Staff Enterprise Security Engineer

Databricks · Remote - California · Security · listed April 1, 2026

The shape of it

Seniority
Staff
Experience asked
8+ years
Where
Remote
Stated pay
$194,800 – $267,850 USD
Requirements listed
10
Length
1,041 words

In the posting’s own words

This role sits at the intersection of enterprise architecture, security engineering, product security partnership, and business enablement. Corporate production development within the Databricks platform remains owned by the Data team; EntSec defines how we engage, reviewing implementation designs, configurations, and data flows as capabilities are built, alongside ongoing enterprise application and integration reviews. The engineer will assess new technologies, integrations, and workflows with an emphasis on secure design, authentication and authorization, data handling, logging, third-party connectivity, API and token security, and operational resilience. The role partners closely with Product Engineering, IT, Legal Privacy, and business stakeholders to surface risk early, set clear requirements, and build automation that scales security coverage. This is a strong opportunity to help shape how Enterprise Security supports Databricks product development, enterprise data security, SaaS, and internal platforms, automation, and AI-connected systems as the environment continues to grow in complexity.

What it asks for · 10

  • 8+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field.
  • Experience conducting security design or architecture reviews for product features, enterprise applications, SaaS platforms, integrations, or internally developed systems.
  • Hands-on familiarity with the Databricks platform or comparable data/AI platforms (Unity Catalog, workspace governance, service principals, data access patterns).
  • Strong understanding of authentication, authorization, SSO, federation, SCIM, API security, token handling, secrets management, and least privilege design.
  • Experience assessing data flows, third-party integrations, trust boundaries, logging and monitoring, and security controls across interconnected systems.
  • Proven track record building security automation in production: monitoring, posture checks, review workflows, or tooling (Python, SQL, Terraform, or similar).
  • Ability to evaluate risk in modern enterprise environments, including automation platforms, AI-adjacent workflows, and emerging integration patterns such as MCP.
  • Strong written and verbal communication skills, including the ability to translate technical risk into clear requirements and actionable guidance.
  • Experience driving security outcomes through engineering judgment, influence, and scalable process improvement.
  • Familiarity with cloud platforms, enterprise identity systems, and core control domains such as audit logging, encryption, access control, data retention, and incident response.

Tools and skills named

Security & compliance
  • Security36×
  • Audit
Data
  • Databricks7×
Go to market
  • SaaS2×
Languages
  • Python
  • SQL
Cloud & infra
  • Terraform
Operations & finance
  • Process improvement
Ways of working
  • Cross-functional

Words the posting leans on

  • security33×
  • enterprise16×
  • data14×
  • platform12×
  • integration10×
  • product10×
  • automation8×
  • design8×
  • engineering8×
  • review8×
  • outcome6×
  • requirements6×
  • risk6×
  • data flows5×
  • systems5×
  • configuration4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Databricks

every open role at Databricks

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Databricks on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.