Product Security Engineer

Databricks Databricks · Data AI · Mountain View, CA · Security

Databricks is seeking a Product Security Engineer to join their Product Security Team. The role involves managing SDLC functions for features and products, including security design reviews, threat models, manual code reviews, and exploit writing. The engineer will also support Incident Response and Vulnerability Response programs, work with SAST and DAST tools, maintain automation frameworks, and help develop security processes. Experience with threat modeling, web/cloud/systems security, applied cryptography, programming languages (Python/Java/Scala/JavaScript), scripting, automation, and fuzzing/exploit writing skills are required.

What you'd actually do

  1. Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  2. Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  3. Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  4. Work on DAST tools and related automation for auto-assessment and defect filing.
  5. Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.

Skills

Required

  • Threat Modeling process
  • Web Security
  • Cloud Security
  • Systems Security
  • Applied Cryptography
  • Python
  • Java
  • Scala
  • JavaScript
  • scripting
  • automation
  • exploit writing

Nice to have

  • Fuzzing skills

What the JD emphasized

  • FedRamp
  • PCI
  • HIPPA