Sr. Staff Security Engineer, Incident Response

Databricks Databricks · Data AI · Mountain View, CA · Security

Sr. Staff Security Engineer, Incident Response role at Databricks. This position focuses on leading complex security investigations, developing multi-year technology strategy for security posture, and architecting automation frameworks for incident response. The role leverages Databricks' platform for log analytics and forensics, and requires expertise in cloud security, digital forensics, and enterprise security incidents. The candidate will also mentor team members and collaborate across departments.

What you'd actually do

  1. Lead complex investigations and impact analysis, performing crisis management using the Incident Management System (IMS).
  2. Architect scalable and organized frameworks for security automation and orchestration, including pre-investigation analysis and triage of alerts.
  3. Drive or influence the organization’s direction and roadmap, leading internal conversations about major technology areas and inspiring adoption.
  4. Exhibit expert knowledge in all cloud vendors used by Databricks (AWS, Azure, GCP), deeply understanding the entire architecture of major business components and articulating their security and risk limits.
  5. Demonstrate the ability to fix difficult and company-impactful problems wherever they lie, even if outside your comfort zone.

Skills

Required

  • 12+ years of experience in security, with a strong focus on incident response, detection, and/or threat intelligence
  • Deep expertise in Incident Management and Incident Response tool development
  • Knowledge of Azure and AWS cloud concepts
  • Expertise in analyzing logs, correlating available log sources to conclude an attack scenario
  • Highly skilled in multiple areas of digital forensics (e.g., Network, Application/Log Analysis, Host/Disk, Memory Forensics/Malware Analysis, Cloud Forensics, Endpoint Forensics)
  • Detailed understanding of enterprise security incidents
  • In-depth knowledge of malware on endpoints
  • Expert understanding of MacOS security posture and architecture
  • Proficient with SIEM and SOAR platforms, EDR solutions, and forensic analysis tools
  • Exceptional ability to engage in difficult conversations, handle them appropriately, and exhibit empathy and emotional intelligence
  • Proven capability to build, mentor, and lead high-performing cybersecurity teams
  • Strong communication of technical decisions through design docs and tech talks
  • History of proactively identifying and solving issues that impact the team and company
  • Demonstrates a strong desire to help peers and collaborate effectively
  • Able to push back or say no to unreasonable stakeholder requests in a professional and constructive manner

Nice to have

  • Advanced degree with 8+ years of experience
  • Skilled in leveraging AI and automation technologies to enhance security operations and threat detection capabilities

What the JD emphasized

  • U.S. citizenship is required
  • This role will involve services that are covered by and must comply with the U.S. Government information security and federal contractor regulations