Talent.com
Product Security Engineer

Product Security Engineer

Databricks Inc.San Francisco, CA, United States
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Overview

RDQ326R24 - This role can be based remotely anywhere in the United States.

The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.

You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You will work with a global team, spread across various locations in the US and EMEA.

Responsibilities

  • Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  • Work on DAST tools and related automation for auto-assessment and defect filing.
  • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
  • Prioritize security from a risk management perspective, rather than an absolute textbook version.
  • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general

Qualifications

  • 2-4 years Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
  • Understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
  • Skilled in scripting and automation on exploits
  • Fuzzing skills are good to have.
  • Exploit writing skills is a positive and greatly required.
  • Pay Range Transparency

    Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here .

    Zone 1 Pay Range

    $156,700 — $219,325 USD

    Zone 2 Pay Range

    $141,000 — $197,400 USD

    Zone 3 Pay Range

    $133,200 — $186,450 USD

    Zone 4 Pay Range

    $125,400 — $175,500 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We ensure hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    Voluntary Self-Identification

    For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Your information will be confidential and used for compliance purposes. This section includes sections on disability status and related disclosures as applicable.

    #J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Product Security Engineer • San Francisco, CA, United States

    Ofertas relacionadas
    • Oferta promocionada
    Senior Security Engineer (Product and Platform Security)

    Senior Security Engineer (Product and Platform Security)

    Box, Inc.Redwood City, CA, United States
    A tiempo completo
    Box (NYSE : BOX) is the leader in Intelligent Content Management.Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform ...Mostrar másÚltima actualización: hace 4 días
    • Oferta promocionada
    Security Engineer, Application Security

    Security Engineer, Application Security

    OpenAISan Francisco, CA, United States
    A tiempo completo
    Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products.We are...Mostrar másÚltima actualización: hace 12 días
    • Oferta promocionada
    Security Engineer

    Security Engineer

    Mercor, Inc.San Francisco, CA, United States
    A tiempo completo
    Mercor is training models that predict how well someone will perform on a job better than a human can.We use our platform to source, vet, and onboard expert contractors who help train AI models in ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Security Engineer, Agent Security

    Security Engineer, Agent Security

    OpenAISan Francisco, CA, United States
    A tiempo completo
    Security Engineer, Agent Security | OpenAI.Security Engineer, Agent Security.Apply now (opens in a new window).The team’s mission is to accelerate the secure evolution of agentic AI systems at Open...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Security Engineer

    Security Engineer

    DelveSan Francisco, CA, United States
    A tiempo completo
    We’re the fastest growing compliance company on the market.Lovable, 11x, WisprFlow) by eliminating compliance busywork and helping them focus on what matters — securely supporting their customers.O...Mostrar másÚltima actualización: hace 2 días
    • Oferta promocionada
    • Nueva oferta
    Security Engineer

    Security Engineer

    FactorySan Francisco, CA, United States
    A tiempo completo
    Factory is seeking a talented Security Engineer to join our team.In this role, you will play a critical role in developing and maintaining the security foundation of our platform.You will conduct i...Mostrar másÚltima actualización: hace 8 horas
    • Oferta promocionada
    Senior Security Engineer

    Senior Security Engineer

    QualifiedSan Francisco, CA, United States
    A tiempo completo
    Qualified is the Agentic Marketing Platform for B2B companies.With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email...Mostrar másÚltima actualización: hace 12 días
    • Oferta promocionada
    Security Engineer

    Security Engineer

    Recruiting From ScratchSan Francisco, CA, United States
    A tiempo completo
    Hyper-Growth, Highly Profitable Private Company.Competitive (based on experience) + Equity.We’re representing one of the fastest-growing companies in the world, scaling from $1M to $500M in revenue...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    • Nueva oferta
    Software Engineer - Security

    Software Engineer - Security

    Modern TreasurySan Francisco, CA, United States
    A tiempo completo
    This position can be based out of San Francisco, New York, or remote (we accept candidates from many states).Modern Treasury’s mission is to build the most trusted financial infrastructure for glob...Mostrar másÚltima actualización: hace 8 horas
    • Oferta promocionada
    Physical Security Systems Engineer

    Physical Security Systems Engineer

    OpenAISan Francisco, CA, United States
    A tiempo completo
    The Physical Security Technology group at OpenAI is a critical part of our Corporate Security organization.We’re responsible for deploying advanced security technologies that protect our people, co...Mostrar másÚltima actualización: hace 10 días
    • Oferta promocionada
    Product Engineer

    Product Engineer

    KubeltSan Francisco, CA, United States
    A tiempo completo
    Skiff is hiring product engineers to bring freedom to the internet.If you enjoy working on privacy-first, open-source, and well-crafted products you’ll fit right in. Engineers at Skiff own large chu...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Staff Product Security Engineer (Security)

    Staff Product Security Engineer (Security)

    P2PSan Francisco, CA, United States
    A tiempo completo
    Phantom is revolutionizing the way millions of people interact with the crypto ecosystem.Our self-custodial wallet offers a seamless, unified experience for managing accounts and tokens across Sola...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Software Engineer, Security Observability

    Software Engineer, Security Observability

    OpenAISan Francisco, CA, United States
    A tiempo completo
    Software Engineer, Security Observability.Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Enterprise Security Engineer

    Enterprise Security Engineer

    OpenAISan Francisco, CA, United States
    A tiempo completo
    Within the OpenAI Security organization, our IT team works to ensure our team of researchers, engineers, and staff have the tools they need to work comfortably, securely, and with minimal interrupt...Mostrar másÚltima actualización: hace 12 días
    • Oferta promocionada
    Product Security Engineer

    Product Security Engineer

    CascaSan Francisco, CA, United States
    A tiempo completo
    Casca is building AGI for banking.We’re replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do. We're seeking a Product Security E...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Senior Product Security Engineer

    Senior Product Security Engineer

    Epoch BiodesignSan Francisco, CA, United States
    A tiempo completo
    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do! https : / / www. We aim to align the long term interests of the cli...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Security Agent Engineer

    Security Agent Engineer

    Anvilogic IncPalo Alto, CA, United States
    A tiempo completo
    Anvilogic is a Palo Alto-based AI cybersecurity startup founded in 2019 by security veterans and data scientists from Fortune 500 companies. Our mission is to democratize threat detection and huntin...Mostrar másÚltima actualización: hace 5 días
    • Oferta promocionada
    Enterprise Security Engineer

    Enterprise Security Engineer

    PersonaSan Francisco, CA, United States
    A tiempo completo
    Persona is the configurable identity platform built for businesses in a digital-first world.Verifying individuals and organizations is harder — but more important — than ever, with AI enabling frau...Mostrar másÚltima actualización: hace 2 días