Overview
== To comply with U.S. federal government requirements, U.S. Citizenship is required for this position ==
Job Description
The Databricks Security Assurance Team ensures that Databricks achieves and maintains critical third-party certifications, helping secure our operations and instill confidence in customers. As a Staff Security Assurance Engineer, you will lead efforts to obtain and sustain certifications such as SOC 2, HIPAA, and ISO 27001 for Databricks’ new acquisitions, while also spearheading compliance tooling and automation initiatives that enhance compliance operation efficiency and audit readiness. You will be an individual contributor reporting to the Sr. Manager of the Security Assurance Team.
This is a work opportunity within the following geographic region :
Responsibilities
Drive certification success by leading and managing SOC 2, HIPAA, and ISO 27001 certification efforts for Databricks’ new acquisitions, ensuring seamless integration into the existing compliance programs.Lead compliance tooling and automation strategy, defining the roadmap and delivering solutions that scale security compliance operations, reduce manual effort, and improve audit efficiency.Enable new business by conducting and supporting gap assessments of new security compliance requirements.Ensure audit readiness and security compliance across the organization by working cross-functionally with other teams such as Engineering, IT, Legal, and HR.Support broader certifications and assurance efforts, contributing to the Security Assurance Team’s portfolio of certifications, reports, and customer deliverables as needed.Develop and maintain strong relationships with external auditors and certification bodies to facilitate smooth audit processes.Qualifications
Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience.8+ years of security experience with at least 4 years of that in security compliance management, security audits, or GRC tooling.Experience leading, achieving, and maintaining SOC2, HIPAA, and / or ISO 27001 certifications.Experience managing security audits from end to end, including planning, evidence collection, stakeholder coordination, and auditor engagement.Experience improving security compliance or security audit programs through process standardization, automation, and effective tooling.A comprehensive understanding of security controls across all domains.A general understanding of key technical security controls in cloud environments (AWS, Azure, GCP).Experience working effectively across the spectrum of individual contributors and senior leadership within an organization (for example, Engineering, IT, Security, Legal, etc.).Experience leading and managing compliance tooling and automation initiatives.Experience with developing or scripting GRC tools and automation workflows to improve efficiency and streamline compliance operations.About Databricks
Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter ,LinkedIn and Facebook .
Benefits
At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please visithttps : / / www.mybenefitsnow.com / databricks .
#J-18808-Ljbffr