Sr Security Engineer, Incident Response
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Incident Response teamâs mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. Weâre a tight-knit team of security incident responders and incident handlers doing âSecurity for Databricks on Databricksâ, using our own platform to create near-real-time log analytics, alerting and forensics.
You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.
The impact you will have:
- You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
- You will triage and respond to security events and alerts, ensuring quick and effective containment.
- You will contribute to security investigations, conducting analysis and forensics across a range of data sources to determine the timeline and impact of security events.
- You will build automations, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
- You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.
Requirements
- Bachelorâs Degree AND 4+ years experience in Incident Response work OR Masterâs Degree AND 2+ years experience.
- Strong cloud security background in at least 1 of AWS, GCP or Azure, and working knowledge of the others.
- Knowledge of AI/LLM and agentic capabilities, including effective prompting and use of MCP, agents and agent skills. Prefer experience with building and operating agentic systems in a security setting.
- Broad security subject matter expertise.
- Expertise in few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
- Experience with Enterprise Security and SaaS applications.
- Working knowledge of a SIEM and SOAR.
- Experience building Incident Response Tooling and scripting language skills.
Benefits & conditions
At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees.
About the company
Databricks is the data and AI company. More than 10,000 organizations worldwide - including Comcast, CondĂŠ Nast, Grammarly, and over 50% of the Fortune 500 - rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark , Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
Dev Digest 138 - Are you secure about this?
Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents