Talent.com
Product Security Engineer

Product Security Engineer

Databricks Inc.San Francisco, CA, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

RDQ326R24 - This role can be based remotely anywhere in the United States.

The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.

You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You will work with a global team, spread across various locations in the US and EMEA.

Responsibilities

  • Full SDLC Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc.
  • Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed.
  • Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.
  • Work on DAST tools and related automation for auto-assessment and defect filing.
  • Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPPA, etc.
  • Prioritize security from a risk management perspective, rather than an absolute textbook version.
  • Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general

Qualifications

  • 2-4 years Experience with the Threat Modeling process and ability to find design problems based on a block diagram of data flow.
  • Understanding on at least two of the following domains - Web Security, Cloud Security, Systems Security and Applied Cryptography.
  • Skilled in scripting and automation on exploits
  • Fuzzing skills are good to have.
  • Exploit writing skills is a positive and greatly required.
  • Pay Range Transparency

    Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here .

    Zone 1 Pay Range

    $156,700 — $219,325 USD

    Zone 2 Pay Range

    $141,000 — $197,400 USD

    Zone 3 Pay Range

    $133,200 — $186,450 USD

    Zone 4 Pay Range

    $125,400 — $175,500 USD

    About Databricks

    Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.

    Our Commitment to Diversity and Inclusion

    At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We ensure hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

    Compliance

    If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

    Voluntary Self-Identification

    For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Your information will be confidential and used for compliance purposes. This section includes sections on disability status and related disclosures as applicable.

    #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Product Security Engineer • San Francisco, CA, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Product Manager - Agentic AI & Security

    Product Manager - Agentic AI & Security

    Obsidian SecurityPalo Alto, CA, US
    serp_jobs.job_card.full_time
    Founded in 2017, Obsidian Security was created to close a critical gap : securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds mor...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Principal Software Engineer, Security Innovation

    Principal Software Engineer, Security Innovation

    Cisco Systems, Inc.San Jose, CA, United States
    serp_jobs.job_card.full_time
    The application window is expected to close on October 14th, 2025.Note : Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.The Infra...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_less
    • serp_jobs.job_card.promoted
    Product Manager - AI Security

    Product Manager - AI Security

    Diversity Talent ScoutsSan Jose, CA, US
    serp_jobs.job_card.full_time
    AI Platforms & Security group.AI-powered solutions that help organizations strengthen resilience and defend against modern threats. We believe in simplifying security without compromise and enab...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Engineer - Sensor Security

    Senior Engineer - Sensor Security

    VirtualVocationsSanta Clara, California, United States
    serp_jobs.job_card.full_time
    Engineer - Sensor Security Platform (Remote).Key Responsibilities Understand, modify, and assume ownership of complex sensor detections and response capabilities Gain expertise in the core logic...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Software Engineer

    Senior Security Software Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Software Engineer.Key Responsibilities Develop and maintain embedded software with a focus on security Implement and manage security protocols and auth...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer, Product Security

    Security Engineer, Product Security

    Scale AISan Francisco, CA, United States
    serp_jobs.job_card.full_time
    We are seeking a highly technical Security Engineer to join our Product Security team.This role is integral to ensuring the security and integrity of our products and services.You will conduct in-d...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Principal Cyber Security Engineer

    Principal Cyber Security Engineer

    Cloud Software Group, Inc.San Ramon, CA, United States
    serp_jobs.job_card.full_time
    Architectural Leadership : Design, develop, and maintain the comprehensive security architecture for Cloud Software Group's products and corporate infrastructure. Cloud Security Expertise : Lead the s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Product Manager (IoT- Device Security)

    Senior Product Manager (IoT- Device Security)

    Palo Alto NetworksSanta Clara, CA, US
    serp_jobs.job_card.full_time
    At Palo Alto Networks® everything starts and ends with our mission : .Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    PAM Security Engineer

    PAM Security Engineer

    VirtualVocationsSanta Clara, California, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM / PAM Security Engineer to implement cybersecurity strategies for protecting digital identities within a federal agency's IT environment.Key Responsibilities Imple...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Detection Engineer

    Detection Engineer

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Detection Engineer (1st Shift).Key Responsibilities Analyze EDR telemetry and alerts across various detection domains Publish threat reports with clear communication o...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    FIPS Certified Security Engineer

    FIPS Certified Security Engineer

    VirtualVocationsSanta Clara, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, FIPS / CC (Mobile Devices).Key Responsibilities Lead the end-to-end validation process for IT products, including security assessments and documentatio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocationsConcord, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Infrastructure Support Senior Security Engineer.Key Responsibilities : Design, install, maintain, and support enterprise IT systems across hybrid environments ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    Cloud Software Group, Inc.San Ramon, CA, United States
    serp_jobs.job_card.full_time
    Analyze and investigate activity on company devices and infrastructure (Public Cloud & on-premise) that could represent a security threat. Work cross-functionally with the Security teams to develop ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Staff Product Security Engineer

    Staff Product Security Engineer

    Databricks Inc.San Francisco, CA, United States
    serp_jobs.job_card.full_time
    RDQ226R605; This role can be based remotely anywhere in the United States.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    Epoch BiodesignSan Francisco, CA, United States
    serp_jobs.job_card.full_time
    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do! https : / / www. We aim to align the long term interests of the cli...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Security Engineer - Application Security

    Security Engineer - Application Security

    VirtualVocationsHayward, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer - Application & AI Security (REMOTE).Key Responsibilities Build and deploy security controls across web applications, data pipelines, and AI systems; ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    VirtualVocationsSan Francisco, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a FIPS 140 Security Engineer to support various FIPS 140 validation projects.Key Responsibilities Conduct general security analysis and design work for product architectu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    VirtualVocationsSanta Clara, California, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer to join their cybersecurity team.Key Responsibilities Administer and maintain identity providers and manage endpoint protection platforms Monitor and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30