Staff Security Engineer, Incident Response
Databricks · Remote - California
About this role
**Staff Security Engineer, Incident Response** **About the role** The Incident Response (IR) team’s mission is to respond to security threats, incidents, and investigations to protect customers, employees, and enterprise data—fast, efficiently, and in a standardized way. You’ll be part of a tight-knit team of incident responders and handlers delivering “Security for Databricks on Databricks” using Databricks’ own platform for near-real-time log analytics, alerting, and forensics. As an individual contributor on the Security Incident Response team, you’ll report to the regional IR manager. You’ll conduct security analysis and forensics, respond to high-priority alerts, and contribute to automations and agentic capabilities—helping scale incident response across Databricks. **Impact you will have** - Respond to incidents as part of a distributed 24x7 operations and on-call schedule. - Triage and respond to security events and alerts to ensure quick, effective containment. - Conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events. - Provide technical leadership and influence team direction. - Develop solutions (including leveraging AI and agentic platforms) to deliver autonomous capabilities, expedite your work, and scale team impact. - Communicate technical decisions through design docs and tech talks; mentor junior responders via security guidance, design reviews, and code reviews. **What we look for** - Must have an active or current US GOV Secret clearance eligibility (Top Secret preferred). - Bachelor’s degree + 7+ years incident response experience **OR** Master’s degree + 5+ years incident response experience. - Cloud security expertise in at least one of AWS, GCP, or Azure, with proficiency in the others. - Proficiency in AI/LLM and agentic capabilities (prefer experience building and operating agentic systems in a security setting). - Broad security subject matter expertise. - Expertise in a few core IR skills (e.g., DFIR, Reverse Engineering, Traditional Network Security, Storage & access security, Sandboxing, Compute security, etc.). - Experience with Enterprise Security and SaaS applications. - Working knowledge of a SIEM and SOAR. - Experience building incident response tooling; scripting language skills; experience with AI coding tools. **Location** While candidates in the listed location(s) are encouraged, US-based candidates will be considered. **About Databricks** Databricks is the Data and AI company. More than 20,000 organizations worldwide rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics, and agents. **Benefits & Inclusion** Databricks offers comprehensive benefits and is committed to diversity and inclusion. **Compliance** If access to export-controlled technology or source code is required for job duties, it is within the Employer’s discretion whether to apply for a U.S. government license, and the Employer may decline to proceed with an applicant on this basis alone.
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.