Databricks Enterprise Lead Security Architect - Principal It Software Engineer

Databricks Databricks · Data AI · Mountain View, CA · Infrastructure

Lead Security Architect for Databricks IT, responsible for designing and implementing secure and scalable architectures across cloud, SaaS, and custom applications, with a focus on IAM, Zero Trust, endpoint security, and securing critical business applications and sensitive data. The role also involves building proactive security strategies, securing modern platforms (AWS, Azure, GCP), establishing least privilege, and contributing to the internal strategy for secure AI development.

What you'd actually do

  1. Design and implement secure, scalable reference architectures for the Databricks IT across Cloud Infra (Compute, DBs, Network, Storage), SaaS, Custom Built Applications, Data & AI systems.
  2. Establish and enforce security controls for: Databricks Workspace Management: Workspace isolation, Unity Catalog for data governance.
  3. SSO, SCIM user provisioning, RBAC via Un, Strong MFA best practices for enterprise identities and customers
  4. Cluster Security: User isolation, compliance with enhanced security monitoring/Compliance Security Profiles (HIPAA, PCI-DSS, FedRAMP).
  5. Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs to enhance security posture.

Skills

Required

  • cybersecurity
  • security architecture
  • enterprise platforms
  • multi-cloud environments
  • enterprise architecture
  • security features
  • network infra
  • workspace hardening
  • network segmentation/ isolation
  • automating security controls
  • Terraform
  • scripting
  • data analytics pipelines
  • SaaS integrations
  • workload isolation
  • Enterprise Security Analysis Tools
  • monitoring/security policy optimization
  • Identity and Access Management (IAM)
  • Zero Trust architecture
  • endpoint security
  • AWS
  • Azure
  • GCP
  • least privilege (PoLP)
  • secure AI development
  • Google Workspace
  • VPC configs
  • PrivateLink
  • IP Allow Lists
  • SSO
  • SCIM user provisioning
  • RBAC
  • MFA
  • Data Encryption
  • Data Exfiltration Prevention
  • Cluster Security
  • HIPAA
  • PCI-DSS
  • FedRAMP
  • Offensive Security
  • Non-human Identity Management
  • Data Loss Prevention (DLP)
  • SaaS Proxy Design
  • SASE solutions
  • Infrastructure as Code
  • incident response
  • vulnerability management
  • threat modeling
  • red teaming

Nice to have

  • Master’s degree in Computer Science specifically in Information Security or a related discipline
  • FedRAMP High systems/ GovCloud

What the JD emphasized

  • Must have direct experience designing and securing enterprise platforms in complex multi-cloud environments
  • deep knowledge of enterprise architecture and security features
  • hands-on experience automating security controls with Terraform and scripting
  • Proven expertise securing data analytics pipelines, SaaS integrations, and workload isolation in enterprise ecosystems.