← Back to results

Staff Security Engineer, Incident Response

Join Databricks as a Staff Security Engineer to lead incident response efforts and enhance security capabilities using AI and automation.

Location
Remote - California
Compensation
Not disclosed
Level
staff
Type
full time · Remote

Posted by employer 21 hours ago

First seen on Joblaze 2 hours ago

Last verified on the company career page 2 hours ago

What you'll build

  • Respond to incidents as part of a distributed 24x7 operations
  • Triage and respond to security events and alerts
  • Conduct analysis and forensics across data sources
  • Develop solutions leveraging AI and agentic platforms
  • Communicate technical decisions and mentor junior responders

Must have

  • Active or current US GOV Secret clearance eligibility; Top Secret preferred
  • Bachelor's Degree AND 7+ years experience in Incident Response work OR Master's Degree AND 5+ years experience
  • Cloud security expertise in at least 1 of AWS, GCP or Azure
  • Proficiency in AI/LLM and agentic capabilities
  • Expertise in core IR skills

Nice to have

  • Experience with Enterprise Security and SaaS applications
  • Working knowledge of a SIEM and SOAR
  • Experience building Incident Response Tooling
  • Scripting language skills
  • Experience with AI coding tools

AI in the day-to-day

Leveraging AI and agentic platforms to deliver autonomous capabilities and expedite work.

Requirements

Experience
5–7 years
Education
Bachelor's degree

Not disclosed in this posting: compensation, visa sponsorship.

Joblaze summary

In the role of Staff Security Engineer on the Incident Response team at Databricks, the individual will engage in security analysis, respond to high-priority alerts, and contribute to automation efforts. Key skills include cloud security expertise across AWS, GCP, or Azure, along with proficiency in AI and incident response tooling. This position is suited for experienced professionals with a strong background in incident response and security analysis, ideally holding a bachelor's or master's degree and relevant certifications. The team operates in a collaborative environment, leveraging Databricks' own platform for security operations.

Joblaze insights

Quick facts

Is the Staff Security Engineer, Incident Response role remote?
Yes — Databricks lists this as a fully remote position.
How much experience is required?
5–7 years of relevant experience for this Staff Security Engineer, Incident Response role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, AWS, Access Security, Azure, Compute Security, DFIR.
What seniority level is this role?
Databricks targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Security Engineer, Incident Response role at Databricks.

From the original posting

RDQ227R1180

While candidates in the listed location(s) are encouraged for this role, candidates in other locations (US based) will be considered.

The Incident Response team's mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We're a tight-knit team of security incident responders and incident handlers doing "Security for Databricks on Databricks", using our own platform to create near-real-time log analytics, alerting and forensics.

You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.

The impact you will have:

  • You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
  • You will triage and respond to security events and alerts, ensuring quick and effective containment.
  • You will conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events.
  • You will provide technical leadership and influence team direction.
  • You will develop solutions, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
  • You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.

What we look for:

  • Must have an active or current US GOV Secret clearance eligibility; Top Secret preferred.
  • Bachelor's Degree AND 7+ years experience in Incident Response work OR Master's Degree AND 5+ years experience.
  • Cloud security expertise in at least 1 of AWS, GCP or Azure, and proficiency in the others.
  • Proficiency in AI/LLM and agentic capabilities. Prefer experience with building and operating agentic systems in a security setting.
  • Broad security subject matter expertise.
  • Expertise in a few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
  • Experience with Enterprise Security and SaaS applications.
  • Working knowledge of a SIEM and SOAR.
  • Experience building Incident Response Tooling, scripting language skills and experience with AI coding tools.

About Databricks

Benefits

Standard company text repeated across Databricks's postings is omitted here.

Similar positions

Databricks
Staff Security Engineer, Incident Response
Databricks · Belgium; Finland; Remote - Denmark; Remote - France; Remote - Germany; Remote - Italy; Remote - Netherlands; Remote - Spain; Remote - Sweden; Remote - United Kingdom; Switzerland
Databricks
Staff Security Field Engineer
Databricks · Remote - California
Databricks
Staff Enterprise Security Engineer
Databricks · Remote - California
Databricks