Summary
Join Databricks' Incident Response team as a Sr. Staff Security Engineer and make strategic decisions impacting the company's long-term security. Lead complex investigations, manage crises, and develop multi-year technology strategies. You will leverage Databricks' platform for real-time log analytics and forensics. This role requires expertise in cloud security (AWS, Azure, GCP), digital forensics, and enterprise security. You will also mentor team members and collaborate across departments. The position is remote-friendly, with a preference for candidates in the San Francisco Bay Area or Seattle/Bellevue.
Requirements
- Typically 12+ years of experience in security, with a strong focus on incident response, detection, and/or threat intelligence, or an advanced degree with 8+ years of experience
- This includes deep expertise in Incident Management and Incident Response tool development
- Demonstrates knowledge of Azure and AWS cloud concepts, showing expertise in analyzing logs, correlating available log sources to conclude an attack scenario, and identifying logging gaps to suggest best configurations for IR needs
- You can function as an architect of cloud deployment and map cloud environment fundamentals to other major providers
- Highly skilled in multiple areas of digital forensics (e.g., Network, Application/Log Analysis, Host/Disk, Memory Forensics/Malware Analysis, Cloud Forensics, Endpoint Forensics), able to speak confidently on advanced concepts like virtualized networking, advanced network anomalies, and container forensics
- Has a detailed understanding of enterprise security incidents and in-depth knowledge of malware on endpoints
- Possesses expert understanding of MacOS security posture and architecture
- Proficient with SIEM and SOAR platforms, EDR solutions, and forensic analysis tools
- Skilled in leveraging AI and automation technologies to enhance security operations and threat detection capabilities
- Exceptional ability to engage in difficult conversations, handle them appropriately, and exhibit empathy and emotional intelligence
- Proven capability to build, mentor, and lead high-performing cybersecurity teams, fostering a culture of excellence and continuous improvement
- Strong communication of technical decisions through design docs and tech talks
- A history of proactively identifying and solving issues that impact the team and company
- Demonstrates a strong desire to help peers and collaborate effectively
- Able to push back or say no to unreasonable stakeholder requests in a professional and constructive manner
- U.S. Citizenship Requirement
Responsibilities
- Drive or influence the organizationโs direction and roadmap, leading internal conversations about major technology areas and inspiring adoption
- Provide decisions with direct, long-term impact on Databricks' success
- Lead complex investigations and impact analysis, performing crisis management using the Incident Management System (IMS)
- Engage with various stakeholders and communicate findings to executive leadership, ensuring successful navigation of major security incidents with minimal business impact
- Exhibit expert knowledge in all cloud vendors used by Databricks (AWS, Azure, GCP), deeply understanding the entire architecture of major business components and articulating their security and risk limits
- Drive the establishment of a cutting-edge threat detection and response program, significantly reducing Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to security incidents
- Architect scalable and organized frameworks for security automation and orchestration, including pre-investigation analysis and triage of alerts
- Understand trends and directions of the security industry within your domain and architect large-scale designs consistent with organizational and company goals
- Demonstrate the ability to fix difficult and company-impactful problems wherever they lie, even if outside your comfort zone
- Possess a full understanding of what malicious activity looks like in each cloud layer (network, storage, compute), understanding existing logs and correlating from multiple sources during an investigation
- Serve as a role model and mentor to every technical member of the team
- Identify areas where Databricks can share effectively with the outside world, guiding content creation and communication via presentations and blogs
- Work across departments, integrating security practices into various aspects of the organization and product development lifecycle
Benefits
- Annual performance bonus
- Equity
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.