Talent.com
Databricks Enterprise Lead Security Architect - Principal IT Software Engineer

Databricks Enterprise Lead Security Architect - Principal IT Software Engineer

Databricks Inc.Mountain View, CA, United States
16 days ago
Job type
  • Full-time
Job description

We are looking for a highly skilled, technology and business-savvy Lead Security Architect to join our team within Databricks IT. In this dynamic, fast-paced environment, you will be responsible for designing and implementing a secure and scalable architecture to protect our corporate assets. You'll focus on key areas of IT security, including Identity and Access Management, Zero Trust architecture, and endpoint security, while also working to secure critical business applications and sensitive data. Your expertise will be crucial in building proactive security strategies that align with our business goals and protect the company from an ever-evolving threat landscape.

This position demands deep expertise in security principles and a comprehensive understanding of the entire infrastructure stack and IAM systems to design robust, future-ready security solutions. You will be instrumental in safeguarding our systems' resilience and integrity against ever-evolving cyber threats.

You will play a critical role in shaping our security strategy for modern platforms across AWS, Azure, GCP, network infrastructure, storage, and SaaS solutions, help establish a strong least privilege (PoLP) model, providing specialized IAM expertise, and securely supporting SaaS with sensitive information (NHI). You will also be a key contributor in building our internal strategy for secure AI development.

Additionally, you will support the secure integration of SaaS platforms such as Google Workspace, collaboration tools, and GTM systems, maintaining alignment with enterprise security standards. Close collaboration with cross-functional teams is essential to embed security throughout the technology stack.

The impact you will have :

What You Will Do :

Design and implement secure, scalable reference architectures for the Databricks IT across Cloud Infra (Compute, DBs, Network, Storage), SaaS, Custom Built Applications, Data & AI systems.

Identity and Access Management (IAM) :

SSO, SCIM user provisioning, RBAC via Un, Strong MFA best practices for enterprise identities and customers.

Core Security Areas :

  • Databricks Workspace Management : Workspace isolation, Unity Catalog for data governance.
  • Secure Networking : VPC configs, PrivateLink, IP Allow Lists.
  • Data Encryption : At rest and in transit, customer-managed keys for critical assets.
  • Data Exfiltration Prevention : Admin console settings, VPC endpoint controls.
  • Cluster Security : User isolation, compliance with enhanced security monitoring / Compliance Security Profiles (HIPAA, PCI-DSS, FedRAMP).
  • Offensive Security : Test and challenge the effectiveness of the organization’s security defenses by mimicking the tactics, techniques, and procedures used by actual attackers.

Specialized Security Functions :

  • Non-human Identity Management : Design and implement secure authentication and authorization for automated systems (service accounts, API keys, machine identities), focusing on automation and integration with existing identity management systems.
  • IAM Best Practices : Develop and document comprehensive Identity and Access Management policies, including user provisioning, de-provisioning, access reviews, privileged access management, and multi-factor authentication, ensuring security and compliance.
  • Data Loss Prevention (DLP) : Implement DLP solutions to identify, monitor, and protect sensitive data across endpoints, networks, and cloud environments, preventing unauthorized access, use, or transmission.
  • SaaS Proxy Design and Implementation : Design and implement cloud-based proxies for SaaS applications (SASE solutions) to provide secure access, enforce security policies, monitor user activity, and protect against threats.
  • Cloud Infrastructure Best Practices : Establish and document best practices for VPC configurations, cloud networking, and infrastructure as code using Terraform, ensuring secure network segmentation, routing, firewalls, and VPNs for consistent, automated, and secure deployments.
  • Least Privilege Access for Data Security : Design and implement data security controls based on the principle of least privilege, ensuring users and systems have only the minimum necessary access through fine-grained controls, data classification, and regular access reviews.
  • Guide internal IT on Databricks’ security and compliance certifications (SOC 2, ISO 27001 / 27017 / 27018, HIPAA, PCI-DSS, FedRAMP), and support security reviews / audits.
  • Support incident response, vulnerability management, threat modeling, and red teaming using audit logs, cluster policies, and enhanced monitoring.
  • Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs to enhance security posture.
  • Advise executive leadership on security architecture, risks, and mitigation.
  • Mentor security engineers and developers on secure design and best practices.
  • What we look for :

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field
  • Master’s degree in Computer Science specifically in Information Security or a related discipline is strongly preferred
  • Minimum 12 years in cybersecurity, with 5+ in security architecture or senior technical roles.
  • Experience in FedRAMP High systems / GovCloud preferred.
  • Must have direct experience designing and securing enterprise platforms in complex multi-cloud environments, deep knowledge of enterprise architecture and security features (control plane / data plane separation, network infra, workspace hardening, network segmentation / isolation), and hands-on experience automating security controls with Terraform and scripting.
  • Proven expertise securing data analytics pipelines, SaaS integrations, and workload isolation in enterprise ecosystems.
  • Experience with Enterprise Security Analysis Tools and monitoring / security policy optimization.
  • Deep experience in threat modeling, design, PoC, and implementing large-scale enterprise solutions.
  • Extensive hands-on experience in AWS cloud security, network security, with knowledge of Zero Trust, Data Protection, and Appsec.
  • Strong understanding of enterprise IAM systems (Okta, SailPoint, VDI, Entra ID) and Data Protection.
  • Expert experience with SIEM platforms, XDR, and cloud-native threat detection tools.
  • Expert in web application security, OWASP, API security, and secure design and testing.
  • Hands-on experience with security automation is required, with proficiency in AI-assisted development, Python, Cursor, Lambda, Terraform, or comparable scripting / IaC tools for operational efficiency.
  • Industry certifications like CISSP, CCSP, CEH, AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, or AWS Certified Advanced Networking – Specialty (or equivalent) are preferred.
  • Ability to influence stakeholders and drive alignment.
  • Strategic thinker with a passion for security innovation, continuous improvement, and building scalable defenses.
  • Pay Range Transparency

    Zone 1 Pay Range

    $258,300 — $361,575 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter , and Facebook.

    Benefits

    At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    #J-18808-Ljbffr

    Create a job alert for this search

    Enterprise Security Architect • Mountain View, CA, United States

    Related jobs
    • Promoted
    Sr. Information Security Engineer (27639)

    Sr. Information Security Engineer (27639)

    SupermicroSan Jose, CA, United States
    Full-time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...Show moreLast updated: 12 days ago
    • Promoted
    Senior Technology Cloud Security Architect

    Senior Technology Cloud Security Architect

    CooleyPalo Alto, CA, United States
    Full-time
    Senior Technology Cloud Security Architect.Cooley is seeking a Technology Cloud Security Architect to join the Security team. Cooley Technology embraces a culture of customer service excellence, and...Show moreLast updated: 30+ days ago
    • Promoted
    Enterprise Information Security Architect

    Enterprise Information Security Architect

    QuantumScape CorporationSan Francisco, CA, United States
    Full-time
    QuantumScape is on a mission to transform energy storage with solid-state lithium-metal battery technology.The company's next-generation batteries are designed to enable greater energy density, fas...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Cloud Architect, Cyber Security

    Senior Cloud Architect, Cyber Security

    International Staff ConsultingSan Jose, CA, United States
    Full-time
    Our client is a rapidly growing developer of cyber security software.Due to their expansion, a need for an experienced cloud architect has developed. Qualified candidates for this critical opening w...Show moreLast updated: 30+ days ago
    • Promoted
    Databricks Enterprise Lead Security Architect -Principal IT Software Engineer

    Databricks Enterprise Lead Security Architect -Principal IT Software Engineer

    DatabricksMountain View, CA, United States
    Full-time
    Databricks Enterprise Lead Security Architect - Principal IT Software Engineer.Join Databricks as a Lead Security Architect and influence the company’s security strategy across multi‑cloud platform...Show moreLast updated: 26 days ago
    • Promoted
    Senior Technology Cloud Security Architect

    Senior Technology Cloud Security Architect

    Cooley LLPPalo Alto, CA, United States
    Full-time
    Senior Technology Cloud Security Architect.Cooley is seeking a Technology Cloud Security Architect to join the Security team. Cooley Technology embraces a culture of customer service excellence, and...Show moreLast updated: 30+ days ago
    • Promoted
    Principal Enterprise Security Engineer

    Principal Enterprise Security Engineer

    F5 Networks, Inc.Palo Alto, CA, United States
    Full-time
    Location : • • Remote • •About the Role • • We are seeking a seasoned • •Principal Enterprise Security Engineer • • to design, implement, and manage enterprise-wide security solutions.You'll shape our secur...Show moreLast updated: 14 days ago
    • Promoted
    Security Architect

    Security Architect

    BayoneSan Jose, CA, United States
    Full-time
    Job Description : Official Job Title : Solution Architect / Tech.Duration? : 6 / 4 / 2024 to 6 / 4 / 2025 (could be possibility to convert to FTE based on business needs and candidate performance).Location? H...Show moreLast updated: 30+ days ago
    • Promoted
    Platform Architect - Security

    Platform Architect - Security

    AppleCupertino, CA, United States
    Full-time
    Cupertino, California, United States Hardware.At Apple, we strive to do our life's best work by building a seamless ecosystem across tightly integrated hardware, software, and services.The Platform...Show moreLast updated: 30+ days ago
    • Promoted
    Principal Cyber Security Engineer

    Principal Cyber Security Engineer

    Cloud Software Group, Inc.San Ramon, CA, United States
    Full-time
    Architectural Leadership : Design, develop, and maintain the comprehensive security architecture for Cloud Software Group's products and corporate infrastructure. Cloud Security Expertise : Lead the s...Show moreLast updated: 30+ days ago
    • Promoted
    Security Architect

    Security Architect

    TWO95 InternationalSan Jose, CA, United States
    Temporary
    Duration : 6-9 Months Contract to Hire.Define security requirements and checklist for IoT platforms.Champion the Client’s product security SDLC. This includes threat modeling, security testing, penet...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Security Manager

    Sr. Security Manager

    SupermicroSan Jose, CA, United States
    Full-time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...Show moreLast updated: 21 days ago
    • Promoted
    Enterprise Security Architect

    Enterprise Security Architect

    Okta for DevelopersSan Francisco, CA, United States
    Full-time
    Join the global team that builds the world’s leading Identity platform.We empower everyone to securely use any technology, across devices, apps, and cloud services. Okta is the world’s identity comp...Show moreLast updated: 16 days ago
    • Promoted
    SoC Security Engineer - Platform Architecture

    SoC Security Engineer - Platform Architecture

    AppleCupertino, CA, United States
    Full-time
    Imagine what you could do here! At Apple, new ideas have a way of becoming extraordinary products, services, and customer experiences very quickly. Bring passion and dedication to your job and there...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Cloud Security Architect

    Senior Information Cloud Security Architect

    First American Financial CompanySan Francisco, CA, United States
    Full-time
    Join a team that puts its People First! Since 1889, First American (NYSE : FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate abou...Show moreLast updated: 30+ days ago
    • Promoted
    Security Architect

    Security Architect

    DexterityRedwood City, CA, United States
    Full-time
    Software Security for Dexterity's Robotics Product Lines.This is a very visible and "hands-on" role that requires you to write and review code, write and audit policies, and work with auditors, pro...Show moreLast updated: 30+ days ago
    • Promoted
    Senior SoC Security Architect

    Senior SoC Security Architect

    Advanced Micro Devices, Inc.San Jose, CA, United States
    Full-time
    WHAT YOU DO AT AMD CHANGES EVERYTHING.At AMD, our mission is to build great products that accelerate next-generation computing experiences-from AI and data centers, to PCs, gaming and embedded syst...Show moreLast updated: 30+ days ago
    • Promoted
    Solution Architect - Cyber Security Hardware

    Solution Architect - Cyber Security Hardware

    X-PHYSan Mateo, CA, United States
    Full-time
    We are seeking an experienced Solution Architect to design and implement end-to-end architectures connecting PC cybersecurity hardware, to a centralized infrastructure for data protection and manag...Show moreLast updated: 30+ days ago