
Databricks · Remote - California
RDQ227R1176 While candidates in the listed location(s) are encouraged for this role, candidates in other locations (US based) will be considered. Mission Dat...
While candidates in the listed location(s) are encouraged for this role, candidates in other locations (US based) will be
considered.
Mission
Databricks is hiring an L6 Enterprise Security Engineer to expand Enterprise Security coverage across a rapidly evolving
enterprise environment. This role will focus on securing enterprise applications, cross-system integrations, data flows, and
emerging AI-adjacent use cases. The scope includes modern access patterns such as MCP, integration, and trust boundary security,
and broader security engineering support across enterprise platforms and services. This engineer will help identify risk, define
practical security requirements, and improve security outcomes through strong technical judgment and cross-functional partnership.
Opportunity
This role sits at the intersection of enterprise architecture, security engineering, and business enablement. The engineer will
review new technologies, integrations, and workflows with an emphasis on secure design, authentication and authorization, data
handling, logging, third-party connectivity, API and token security, and operational resilience. The role partners closely with
IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support
scalable adoption of secure patterns. This is a strong opportunity to help shape how Enterprise Security supports SaaS, internal
platforms, automation, and AI-connected systems as the environment continues to grow in complexity.
internally developed systems.
and least privilege design
across interconnected systems.
integration patterns such as MCP.
actionable guidance.
access control, data retention, and incident response.
Outcomes
improving requirement quality, and helping teams address security issues earlier in the lifecycle.
and cross-system data flow risk, while improving the consistency and scale of security reviews.
allowing IT workflows, internal bots, and automation platforms to call Enterprise Security guidance directly for risk triage,
control validation, and escalation decisions. This should reduce dependency on manual review and embed security guidance
earlier in the system lifecycle.
Pay Range Transparency
Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and
represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual
compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related
skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above,
Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include
eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your
location is in visit our page here.
Zone 1 Pay Range
Zone 2 Pay Range
Zone 3 Pay Range
Zone 4 Pay Range
About Databricks
Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and
over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI.
Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse,
Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.
Benefits
At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific
details on the benefits offered in your region click here.
Our Commitment to Diversity and Inclusion
At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to
ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment
at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or
expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation,
socio-economic status, veteran status, and other protected characteristics.
Compliance
If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's
discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an
applicant on this basis alone.
RDQ426R108 This role is open to candidates in the US (any location) ABOUT THE TEAM The AI Security team at Databricks sits at the frontier of securing the AI/ML services in the Databricks platform. As we ship AI capabilities at the leading edge of the industry, including Agent Bricks, the Genie suite, AI Model Serving, MLflow, and Unity AI Gateway, the AI Security team ensures these systems are designed, built, and operated securely. Our work also extends to securing our own usage of AI: building the right guardrails that enable Databricks employees to innovate and deliver securely. The team combines offensive security depth with AI/ML engineering knowledge to identify novel threats, build scalable defenses, and influence how AI products are architected from the ground up. We lead AI Red Team exercises, build security tooling for AI workloads, and partner directly with AI Product teams to embed security into the development lifecycle. --- THE ROLE As a Staff Security Software Engineer on the AI Security team, you are a senior technical leader who sets the standards for how Databricks secures its AI and ML capabilities. You combine deep offensive security expertise with practical knowledge of AI/ML systems to identify and drive resolution of the most significant security risks in Databricks' AI platform. You lead AI red team engagements against production AI systems, conduct security architecture reviews for complex, multi-system AI features, and build the tooling and frameworks that scale the team's impact. You are a subject matter expert in at least two AI security domains and you operate with significant autonomy- driving cross-team remediation, setting technical standards, and mentoring teammates in both offensive techniques and secure AI design. --- THE IMPACT YOU WILL HAVE AI RED TEAM & ADVERSARIAL TESTING * Lead AI red team engagements against Databricks' production AI systems, including Foundation Model APIs, Genie and natural language query systems, Model Serving infrastructure, MCP-connected agents, and RAG pipelines * Design and execute adversarial attack scenarios: prompt injection, jailbreaking, memory poisoning, cross-tenant data leakage in multi-tenant serving, and sandbox bypasses * Develop proof-of-concept exploits for AI-specific vulnerability classes and perform variant analysis to identify the full scope of exposure across the AI platform * Contribute to the evolution of the Databricks AI Security Framework (DASF), maintaining and extending the risk taxonomy, control library, and testing methodology as AI capabilities evolve AI PRODUCT SECURITY & ARCHITECTURE REVIEWS * Lead comprehensive security architecture reviews for complex AI features: threat modeling agentic workflows, RAG pipelines, multi-model serving chains, and MCP-based tool integrations * Partner directly with AI and ML engineering teams to identify security risks early in the design process and define practical, scalable controls * Assess and drive resolution of cross-cutting AI security risks: Unity Catalog permission enforcement in AI contexts, inference data isolation, model artifact integrity, fine-tuning pipeline security, and external model API governance via AI Gateway * Identify recurring security patterns across AI features; advocate for class-level architectural fixes rather than feature-by-feature point solutions AI SECURITY TOOLING & AUTOMATION * Design and build automated AI security testing tooling, including adversarial prompt libraries, agent behavior analysis frameworks, and continuous testing harnesses * Build AI-assisted automation that scales security reviews, threat modeling, and vulnerability triage for AI features * Develop and maintain security guardrails and enforcement mechanisms: LLM-as-judge review, prompt delimiting, output validation, rate limiting, and audit logging CROSS-TEAM REMEDIATION & STANDARDS * Set technical standards for how AI security risks are assessed, prioritized, and remediated across the engineering organization * Drive cross-team remediation for significant AI security findings, defining fix requirements, validating patches, and ensuring regression coverage in CI/CD pipelines * Produce high-quality threat models, security advisories, and post-mortems that inform organizational risk decisions for AI products MENTORSHIP & COMMUNITY * Mentor engineers on the AI Security team in adversarial ML techniques, AI threat modeling, and security tooling development * Contribute to internal knowledge assets, including training materials, design patterns, and threat model templates, that raise AI security fluency across the engineering organization * Represent Databricks in the external AI security community through publications, conference talks, or open-source contributions --- WHAT WE LOOK FOR * 7–10 years of combined experience in offensive security, AI/ML security research, or product security engineering, with demonstrated leadership in securing complex systems * Subject matter expert in at least two of the following AI security domains: - LLM and generative AI security (prompt injection, jailbreaking, training data extraction) - AI agent and orchestration security (MCP, memory sharing, multi-agent systems) - ML infrastructure and serving security (model serving multi-tenancy risks, training infrastructure security) - AI data governance and privacy (fine-grained access control, data residency, inference data isolation) * Demonstrated ability to design and execute adversarial attacks against production AI systems * Deep understanding of AI/ML platform architecture- how models are trained, served, and integrated, and where the trust boundaries between components lie * Expert in at least one major cloud platform (AWS, Azure, GCP) and its AI/ML security model * Proficient in Python; able to read and analyze ML model code, training scripts, and API serving code; working knowledge of at least one additional language (Go, Java, Scala, Rust) * Track record of driving cross-team AI security improvements and influencing product architecture decisions * Experience building automated security tooling for AI systems * Strong communicator- translates AI security risks into actionable guidance for engineers, product managers, and leadership * Pragmatic approach to risk- distinguishes real-world exploitable AI risk from theoretical concerns NICE TO HAVE * Published research on AI/ML security topics or experience presenting at AI security venues (DEF CON AI Village, NeurIPS workshops, Black Hat) * Experience with OWASP Top 10 for LLMs, MITRE ATLAS, or similar AI security frameworks * Familiarity with MLflow, Unity Catalog, Delta Lake, or Databricks platform internals * OSCP or equivalent offensive security certification * Academic or research background in machine learning, adversarial ML, or AI safety --- WHY DATABRICKS On the AI Security team, you'll work on a class of security problem that didn't exist five years ago, and that the industry is still figuring out. You'll run red team engagements against a live AI platform used by over 12,000 organizations, build tooling that has no precedent to copy, and drive security decisions that shape how AI products are built across the company. The problems are novel, the stakes are real, and the team working on them is exceptional. About Databricks Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook. Benefits At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here. Our Commitment to Diversity and Inclusion At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics. Compliance If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.
RDQ327R181 While candidates in the listed location(s) are encouraged for this role, candidates in other US locations will be considered. The Security Field Engineering team helps data teams solve the world's toughest problems by empowering customers to understand the security of the Databricks platform and by helping account teams address questions that come up during security reviews. Reporting to the Head of Security Field Engineering, you will meet with customers to answer questions, train other Databricks team members, build customer-facing content such as slide decks, white papers, and maybe write code that customers can use. Our team prioritizes scale -- we'd rather spend an hour building a doc than be in ten hours of meetings, rather deliver agent skills and knowledge base articles than be the rock star answering all the questions. If you want high growth, autonomy, and to touch all elements of security, look no further. The impact you will have: * You will be viewed as a security expert as you work with field teams and customers to understand architectures, address concerns and handle compliance questions * Your contributions may come in multiple ways, including customer interactions, scalable slides or white paper creation, internal enablement, process improvement, automation, or technical leadership—no one excels in every area, but all are valuable * When you’re on the call, you will be directly appreciated. When you’re not, your impact will be felt across the company through the enablement, collateral, knowledge management, and systems you build * You might not come from an assurance team, but you’ll come up to speed with common security and compliance regimes to save customers hours of effort and months of uncertainty * You will identify customer pain points and work with product management and product marketing will improve our product and our messaging * You will contribute to internal-facing services and automation that make life easier for our field staff and our customers. * You are probably already great at AI productivity, but you’ll sit in a group focused on becoming legendary. What we look for: * 6 + years of technical pre-sales or post-sales experience where you're the person in the room explaining the hard concepts * Equal love of understanding complex security principles and architectures, and of communicating them simply * Real-world experience in multiple security domains such as IaaS+PaaS+SaaS, network and endpoint security, web applications, vulnerability management, identity management, and SIEM, though not all are needed * You've done some scripting or programming, and are excited to use AI relentlessly to scale our impact across many thousands of customers and employees. * Understanding of the Databricks platform is a strong plus. Pay Range Transparency Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here. Zone 1 Pay Range $194,800—$267,850 USD Zone 2 Pay Range $175,400—$241,100 USD Zone 3 Pay Range $165,600—$227,700 USD Zone 4 Pay Range $155,800—$214,300 USD About Databricks Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook. Benefits At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here. Our Commitment to Diversity and Inclusion At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics. Compliance If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.
RDQ226R605; This role can be based remotely anywhere in the United States. The AI Security Engineering team at Databricks builds the security tools, detection systems, and engineering infrastructure that protect Databricks' AI platform and the AI capabilities our customers depend on. We are the builders — designing and shipping security tooling that scales AI threat detection, automates security assessment of AI systems, and gives Databricks and its customers high-confidence assurance that AI capabilities are operating securely. We sit at the intersection of security engineering and AI systems: we understand how AI systems work, how they can be attacked, and how to build engineering solutions that keep them safe at scale. --- As a Staff Security Software Engineer on the AI Security Engineering team, you set the technical direction for AI security engineering at Databricks — defining the architecture, standards, and methodology by which the team builds tooling for AI security assessment, detection, and defense. You are recognized across the Security organization as the authority on AI security engineering: the person engineering leadership consults when AI security tooling decisions have organizational-scale consequences. You operate across team and organizational boundaries — aligning the AI Security Engineering team's technical roadmap with the detection, GRC, and product security teams that depend on its outputs, and driving AI security engineering standards that the whole security organization can adopt. --- THE IMPACT YOU WILL HAVE AI SECURITY ENGINEERING ARCHITECTURE * Define the architecture and technical strategy for Databricks' AI security tooling platform — spanning adversarial testing, behavioral monitoring, threat detection, and automated assessment of AI components * Set engineering standards for the team: design review processes, reliability requirements, observability practices, security properties of the tooling itself, and integration patterns with downstream consumers * Own the technical decisions on how the team's systems scale to cover Databricks' growing AI surface, how they integrate with product security and detection pipelines, and what tooling capabilities to build vs. buy vs. open-source AI THREAT DETECTION AT SCALE * Lead the design and development of AI platform capabilities that operate at production scale — behavioral analysis of usage, detection of prompt injection attempts, anomaly detection on agentic workflow behavior * Define the methodology for AI security assessment: how Databricks systematically evaluates new AI capabilities against a comprehensive threat model before deployment and monitors them continuously after * Drive technical strategy for AI red-teaming tooling: automated adversarial testing platforms that simulate how real attackers attempt to abuse Databricks' AI systems CROSS-ORGANIZATIONAL TECHNICAL LEADERSHIP * Serve as the technical authority on AI security engineering for the Product Security, SITH, IR, and ConMon teams — ensuring that AI security tooling outputs integrate cleanly into their workflows and meet their detection and assessment needs * Represent AI Security Engineering in architecture reviews, platform security decisions, and cross-team technical discussions where AI security engineering considerations are material * Establish AI security engineering standards that teams building AI-connected systems can adopt — reusable patterns for securing AI components in the Databricks platform MENTORSHIP & TEAM CAPABILITY * Mentor senior and mid-level engineers on AI security engineering architecture, adversarial threat modeling, and technical leadership * Lead design reviews, define team engineering practices, and drive continuous improvement in the quality and reliability of AI security tooling --- WHAT WE LOOK FOR * 7–10 years of experience in security software engineering, security engineering, or a closely related discipline; with demonstrated technical leadership of security tooling programs and organizational-level impact * Expert Python engineering: designs and delivers production systems at scale; understands observability, reliability engineering, and how security tooling integrates into larger security operations ecosystems * Deep expertise in AI/ML security — adversarial ML, prompt injection, model security, agentic framework trust boundaries — at both a research-informed and engineering-practical level * Experience designing security tooling architectures that span multiple teams and systems — not just building features, but defining how the platform is structured, scaled, and maintained * Strong technical communicator: can align engineering and security leadership on architectural direction and drive cross-team adoption of standards and patterns * Track record of shipping high-quality security tooling that other teams depend on in production NICE TO HAVE * Research contributions or deep familiarity with adversarial ML, AI safety, or AI red-teaming methodology * Experience with MLOps platforms, AI serving infrastructure, or AI platform security at cloud scale * Familiarity with AI governance standards (NIST AI RMF, ISO/IEC 42001, EU AI Act technical provisions) as they apply to security engineering * Open-source contributions or publications in AI security, adversarial ML, or security tooling Pay Range Transparency Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here. Zone 1 Pay Range $289,200—$397,650 USD Zone 2 Pay Range $260,300—$357,950 USD Zone 3 Pay Range $245,800—$338,050 USD Zone 4 Pay Range $231,400—$318,100 USD About Databricks Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook. Benefits At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here. Our Commitment to Diversity and Inclusion At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics. Compliance If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.