Synced from Greenhouse · 45d ago

Security Engineer, Incident Response

DatabricksSwitzerlandPosted Jul 3, 2026
Security EngineerSenior
Apply now - freeSave & get alerts

Mirrored from Databricks's own Greenhouse careers system · refreshed hourly

805
Other open Databricks roles
45d ago
Posted
Greenhouse
Applicant system
Job descriptionReq 8618455002

RDQ326R15

The Incident Response team's mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We're a tight-knit team of security incident responders and incident handlers doing "Security for Databricks on Databricks", using our own platform to create near-real-time log analytics, alerting and forensics.

You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.

The impact you will have:

  • You will respond to incidents as part of a distributed 24x7 operations and on-call schedule.
  • You will triage and respond to security events and alerts, ensuring quick and effective containment.
  • You will contribute to security investigations, conducting analysis and forensics across a range of data sources to determine the timeline and impact of security events.
  • You will build automations, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
  • You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.

What we look for:

  • Bachelor's Degree AND 4+ years experience in Incident Response work OR Master's Degree AND 2+ years experience.
  • Strong cloud security background in at least 1 of AWS, GCP or Azure, and working knowledge of the others.
  • Knowledge of AI/LLM and agentic capabilities, including effective prompting and use of MCP, agents and agent skills. Prefer experience with building and operating agentic systems in a security setting.
  • Broad security subject matter expertise.
  • Expertise in few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
  • Experience with Enterprise Security and SaaS applications.
  • Working knowledge of a SIEM and SOAR.
  • Experience building Incident Response Tooling and scripting language skills.

 

About Databricks

Databricks is the Data and AI company. More than 20,000 organizations worldwide — including adidas, AT&T, Bayer, Block, Mastercard, Rivian, Unilever, and 70% of the Fortune 500 — rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics and agents. Headquartered in San Francisco with 30+ offices around the globe, Databricks offers a unified platform that includes Genie, Lakebase, Agent Bricks, Lakeflow, Lakehouse, and Unity Catalog. To learn more, follow Databricks on LinkedIn, X, YouTube, and Instagram.

Benefits

At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here.

Our Commitment to Diversity and Inclusion

At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

Compliance

If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

Applicant Privacy Notice

View original posting on Greenhouse

What applying to Databricks usually looks like

Based on publicly available information, candidates applying through greenhouse for roles at Databricks can generally expect an online application followed by an initial resume screen. If selected, candidates may be invited to a recruiter phone screen to discuss background, motivation, and role fit, followed by one or more interviews with hiring managers or team members. Depending on the role, technical positions may include coding exercises, case studies, or system design discussions, while business roles may involve skills assessments or presentations. Later stages can generally include panel interviews or onsite-style virtual interviews with cross-functional stakeholders. Communication and scheduling are typically coordinated through the Greenhouse platform, and response times vary depending on team needs and volume of applicants. Candidates should prepare to demonstrate both technical or functional expertise and alignment with company values throughout the process.”}

Based on publicly available information. LandEarly does not verify interview process details.

Land this one early - before the req fills.

LandEarly tailors your resume and screening answers to each posting, submits within minutes of a role going live, and tracks every application in one place.

Free to start · No credit card · Cancel anytime

Keep exploring

What this role pays, where else it is open, and how to write the application.

Security Engineer, Incident Response
Databricks · Switzerland
Apply