Sr. Manager, Security — Continuous Monitoring v 2.0

Databricks · Remote - California · Security · listed September 21, 2026

The shape of it

Seniority
Manager
Experience asked
2–12 years
Where
Remote
Stated pay
$228,600 – $314,250 USD
Requirements listed
10
Length
1,801 words

In the posting’s own words

You will own the engineering function that measures whether Databricks' security controls are working — across cloud infrastructure, identity, SaaS, and enterprise systems — and turns that measurement into something the Security organization, and its auditors, can rely on.

What it asks for · 10

  • 2+ years of prior management experience leading Engineering or Security engineering teams.
  • Typically 12+ years of experience, or an advanced degree plus 8 years, preferably focused on security engineering, security posture monitoring, or compliance automation.
  • Sufficient technical depth to review the work of the team: can read and critique Python automation, evaluate an integration architecture, and assess whether a monitoring approach will hold up in production.
  • Solid understanding of security controls and where they fail in practice — identity and access, configuration management, logging coverage, vulnerability management, and data protection — enough to judge whether a given measurement is telling you anything useful.
  • Solid cloud security knowledge across at least one major platform (AWS, Azure, GCP) — IAM, audit logging, CSPM concepts, and cloud-native security services.
  • Working knowledge of compliance frameworks (SOC 2, ISO 27001, FedRAMP, or equivalent) at a level sufficient to assess whether a control monitoring design will satisfy an auditor.
  • Previous experience building security posture monitoring or compliance automation at scale, with attention to accuracy, coverage, and cost tradeoffs (experience with Databricks is preferred).
  • Focused on defining and driving efficiencies and improvements within the team; accountable for defining and achieving targets (e.g. OKRs, KPIs).
  • Makes effective priority decisions on resourcing and alignment within the team.
  • Strong communicator across technical, GRC, and executive audiences — can explain automation architecture to auditors and compliance requirements to engineers.

Also a plus

  • Experience with cloud security posture management (CSPM/SSPM) platforms at an architecture level.
  • Experience with FedRAMP continuous monitoring programs at a leadership level.
  • Hands-on background with GRC automation platforms (Vanta, Drata, ServiceNow GRC, Archer, or equivalent) at an implementation or architecture level.
  • Experience building automated monitoring for AI system controls and AI governance frameworks.
  • Track record of building or scaling a security measurement or compliance engineering function from early-stage to mature operations.
  • Background in security operations, detection engineering, or security architecture that informs which controls are worth measuring.
  • Experience with front-end development.
  • CISSP, CISM, CISA, or equivalent certifications.

Degree language

  • Typically 12+ years of experience, or an advanced degree plus 8 years, preferably focused on security engineering, security posture monitoring, or compliance automation.

Tools and skills named

Security & compliance
  • Security35×
  • Audit4×
  • Risk management3×
  • SOC 23×
  • PCI2×
  • Regulatory2×
  • IAM
Data
  • Databricks10×
  • Data pipelines
Cloud & infra
  • AWS
  • Azure
  • GCP
  • Observability
Go to market
  • SaaS3×
  • Partnerships
Ways of working
  • Code review
  • Cross-functional
  • Technical writing
Languages
  • Python2×
Product & design
  • Roadmap2×
Models & research
  • Evaluations

Words the posting leans on

  • security35×
  • control30×
  • engineering17×
  • monitoring16×
  • grc13×
  • posture12×
  • automation11×
  • cloud9×
  • coverage9×
  • program9×
  • experience8×
  • management8×
  • measurement8×
  • continuous monitoring7×
  • governance7×
  • leadership7×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Databricks

every open role at Databricks

How this page was made

An automated read of a public job posting, fetched September 22, 2026 and last changed by Databricks on September 21, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.