Staff Security Engineer, Incident Response
Databricks is hiring a Staff Security Engineer, Incident Response for a remote role open to applicants in United States. Level rates it ; you can apply on Level.
AI in this role
Lead security incident response and develop autonomous agentic security solutions using AI platforms.
RDQ227R1180
While candidates in the listed location(s) are encouraged for this role, candidates in other locations (US based) will be considered.
The Incident Response team's mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We're a tight-knit team of security incident responders and incident handlers doing "Security for Databricks on Databricks", using our own platform to create near-real-time log analytics, alerting and forensics.
You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.
The impact you will have:
- You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
- You will triage and respond to security events and alerts, ensuring quick and effective containment.
- You will conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events.
- You will provide technical leadership and influence team direction.
- You will develop solutions, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
- You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.
What we look for:
- Must have an active or current US GOV Secret clearance eligibility; Top Secret preferred.
- Bachelor's Degree AND 7+ years experience in Incident Response work OR Master's Degree AND 5+ years experience.
- Cloud security expertise in at least 1 of AWS, GCP or Azure, and proficiency in the others.
- Proficiency in AI/LLM and agentic capabilities. Prefer experience with building and operating agentic systems in a security setting.
- Broad security subject matter expertise.
- Expertise in a few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
- Experience with Enterprise Security and SaaS applications.
- Working knowledge of a SIEM and SOAR.
- Experience building Incident Response Tooling, scripting language skills and experience with AI coding tools.
About Databricks
Databricks is the Data and AI company. More than 20,000 organizations worldwide — including adidas, AT&T, Bayer, Block, Mastercard, Rivian, Unilever, and 70% of the Fortune 500 — rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics and agents. Headquartered in San Francisco with 30+ offices around the globe, Databricks offers a unified platform that includes Genie, Lakebase, Agent Bricks, Lakeflow, Lakehouse, and Unity Catalog. To learn more, follow Databricks on LinkedIn, X, YouTube, and Instagram.
Benefits
At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here.
Our Commitment to Diversity and Inclusion
At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.
Compliance
If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.
How we rate this
Staff Security Engineer, Incident Response at Databricks rates 65 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.
Works on AI. The daily work is on AI products, without building the model.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where forensics was part of your work. What did you do?
- Tell me about a project where ai systems was part of your work. What did you do?
- Tell me about a project where agentic platforms was part of your work. What did you do?
- Tell me about a project where cloud security was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Incident Response, Forensics, AI Systems, Agentic Platforms, and Cloud Security. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them. A tool named with nothing behind it rarely survives a human read.
- Show where AI is part of your daily process, not a one-off project. This role expects it to be a running habit.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get new remote cybersecurity jobs (Works on AI ●●●○ or higher) by email
One email a week with the new remote cybersecurity jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that work on AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step