Talent.com
Staff Product Security Engineer
Staff Product Security EngineerDatabricks Inc. • San Francisco, CA, United States
Staff Product Security Engineer

Staff Product Security Engineer

Databricks Inc. • San Francisco, CA, United States
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

RDQ226R605; This role can be based remotely anywhere in the United States.

The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.

You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You will work with a global team, spread across various locations in the US and EMEA.

The impact you will have :

  • Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  • Work on DAST tools and related automation for auto-assessment and defect filing.
  • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
  • Prioritize security from a risk management perspective, rather than an absolute textbook version.
  • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general

What we look for :

  • 3-10 years Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
  • Solid understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
  • Strong skills on scripting and automation on exploits
  • Fuzzing skills are good to have.
  • Exploit writing skills is a positive and greatly required.
  • Zone 1 Pay Range

    $178,200 — $249,450 USD

    Zone 2 Pay Range

    $160,300 — $224,425 USD

    Zone 3 Pay Range

    $151,400 — $212,000 USD

    Zone 4 Pay Range

    $142,500 — $199,500 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter , and Facebook .

    Benefits

    At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please .

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    #J-18808-Ljbffr

    [job_alerts.create_a_job]

    Staff Security Engineer • San Francisco, CA, United States

    [internal_linking.similar_jobs]
    Staff Product Security Engineer

    Staff Product Security Engineer

    Code Red Partners • San Francisco, CA, United States
    [job_card.full_time]
    Code Red is partnered with a unicorn FinTech in SF to bring on a.Staff Product Security Engineer.This will be a foundational hire within a small, high‑impact security org that supports a global org...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Product Security Engineer

    Product Security Engineer

    Airtable • San Francisco, CA, United States
    [job_card.full_time]
    Airtable is the no‑code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100,...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Staff Product Manager, Agentic Offensive Security

    Staff Product Manager, Agentic Offensive Security

    hackerone • San Francisco, CA, United States
    [job_card.full_time]
    HackerOne is a global leader in Continuous Threat Exposure Management (CTEM).The HackerOne Platform unites agentic AI solutions with the ingenuity of the world's largest community of security resea...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Software Engineer, Product Safety

    Staff Software Engineer, Product Safety

    Pinterest • San Francisco, CA, United States
    [job_card.full_time]
    Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we're on a mission to br...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Backend Engineer - Device Security

    Staff Backend Engineer - Device Security

    Verkada • San Mateo, California, United States
    [job_card.full_time]
    Verkada is the largest cloud-based B2B physical security platform company in the world.Only Verkada offers six product lines — video security cameras, access control, environmental sensors, alarms,...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Platform Security Engineer

    Staff Platform Security Engineer

    Gemini • San Francisco, CA, United States
    [job_card.full_time]
    Staff Platform Security Engineer.Be among the first 25 applicants.Staff Platform Security Engineer.Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offer...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Enterprise Security Engineer — Hybrid & Equity Eligible

    Staff Enterprise Security Engineer — Hybrid & Equity Eligible

    Gemini Trust Company • San Francisco, CA, United States
    [job_card.full_time]
    A leading crypto platform in San Francisco is seeking a Staff Enterprise Security Engineer to secure corporate infrastructure and employee endpoints. Responsibilities include driving security initia...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Product Security Engineer

    Product Security Engineer

    Chime • San Francisco, CA, United States
    [job_card.full_time]
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Product Security Engineer : Secure-by-Design Leader

    Product Security Engineer : Secure-by-Design Leader

    Skild.ai • San Francisco, CA, United States
    [job_card.full_time]
    Skild AI is seeking a Security Lead to oversee the design and execution of security protocols crucial for our innovative robotics projects. The role demands strong software engineering skills and ex...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Founding Security Engineer, Product Security

    Founding Security Engineer, Product Security

    Notion • San Francisco, CA, United States
    [job_card.full_time]
    A tech company focused on productivity tools is seeking a Security Engineer to join their elite security team in San Francisco. You will be responsible for building a secure foundation for the platf...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Staff Product Security Engineer

    Staff Product Security Engineer

    Rippling • San Francisco, CA, United States
    [job_card.full_time]
    Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Staff Security Engineer

    Staff Security Engineer

    Credit Genie • San Francisco, CA, United States
    [job_card.full_time]
    Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights a...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Security Engineer - Hybrid

    Security Engineer - Hybrid

    Worker's Compensation Insurance Rating Bureau • San Francisco, CA, US
    [job_card.full_time]
    For over a century, the Workers' Compensation Insurance Rating Bureau of California (WCIRB) has been California's trusted, objective provider of actuarially based information and research, ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Software Engineer, Product Security

    Staff Software Engineer, Product Security

    Peregrine Technologies • San Francisco, CA, United States
    [job_card.full_time]
    Staff Software Engineer, Product Security.Backed by leading Silicon Valley investors, Peregrine helps the world’s most complex organizations solve their hardest problems with unprecedented speed an...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Staff Security Software Engineer

    Staff Security Software Engineer

    DigitalOcean • San Francisco, CA, United States
    [job_card.full_time]
    Staff Security Software Engineer.We are looking for a Staff Security Software Engineer who is passionate about detecting and mitigating abuse in the Cloud. As a Staff Security Software Engineer at D...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Product Security Engineer

    Product Security Engineer

    Skild AI • San Francisco, CA, United States
    [job_card.full_time]
    At Skild AI, we are building the world's first general purpose robotic intelligence that is robust and adapts to unseen scenarios without failing. We believe massive scale through data-driven machin...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Product Security Engineer

    Product Security Engineer

    Menlo Ventures • San Francisco, CA, United States
    [job_card.full_time]
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Security Engineer for Autonomous Vehicle Platform

    Staff Security Engineer for Autonomous Vehicle Platform

    Australian Competition and Consumer Commission • San Francisco, CA, United States
    [job_card.full_time]
    A leading self-driving technology company is seeking a Security Software Engineer to design and develop new security components for its autonomous vehicle platform. The ideal candidate will have at ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]