Staff Product Security Engineer

Databricks Databricks · Data AI · Washington, WA · Remote · Security

Staff Product Security Engineer responsible for left-shifting SDLC processes, managing security design reviews, threat models, manual code reviews, exploit writing, and supporting incident/vulnerability response. The role also involves working with SAST/DAST tools, maintaining automation frameworks, and ensuring compliance with security standards like FedRamp, PCI, and HIPAA.

What you'd actually do

  1. Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  2. Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  3. Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  4. Work on DAST tools and related automation for auto-assessment and defect filing.
  5. Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.

Skills

Required

  • Threat Modeling process
  • Web Security
  • Cloud Security
  • Systems Security
  • Applied Cryptography
  • Python
  • Java
  • Scala
  • JavaScript
  • scripting
  • automation
  • exploit writing

Nice to have

  • Fuzzing skills

What the JD emphasized

  • security design reviews
  • threat models
  • manual code reviews
  • exploit writing
  • exploit chain creation
  • FedRamp
  • PCI
  • HIPPA