> Markdown version of [/jobs/ext/3157673-staff-security-engineer-incident-response](https://www.wearedevelopers.com/jobs/ext/3157673-staff-security-engineer-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer, Incident Response - **Company:** Databricks - **Location:** Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Code Review, Network Security, Reverse Engineering, Security Information and Event Management, Scripting, Large Language Models, Databricks - **Published:** September 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f8e853af00d3573a ## About the Role * Bachelor's Degree AND 7+ years experience in Incident Response work OR Master's Degree AND 5+ years experience. * Cloud security expertise in at least 1 of AWS, GCP or Azure, and proficiency in the others. * Proficiency in AI/LLM and agentic capabilities. Prefer experience with building and operating agentic systems in a security setting. * Broad security subject matter expertise. * Expertise in a few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.). * Experience with Enterprise Security and SaaS applications. * Working knowledge of a SIEM and SOAR. * Experience building Incident Response Tooling, scripting language skills and experience with AI coding tools. ## Description The Incident Response team's mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We're a tight-knit team of security incident responders and incident handlers doing "Security for Databricks on Databricks", using our own platform to create near-real-time log analytics, alerting and forensics. You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks. The impact you will have: * You will respond to incidents as part of a distributed 24x7 operations and on-call schedule. * You will triage and respond to security events and alerts, ensuring quick and effective containment. * You will conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events. * You will provide technical leadership and influence team direction. * You will develop solutions, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team. * You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Fully Orchestrating Databricks from Airflow](https://www.wearedevelopers.com/videos/336-fully-orchestrating-databricks-from-airflow) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Cutting LLM Costs Without Cutting Quality: How to Beat Proprietary LLMs with Fine-Tuned Open Source](https://www.wearedevelopers.com/videos/100151-cutting-llm-costs-without-cutting-quality-how-to-beat-proprietary-llms-with-fine-tuned-open-source) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture)