Talent.com
Databricks Enterprise Lead Security Architect - Principal IT Software Engineer
Databricks Enterprise Lead Security Architect - Principal IT Software EngineerMenlo Ventures • San Francisco, CA, United States
Databricks Enterprise Lead Security Architect - Principal IT Software Engineer

Databricks Enterprise Lead Security Architect - Principal IT Software Engineer

Menlo Ventures • San Francisco, CA, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

GAQ426R246

We are looking for a highly skilled, technology and business-savvy Lead Security Architect to join our team within Databricks IT. In this dynamic, fast-paced environment, you will be responsible for designing and implementing a secure and scalable architecture to protect our corporate assets. You'll focus on key areas of IT security, including Identity and Access Management, Zero Trust architecture, and endpoint security, while also working to secure critical business applications and sensitive data. Your expertise will be crucial in building proactive security strategies that align with our business goals and protect the company from an ever-evolving threat landscape.

This position demands deep expertise in security principles and a comprehensive understanding of the entire infrastructure stack and IAM systems to design robust, future-ready security solutions. You will be instrumental in safeguarding our systems’ resilience and integrity against ever-evolving cyber threats.

You will play a critical role in shaping our security strategy for modern platforms across AWS, Azure, GCP, network infrastructure, storage, and SaaS solutions, help establish a strong least privilege (PoLP) model, providing specialized IAM expertise, and securely supporting SaaS with sensitive information (NHI). You will also be a key contributor in building our internal strategy for secure AI development.

Additionally, you will support the secure integration of SaaS platforms such as Google Workspace, collaboration tools, and GTM systems, maintaining alignment with enterprise security standards. Close collaboration with cross-functional teams is essential to embed security throughout the technology stack.

The impact you will have :

What You Will Do :

Design and implement secure, scalable reference architectures for the Databricks IT across Cloud Infra (Compute, DBs, Network, Storage), SaaS, Custom Built Applications, Data & AI systems.

Establish and enforce security controls for :

Core Security Areas :

  • Databricks Workspace Management : Workspace isolation, Unity Catalog for data governance.
  • Secure Networking : VPC configs, PrivateLink, IP Allow Lists.

Identity and Access Management (IAM) : SSO, SCIM user provisioning, RBAC via Un, Strong MFA best practices for enterprise identities and customers

  • Data Encryption : At rest and in transit, customer-managed keys for critical assets.
  • Data Exfiltration Prevention : Admin console settings, VPC endpoint controls.
  • Cluster Security : User isolation, compliance with enhanced security monitoring / Compliance Security Profiles (HIPAA, PCI-DSS, FedRAMP).
  • Offensive Security : Test and challenge the effectiveness of the organization’s security defenses by mimicking the tactics, techniques, and procedures used by actual attackers.
  • Specialized Security Functions :

  • Non-human Identity Management : Design and implement secure authentication and authorization for automated systems (service accounts, API keys, machine identities), focusing on automation and integration with existing identity management systems.
  • IAM Best Practices : Develop and document comprehensive Identity and Access Management policies, including user provisioning, de-provisioning, access reviews, privileged access management, and multi-factor authentication, ensuring security and compliance.
  • Data Loss Prevention (DLP) : Implement DLP solutions to identify, monitor, and protect sensitive data across endpoints, networks, and cloud environments, preventing unauthorized access, use, or transmission.
  • SaaS Proxy Design and Implementation : Design and implement cloud-based proxies for SaaS applications (SASE solutions) to provide secure access, enforce security policies, monitor user activity, and protect against threats.
  • Cloud Infrastructure Best Practices : Establish and document best practices for VPC configurations, cloud networking, and infrastructure as code using Terraform, ensuring secure network segmentation, routing, firewalls, and VPNs for consistent, automated, and secure deployments.
  • Least Privilege Access for Data Security : Design and implement data security controls based on the principle of least privilege, ensuring users and systems have only the minimum necessary access through fine-grained controls, data classification, and regular access reviews.
  • Guide internal IT on Databricks’ security and compliance certifications (SOC 2, ISO 27001 / 27017 / 27018, HIPAA, PCI‑DSS, FedRAMP), and support security reviews / audits.
  • Support incident response, vulnerability management, threat modeling, and red teaming using audit logs, cluster policies, and enhanced monitoring.
  • Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs to enhance security posture.
  • Advise executive leadership on security architecture, risks, and mitigation.
  • Mentor security engineers and developers on secure design and best practices.
  • What we look for :

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field
  • Master’s degree in Computer Science specifically in Information Security or a related discipline is strongly preferred
  • Minimum 12 years in cybersecurity, with 5+ in security architecture or senior technical roles.
  • Experience in FedRAMP High systems / GovCloud preferred.
  • Must have direct experience designing and securing enterprise platforms in complex multi-cloud environments, deep knowledge of enterprise architecture and security features (control plane / data plane separation, network infra, workspace hardening, network segmentation / isolation), and hands‑on experience automating security controls with Terraform and scripting.
  • Proven expertise securing data analytics pipelines, SaaS integrations, and workload isolation in enterprise ecosystems.
  • Experience with Enterprise Security Analysis Tools and monitoring / security policy optimization.
  • Deep experience in threat modeling, design, PoC, and implementing large‑scale enterprise solutions.
  • Extensive hands‑on experience in AWS cloud security, network security, with knowledge of Zero Trust, Data Protection, and Appsec.
  • Strong understanding of enterprise IAM systems (Okta, SailPoint, VDI, Entra ID) and Data Protection.
  • Expert experience with SIEM platforms, XDR, and cloud‑native threat detection tools.
  • Expert in web application security, OWASP, API security, and secure design and testing.
  • Hands‑on experience with security automation is required, with proficiency in AI-assisted development, Python, Cursor, Lambda, Terraform, or comparable scripting / IaC tools for operational efficiency.
  • Industry certifications like CISSP, CCSP, CEH, AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, or AWS Certified Advanced Networking – Specialty (or equivalent) are preferred.
  • Ability to influence stakeholders and drive alignment.
  • Strategic thinker with a passion for security innovation, continuous improvement, and building scalable defenses.
  • Pay Range Transparency

    Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipates utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here.

    Zone 1 Pay Range

    $258,300 — $361,575 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, and Facebook.

    Benefits

    At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please visit

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    #J-18808-Ljbffr

    [job_alerts.create_a_job]

    Enterprise Security Architect • San Francisco, CA, United States

    [internal_linking.similar_jobs]
    Enterprise Architect

    Enterprise Architect

    Contact Government Services, LLC • San Francisco, CA, US
    [job_card.full_time]
    Employment Type : Full-Time, Senior-Level.Department : Information Technology.CGS is seeking an experienced senior-level Information Technology Enterprise Architect to support the I.The ideal applica...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Enterprise Security Lead

    Enterprise Security Lead

    OpenAI • San Francisco, CA, United States
    [job_card.full_time]
    Get AI-powered advice on this job and more exclusive features.OpenAI’s Security organization supports the mission of deploying AGI for the benefit of all by ensuring the confidentiality, availabili...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Partner Security Solutions Architect NAMER

    Senior Partner Security Solutions Architect NAMER

    Datadog, • San Francisco, CA, United States
    [job_card.full_time]
    A leading cloud security solutions provider is seeking a Senior IC to onboard and train partner technical teams.The role requires extensive experience in cloud security and observability solutions,...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Lead Security Engineer

    Lead Security Engineer

    Pylon • Menlo Park, CA, US
    [job_card.full_time]
    At Pylon, we're a small team building a very ambitious product in the mortgage space.We're in search of people who find difficult problems invigorating and who fit well into a high-performi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Security Architect, Software Engineering

    Principal Security Architect, Software Engineering

    Form Energy • Berkeley, CA, United States
    [job_card.full_time]
    Principal Security Architect, Software Engineering.Are you ready to build America’s energy future? Form Energy is an American manufacturing and energy technology company. We’re revolutionizing energ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Enterprise Security Engineer

    Principal Enterprise Security Engineer

    Roblox • San Mateo, CA, United States
    [job_card.full_time]
    Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Enterprise AI Security Solutions Architect

    Enterprise AI Security Solutions Architect

    The Rundown AI, Inc. • San Francisco, CA, United States
    [job_card.full_time]
    A leading AI security firm is seeking a Solutions Architect in San Francisco to act as a trusted advisor for enterprise customers. This customer-facing role focuses on designing AI security architec...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Oracle CCB Architect — Design & Security Lead

    Senior Oracle CCB Architect — Design & Security Lead

    AI Technologies LLC. • San Francisco, CA, United States
    [job_card.full_time]
    A technology solutions provider in San Francisco is seeking an Oracle Customer Care and Billing Senior Architect with over 8 years of experience. The role entails leading the design of scalable and ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Information Security Architect

    Information Security Architect

    Forhyre • San Francisco, CA, US
    [job_card.full_time]
    Lead Information Security Architect.DevOps, security, business applications, cloud security, and data architecture.The role oversees cybersecurity for our company's digital products, including ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Systems Integrity & Firmware Security Architect

    Senior Systems Integrity & Firmware Security Architect

    Anthropic • San Francisco, CA, United States
    [job_card.full_time]
    A public benefit corporation in San Francisco is seeking a Systems Integrity Security Engineer to build secure architectures for bare-metal infrastructure. The successful candidate will have extensi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Cloud Security Architect

    Principal Cloud Security Architect

    Labelbox • San Francisco, California, United States
    [job_card.full_time]
    Role Overview The Principal Cloud Security Architect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identify...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Information Security Architect

    Information Security Architect

    Compunnel, Inc. • San Francisco, CA, United States
    [job_card.full_time]
    We are seeking a Senior / Lead Information Security Architect to design secure cloud architectures, perform system threat modeling, and propose effective security controls for critical workloads.The ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Security Engineer - Crypto

    Principal Security Engineer - Crypto

    Career Renew • San Francisco, CA, US
    [job_card.full_time]
    Career Renew is recruiting for one of its clients a Principal Security Engineer - Crypto - this is a fully remote role for US / EU based candidates. Join a stellar team of leaders and experts in block...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Enterprise Security Engineer

    Enterprise Security Engineer

    Persona • San Francisco, CA, United States
    [job_card.full_time]
    Persona is the configurable identity platform built for businesses in a digital-first world.Verifying individuals and organizations is harder — but more important — than ever, with AI enabling frau...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Enterprise Data Architect — Secure AI & Cloud Data

    Enterprise Data Architect — Secure AI & Cloud Data

    Ernst & Young Oman • San Francisco, CA, United States
    [job_card.full_time]
    A global consulting firm in San Francisco seeks a highly skilled Cybersecurity Enterprise Data Architect.The successful candidate will lead the development of data systems, ensuring security and co...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Lead Security Engineer, Cloud Infrastructure

    Lead Security Engineer, Cloud Infrastructure

    Klaviyo • San Francisco, CA, US
    [job_card.full_time]
    At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair sh...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Platform Security Architect (Edge Systems, Cloud & Container Infrastructure)

    Principal Platform Security Architect (Edge Systems, Cloud & Container Infrastructure)

    Fastly • San Francisco, CA, United States
    [job_card.full_time]
    Principal Platform Security Architect (Edge Systems, Cloud & Container Infrastructure).Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables custo...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Enterprise AI Security Solutions Architect

    Enterprise AI Security Solutions Architect

    Lakera Inc • San Francisco, CA, United States
    [job_card.full_time]
    A leading AI security firm is seeking a Solutions Architect to serve as a technical partner for enterprise customers.This role involves collaborating with Customer Success Managers to drive adoptio...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]