Senior Security Engineer, Incident Response

Databricks Databricks · Data AI · Amsterdam, Netherlands · Security

Senior Security Engineer on the Incident Response team at Databricks, responsible for responding to security threats, incidents, and investigations. The role involves conducting security analysis and forensics, responding to high-priority alerts, and contributing to automations and agentic capabilities to scale incident response.

What you'd actually do

  1. You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
  2. You will triage and respond to security events and alerts, ensuring quick and effective containment.
  3. You will contribute to security investigations, conducting analysis and forensics across a range of data sources to determine the timeline and impact of security events.
  4. You will build automations, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
  5. You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.

Skills

Required

  • 4+ years experience in Incident Response work OR Master's Degree AND 2+ years experience
  • Strong cloud security background in at least 1 of AWS, GCP or Azure, and working knowledge of the others.
  • Knowledge of AI/LLM and agentic capabilities, including effective prompting and use of MCP, agents and agent skills.
  • Broad security subject matter expertise.
  • Expertise in few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
  • Experience with Enterprise Security and SaaS applications.
  • Working knowledge of a SIEM and SOAR.
  • Experience building Incident Response Tooling and scripting language skills.

Nice to have

  • Prefer experience with building and operating agentic systems in a security setting.

What the JD emphasized

  • leveraging AI and agentic platforms
  • agentic capabilities
  • building and operating agentic systems in a security setting

Other signals

  • Leveraging AI and agentic platforms for autonomous capabilities
  • Building automations to scale security incident response