Talent.com
Staff Product Security Engineer
Staff Product Security EngineerDatabricks Inc. • San Francisco, CA, United States
Staff Product Security Engineer

Staff Product Security Engineer

Databricks Inc. • San Francisco, CA, United States
30+ days ago
Job type
  • Full-time
Job description

RDQ226R605; This role can be based remotely anywhere in the United States.

The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.

You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You will work with a global team, spread across various locations in the US and EMEA.

The impact you will have :

  • Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  • Work on DAST tools and related automation for auto-assessment and defect filing.
  • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
  • Prioritize security from a risk management perspective, rather than an absolute textbook version.
  • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general

What we look for :

  • 3-10 years Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
  • Solid understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
  • Strong skills on scripting and automation on exploits
  • Fuzzing skills are good to have.
  • Exploit writing skills is a positive and greatly required.
  • Zone 1 Pay Range

    $178,200 — $249,450 USD

    Zone 2 Pay Range

    $160,300 — $224,425 USD

    Zone 3 Pay Range

    $151,400 — $212,000 USD

    Zone 4 Pay Range

    $142,500 — $199,500 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter , and Facebook .

    Benefits

    At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please .

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    #J-18808-Ljbffr

    Create a job alert for this search

    Staff Security Engineer • San Francisco, CA, United States

    Related jobs
    Staff Product Security Engineer

    Staff Product Security Engineer

    Code Red Partners • San Francisco, CA, United States
    Full-time
    Code Red is partnered with a unicorn FinTech in SF to bring on a.Staff Product Security Engineer.This will be a foundational hire within a small, high‑impact security org that supports a global org...Show more
    Last updated: 13 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Airtable • San Francisco, CA, United States
    Full-time
    Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100,...Show more
    Last updated: 19 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Menlo Ventures • San Francisco, CA, United States
    Full-time
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati...Show more
    Last updated: 30+ days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    CHYM • San Francisco, CA, United States
    Full-time
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder's mindset, is eager to learn, and is excited to contribute to both planned initiati...Show more
    Last updated: 19 days ago • Promoted
    Staff Security Engineer, Secure Digital Asset Operations

    Staff Security Engineer, Secure Digital Asset Operations

    P2P • San Francisco, CA, United States
    Full-time
    At Ripple, we’re building a world where value moves like information does today.It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, ...Show more
    Last updated: 30+ days ago • Promoted
    Staff Security Assurance Engineer

    Staff Security Assurance Engineer

    Databricks • San Francisco, CA, United States
    Full-time
    Staff Security Assurance Engineer (US).Citizenship is required for this position ==.The Databricks Security Assurance Team ensures that Databricks achieves and maintains critical third-party certif...Show more
    Last updated: 19 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Skild.ai • San Francisco, CA, United States
    Full-time
    At Skild AI, we are building the world's first general purpose robotic intelligence that is robust and adapts to unseen scenarios without failing. We believe massive scale through data-driven machin...Show more
    Last updated: 30+ days ago • Promoted
    Staff Platform Security Engineer

    Staff Platform Security Engineer

    Gemini • San Francisco, CA, United States
    Full-time
    Staff Platform Security Engineer.Be among the first 25 applicants.Staff Platform Security Engineer.Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offer...Show more
    Last updated: 30+ days ago • Promoted
    Staff Security Engineer, TDI

    Staff Security Engineer, TDI

    Okta, Inc. • San Francisco, CA, United States
    Full-time
    Okta is The World's Identity Company.We free everyone to safely use any technology, anywhere, on any device or app.Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secur...Show more
    Last updated: 19 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Chime • San Francisco, CA, United States
    Full-time
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati...Show more
    Last updated: 13 days ago • Promoted
    Staff Product Security Engineer

    Staff Product Security Engineer

    Rippling • San Francisco, CA, United States
    Full-time
    Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...Show more
    Last updated: 13 days ago • Promoted
    Staff Security Engineer

    Staff Security Engineer

    EvenUp Inc. • San Francisco, CA, United States
    Full-time
    EvenUp is on a mission to close the justice gap using technology and AI.We empower personal injury lawyers and victims to get the justice they deserve. Our products enable law firms to secure faster...Show more
    Last updated: 19 days ago • Promoted
    Staff Security Engineer, Secure Digital Asset Operations

    Staff Security Engineer, Secure Digital Asset Operations

    Ripple • San Francisco, CA, United States
    Full-time
    Staff Security Engineer, Secure Digital Asset Operations.Please note this is for San Francisco, CA, United States.You only need toapply to one location if there are multiple listed for the job.At R...Show more
    Last updated: 30+ days ago • Promoted
    Staff Security Software Engineer

    Staff Security Software Engineer

    DigitalOcean • San Francisco, CA, United States
    Full-time
    Staff Security Software Engineer.We are looking for a Staff Security Software Engineer who is passionate about detecting and mitigating abuse in the Cloud. As a Staff Security Software Engineer at D...Show more
    Last updated: 10 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Skild AI • San Francisco, CA, United States
    Full-time
    At Skild AI, we are building the world's first general purpose robotic intelligence that is robust and adapts to unseen scenarios without failing. We believe massive scale through data-driven machin...Show more
    Last updated: 30+ days ago • Promoted
    Staff+ Product Security Engineer

    Staff+ Product Security Engineer

    Verkada • San Mateo, CA, United States
    Full-time
    Verkada is transforming how organizations protect their people and places with an integrated, AI-powered platform.A leader in cloud physical security, Verkada helps organizations strengthen safety ...Show more
    Last updated: 19 days ago • Promoted
    Staff Security Engineer

    Staff Security Engineer

    Box • Redwood City, CA, United States
    Full-time
    Box (NYSE : BOX) is the leader in Intelligent Content Management.Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Security Engineer - Secure-by-Design

    Senior Product Security Engineer - Secure-by-Design

    DigitalOcean, LLC • San Francisco, CA, United States
    Full-time
    A leading cloud infrastructure provider is seeking a Senior Product Security Engineer in San Francisco, CA.In this role, you will assess security risks for new products and features, collaborate wi...Show more
    Last updated: 4 days ago • Promoted