Sr. Staff Product Security Engineer

1 day ago


Bengaluru, Karnataka, India Databricks Full time US$ 1,25,000 - US$ 1,75,000 per year

RDQ226R536

About The Team
The Product Security Team at Databricks is responsible for embedding security throughout the Software Development Lifecycle (SDLC). Our mission is to
left-shift
security—ensuring that all code, whether powering customer-facing features or supporting internal infrastructure, is developed with security in mind from the start. By reducing the likelihood of introducing vulnerabilities and minimizing the impact of externally reported issues, we safeguard Databricks' products and services at scale.

Role Overview
As a
Product Security Engineer
, you will play a key role in securing the features and infrastructure that power Databricks. You will partner closely with engineering teams across the organization to design secure systems, conduct security reviews, and enable scalable, repeatable secure development practices through automation, paved pathways, and guardrails.

You'll support the full spectrum of security within the SDLC—from architecture and threat modeling through secure coding, pentesting, and deployment. In addition, you will contribute to incident and vulnerability response efforts and help scale our security influence through tools, frameworks, and processes that support both engineers and compliance needs.

Responsibilities

  • Partner with product and engineering teams to design secure systems, identify risks early, and guide the development of robust solutions
  • Conduct comprehensive security reviews including threat modeling, design analysis, manual code reviews, and exploit development to validate potential weaknesses
  • Design and build guardrails that prevent common security mistakes and ensure consistent, enforceable policies across services
  • Develop and maintain paved pathways—secure-by-default development patterns, frameworks, and tools that enable engineering teams to build securely without friction
  • Triage and analyze findings from Static Application Security Testing (SAST) tools, distinguishing false positives from genuine issues and performing variant analysis to identify similar vulnerabilities across the codebase.
  • Operate and evolve Dynamic Application Security Testing (DAST) tooling and automation to support vulnerability detection and defect tracking
  • Support incident response (IR) and vulnerability response (VRP) workflows as needed, partnering with internal teams to investigate and remediate security events
  • Enhance internal security automation frameworks and integrations to meet evolving compliance and regulatory requirements (e.g., FedRAMP, PCI, HIPAA)
  • Contribute to the continuous improvement of SDLC-integrated security processes, with a focus on risk-based prioritization, real-world impact, and the implementation of AI-assisted tooling to enhance efficiency, accuracy, and scalability.

What We Look For

  • 10+ years of experience in product or application security, with deep expertise in securing large-scale, distributed systems
  • Extensive experience influencing architectural decisions, embedding security-by-design principles, and aligning security goals with business objectives
  • Proven leadership in cross-functional initiatives, including incident response, security reviews, and risk management at scale
  • Recognized mentor and technical leader, enabling the growth of security-minded culture through coaching, training, and collaboration
  • Thought leader in emerging security technologies and practices, including the integration of AI/ML to scale security operations and tooling
  • Expertise in at least two of the following domains:
  • Ability to read code and identify security defects in two or more programming languages (e.g., Python, Java, Scala, JavaScript)
  • Hands-on experience with exploit development, proof-of-concept creation, or exploit chaining
  • Strong automation skills for building security tools and processes using AI-agents (think Cursor, Goose, VSCode, etc)
  • Familiarity with fuzzing techniques is a plus
  • Pragmatic approach to security—prioritizing risk management over theoretical severity
  • Other good to have credentials

About Databricks
Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.

Benefits
At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please visit

Our Commitment to Diversity and Inclusion
At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

Compliance
If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.



  • Bengaluru, Karnataka, India beBeeSenior Full time ₹ 2,07,36,000 - ₹ 3,02,40,000

    Job Title: Digital Engineering Sr. Staff Lead About the Role The role of a Digital Engineering Sr. Staff Lead is to lead and mentor a team of skilled professionals in designing, developing, and maintaining cutting-edge cloud infrastructure solutions. Key Responsibilities Design, develop, and maintain Terraform configurations for GCP infrastructure...

  • Staff Engineer

    14 hours ago


    Bengaluru, Karnataka, India Rubrik Security Cloud Full time US$ 1,50,000 - US$ 2,00,000 per year

    Staff Engineer, Rubrik Security AppsBangalore, IndiaAbout Team:The Rubrik Security Apps team helps customers secure their data on the cloud, SaaS and on-prem. Data is growing at an ever growing pace and so are the risks with cyber attacks targeted towards cloud data. We make it easy for businesses to protect, search, analyze all of their data simply and...

  • Staff Engineer

    1 day ago


    Bengaluru, Karnataka, India Safe Security Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    At SAFE Security, our vision is to be the Champions of a Safer Digital Future and the Catalysts of Change. We believe in empowering individuals and teams with the freedom and responsibility to align their goals, ensuring we all move forward together We operate with radical transparency, autonomy, and accountability—there's no room for brilliant jerks. We...


  • Bengaluru, Karnataka, India Motive Full time US$ 1,04,000 - US$ 1,30,878 per year

    Who we are:Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you...


  • Bengaluru, Karnataka, India Cadence Full time

    Job DescriptionAt Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.Position: IT- Sr Staff Systems EngineerLocation: Noida/BangaloreExperience: 15+ YrsJob SummaryWe are looking for a skilled detail-oriented specialist to manage and secure Active Directory environment, Windows server administration...


  • Bengaluru, Karnataka, India Cadence Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.Position:IT- Sr Staff Systems EngineerLocation:Noida/BangaloreExperience:15+ YrsJob SummaryWe are looking for a skilled detail-oriented specialist to manage and secure Active Directory environment, Windows server administration including OS hardening,...


  • Bengaluru, Karnataka, India Stellantis Full time

    Job Description: Sr. Staff SoC BSW Engineer – OS & Hypervisor, Cybersecurity Position Summary: We are seeking a Sr. Staff SoC BSW Engineer – OS & Hypervisor, Cybersecurity to lead the secure design, development, and integration of operating system and hypervisor software components for next-generation automotive SoC platforms. This role combines...


  • Bengaluru, Karnataka, India Iitjobs Inc. Full time ₹ 2,40,000 per year

    GreetingsWe have an urgent opening Sr. Cloud Security Engineer- AWS, Azure, GCP - RemoteRole:- Cloud Security EngineerLocation- RemoteDuration: Long term ContractualBudget: 24 LPAShift: Rotational Shift( 9am - 6pm, 12pm -9pm, 6pm-3am)Immediate to 15 days JoinerJD:Proven hands-on experience with security features and policy enforcement in Azure, AWS, and...


  • Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per year

    Job Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...


  • Bengaluru, Karnataka, India Alcon Full time US$ 90,000 - US$ 1,20,000 per year

    The Sr. Associate I, Product Development, Security & Operations (DevSecOps) (Science/Tech/Engineering Path), is primarily responsible for integrating security into product development and operational systems, working closely with teams to ensure secure practices and effective automation. Specifics include:• Assist in integrating security measures within...