Staff Security Engineer, Incident Response

Databricks
Belgium
12 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Security Code Review Network Security Reverse Engineering Security Information and Event Management Scripting Large Language Models Databricks

Job description

The Incident Response team’s mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We’re a tight-knit team of security incident responders and incident handlers doing “Security for Databricks on Databricks”, using our own platform to create near-real-time log analytics, alerting and forensics.

You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.

The impact you will have:

  • You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
  • You will triage and respond to security events and alerts, ensuring quick and effective containment.
  • You will conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events.
  • You will provide technical leadership and influence team direction.
  • You will develop solutions, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
  • You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.

Requirements

  • Bachelor’s Degree AND 7+ years experience in Incident Response work OR Master’s Degree AND 5+ years experience.
  • Cloud security expertise in at least 1 of AWS, GCP or Azure, and proficiency in the others.
  • Proficiency in AI/LLM and agentic capabilities. Prefer experience with building and operating agentic systems in a security setting.
  • Broad security subject matter expertise.
  • Expertise in a few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
  • Experience with Enterprise Security and SaaS applications.
  • Working knowledge of a SIEM and SOAR.
  • Experience building Incident Response Tooling, scripting language skills and experience with AI coding tools.

Benefits & conditions

At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees.

About the company

Databricks is the Data and AI company. More than 20,000 organizations worldwide - including adidas, AT&T, Bayer, Block, Mastercard, Rivian, Unilever, and 70% of the Fortune 500 - rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics and agents. Headquartered in San Francisco with 30+ offices around the globe, Databricks offers a unified platform that includes Genie, Lakebase, Agent Bricks, Lakeflow, Lakehouse, and Unity Catalog. To learn more, follow Databricks on LinkedIn, X, YouTube, and Instagram.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

5:14 min

Executing Databricks jobs with built-in Airflow operators

Alan Mazankiewicz ¡ LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho ¡ World Congress 2026 Europe

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady ¡ World Congress 2026 Europe

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper ¡ Europe 2026 Virtual

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn ¡ LIVE

Videos

See all

Related articles

See all