Talent.com
Product Security Engineer

Product Security Engineer

Databricks Inc.San Francisco, CA, United States
27 days ago
Job type
  • Full-time
Job description

Overview

RDQ326R24 - This role can be based remotely anywhere in the United States.

The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.

You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You will work with a global team, spread across various locations in the US and EMEA.

Responsibilities

  • Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  • Work on DAST tools and related automation for auto-assessment and defect filing.
  • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
  • Prioritize security from a risk management perspective, rather than an absolute textbook version.
  • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general

Qualifications

  • 2-4 years Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
  • Understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
  • Skilled in scripting and automation on exploits
  • Fuzzing skills are good to have.
  • Exploit writing skills is a positive and greatly required.
  • Pay Range Transparency

    Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here .

    Zone 1 Pay Range

    $156,700 — $219,325 USD

    Zone 2 Pay Range

    $141,000 — $197,400 USD

    Zone 3 Pay Range

    $133,200 — $186,450 USD

    Zone 4 Pay Range

    $125,400 — $175,500 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We ensure hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    Voluntary Self-Identification

    For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Your information will be confidential and used for compliance purposes. This section includes sections on disability status and related disclosures as applicable.

    #J-18808-Ljbffr

    Create a job alert for this search

    Product Security Engineer • San Francisco, CA, United States

    Related jobs
    • Promoted
    Product Security Engineer, Cryptography & PKI

    Product Security Engineer, Cryptography & PKI

    1X Technologies ASPalo Alto, CA, United States
    Full-time
    We're an AI and robotics company based in Palo Alto, California, on a mission to build a truly abundant society through general-purpose robots capable of performing any kind of work autonomously.We...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    FigmaSan Francisco, CA, United States
    Full-time
    Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all.Figma's platform helps teams bring ideas to life-whether you're brainstorming, creating ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior / Staff Software Engineer, Product Security

    Senior / Staff Software Engineer, Product Security

    ZipSan Francisco, CA, United States
    Full-time
    The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer, Kuiper Security

    Security Engineer, Kuiper Security

    AmazonSunnyvale, CA, United States
    Permanent
    Project Kuiper is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communit...Show moreLast updated: 3 days ago
    • Promoted
    Contract Security Engineer

    Contract Security Engineer

    Tech ProvidersMountain View, CA, United States
    Temporary
    Role : Security Software Engineer.The Application Security organization is seeking to hire an experienced Senior Software Security Engineer to design, implement, and deploy baseline security solutio...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Glow NetworksMountain View, CA, United States
    Full-time
    We are seeking a Security Engineer to design and implement Data Loss Protection capabilities for complex security use cases, identifying bad actor threat behaviors and preventing / reducing malicious...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Air AppsSan Francisco, CA, United States
    Full-time
    At Air Apps, we believe in thinking bigger-and moving faster.We're a family-founded company on a mission to create the world's first AI-powered Personal & Entrepreneurial Resource Planner (PRP), an...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer - Semiconductor, Devices and Services Security

    Security Engineer - Semiconductor, Devices and Services Security

    AmazonSunnyvale, CA, United States
    Permanent
    Project Kuiper is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communit...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer, Product Security

    Security Engineer, Product Security

    Scale AISan Francisco, CA, United States
    Full-time
    We are seeking a highly technical Security Engineer to join our Product Security team.This role is integral to ensuring the security and integrity of our products and services.You will conduct in-d...Show moreLast updated: 3 days ago
    Staff Product Security Engineer

    Staff Product Security Engineer

    RipplingSan Francisco, California, United States, 94104
    Full-time
    Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    FactorySan Francisco, CA, United States
    Full-time
    Factory is seeking a talented Security Engineer to join our team.In this role, you will play a critical role in developing and maintaining the security foundation of our platform.You will conduct i...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer - D&R

    Security Engineer - D&R

    FigureSan Jose, CA, United States
    Full-time
    Figure is an AI Robotics company developing a general purpose humanoid.Our humanoid robot, Figure 02, is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days / w...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Cartesia, Inc.San Francisco, CA, United States
    Full-time
    Our mission is to build the next generation of AI : ubiquitous, interactive intelligence that runs wherever you are.Today, not even the best models can continuously process and reason over a year-lo...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer, Product

    Senior Security Engineer, Product

    DecagonSan Francisco, CA, United States
    Full-time
    Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience.Our AI agents provide intelligent, human-like responses across chat, email, and voi...Show moreLast updated: 3 days ago
    • Promoted
    Staff Product Security Engineer

    Staff Product Security Engineer

    Databricks Inc.San Francisco, CA, United States
    Full-time
    RDQ226R605; This role can be based remotely anywhere in the United States.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written i...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    CalTek Staffing, Inc.San Jose, CA, United States
    Full-time
    San Francisco Bay Area (Hybrid - 2 days onsite).Great opportunity to work for a leading cybersecurity company providing enterprise-grade security solutions to Fortune 500 companies and high-growth ...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer, Product Security

    Security Engineer, Product Security

    METAMenlo Park, CA, United States
    Full-time
    Meta), formerly known as Facebook Inc.When Facebook launched in 2004, it changed the way people connect.Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around t...Show moreLast updated: 3 days ago
    • Promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    Epoch BiodesignSan Francisco, CA, United States
    Full-time
    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do! https : / / www. We aim to align the long term interests of the cli...Show moreLast updated: 30+ days ago