static Application Security Testing (SAST) tools to evaluate and discern false positives while reporting genuine issues.
- Engage with Dynamic Application Security Testing (DAST) tools and automation for streamlined assessments and defect tracking.
- Enhance and maintain the automation framework to support compliance initiatives such as FedRamp, PCI, and HIPAA.
- Adopt a risk management perspective to prioritize security efforts effectively.
- Contribute to the development and implementation of security processes to boost the productivity of the product security organization and enhance the SDLC overall.

