Staff Product Security Engineer

Databricks
United States
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Security design","Threat modeling","Code review","Exploit writing","Automation"]

A senior contributor on the Product Security team focused on strengthening the SDLC for Databricks’ products. You will lead security design reviews, threat modeling, manual code reviews, and exploit development, plus support incident response and vulnerability response programs. This role requires cross‑team collaboration across US/EMEA, remote work within the United States, and ongoing automation of security tooling and compliance activities.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Databricks
Databricks
1 year ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

A senior contributor on the Product Security team focused on strengthening the SDLC for Databricks’ products. You will lead security design reviews, threat modeling, manual code reviews, and exploit development, plus support incident response and vulnerability response programs. This role requires cross‑team collaboration across US/EMEA, remote work within the United States, and ongoing automation of security tooling and compliance activities.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Manage SDLC functions for features and products within Databricks, including security design reviews, threat models, manual code reviews, and exploit chain creation
  • •Support Incident Response and Vulnerability Response programs when vulnerabilities are reported or security incidents occur
  • •Work with SAST/DAST outputs to evaluate findings, identify false positives, and file defects for real issues
  • •Develop and maintain automation for security assessments and defect filing, and expand automation for different security compliances such as FedRamp, PCI, HIPAA
  • •Prioritize security risk management to improve overall productivity of the product security organization and SDLC processes

Key Requirements

  • •3-10 years experience with threat modeling and identifying design issues from data-flow diagrams
  • •Proficiency in one or more of Python, Java, Scala, or JavaScript and ability to read code to find security defects
  • •Solid understanding of at least two domains among Web Security, Cloud Security, Systems Security, and Applied Cryptography
  • •Strong scripting and automation skills for exploits
  • •Exploit writing skills are highly requested; fuzzing skills are a plus
Experience:SecurityCybersecurity
Skills:Security designThreat modelingCode reviewExploit writingAutomation
Languages:English
Tech Stack:PythonJavaScalaJavaScriptSASTDASTFuzzing

Company Brief

Databricks
Provides a unified data analytics platform powered by Apache Spark to simplify building, deploying, and scaling data engineering, data science, and machine learning workloads for enterprises.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: San Francisco, United States
Founded: 2013
WebsiteLinkedIn