Sr. Security Detection Engineer
Remote - California
While candidates in the listed locations are encouraged for this role, we are open to remote candidates in other locations.
RDQ125R45
The Detection & Response team's mission is to protect Databricks products, cloud infrastructure, endpoints and employees from security threats and modern attacks. We are a team of expert engineers combining log analysis expertise, cybersecurity skills and software development to build a mature and durable detection platform. We embrace “Detection-as-Code” model by doing “Security for Databricks on Databricks”, using our own platform to build alerts and detections.
You are passionate about ML-based intrusion detection. You have experience building ML at enterprise scale, and are comfortable implementing models from conception to production. You also love to learn continuously about novel attacks, dig into the inner details of cyber-security incidents, discover new log sources and undocumented schemas to detect suspicious activities, and think about attacks using graphs.
You will be an individual contributor on the Security Detection team at Databricks, reporting to the Sr Manager of Detection Engineering.
The impact you will have:
- Dive into new or unknown log sources to understand events, schemas, raw data and build a detection strategy based on threats and adversaries knowledge
- Partner with our data team to build the most efficient and useful log ingestion pipelines
- Engineer detections on Spark in Python using Databricks (with good design, clean code, unit testing, full documentation).
- Fuse numerous log types to implement anomaly- and ML-based intrusion detection on the Databricks platform.
- Partner with Incident Response to provide rich logs, hunting playbooks and relevant alerts with full context, with near-zero false positives
- Present at security/engineering conferences novel detection work and ideas
What we look for:
- 5+ years of software engineering experience
- 3+ years of Security-related engineering (Detection Engineering preferred)
- Proficient in one major cloud, broad experience in at least one other major cloud (AWS, Azure or GCP)
- Knowledge across two or more Security SME areas: Network security, Host/Disk analysis, Application/Log analysis, Memory/Malware analysis, Endpoint security
- Experience with Python, Git/GitHub, and CI/CD automation.
- Experience with applying machine learning (ML) to security problems.
- Individuals who love to learn, execute fast, take feedback well, and give feedback in an environment of mutual respect and aid.
- Communicates effectively with internal and external stakeholders; communicates recommendations and decisions through appropriate collateral …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
Open to remote candidates in other locations
Benefits/Perks401(k) Plan Annual personal development Annual personal development fund Comprehensive health coverage Comprehensive health coverage including medical, dental, and vision Employee assistance Employee Assistance Program Equity awards Family Planning Fitness Reimbursement Flexible time off Health coverage Medical, dental, and vision Mental wellness resources Paid parental leave Pay Range Transparency Personal development fund Work headphones reimbursement
Tasks- Documentation
AI Analytics Apache Spark AWS Azure Cloud Cloud Computing Cybersecurity Data Databricks Delta Lake Excel GCP Git/GitHub Incident Response IT Log Analysis Machine Learning ML MLFlow Python Software Development Spark
Education TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9