<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>27d6fab4-848</externalid>
      <Title>Staff Product Security Engineer</Title>
      <Description><![CDATA[<p>Job Title: Staff Product Security Engineer</p>
<p>Location: United States</p>
<p>Department: Security</p>
<p>Job Description:</p>
<p>This role can be based remotely anywhere in the United States. The Product Security Team&#39;s mission is to left-shift SDLC (Security Development Lifecycle) processes for all code written in Databricks (for customer use or supporting customers internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.</p>
<p>You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing, and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident.</p>
<p>You will work with a global team, spread across various locations in the US and EMEA.</p>
<p>The impact you will have:</p>
<ul>
<li>Full SDLC support for new product features being developed in ENG and non-ENG teams. This would include threat modeling, design review, manual code review, exploit writing, etc.</li>
</ul>
<ul>
<li>Work with other security teams to provide support for incident response and vulnerability response as and when needed.</li>
</ul>
<ul>
<li>Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.</li>
</ul>
<ul>
<li>Work on DAST tools and related automation for auto-assessment and defect filing.</li>
</ul>
<ul>
<li>Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPAA, etc.</li>
</ul>
<ul>
<li>Prioritize security from a risk management perspective, rather than an absolute textbook version.</li>
</ul>
<ul>
<li>Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general</li>
</ul>
<p>What we look for:</p>
<ul>
<li>3-10 years&#39; experience with the threat modeling process and ability to find design problems based on a block diagram of data flow.</li>
</ul>
<ul>
<li>Solid understanding on at least two of the following domains: web security, cloud security, systems security, and applied cryptography.</li>
</ul>
<ul>
<li>Proficient with one or more of programming languages (Python/Java/Scala/JavaScript) and ability to read code to identify security defects.</li>
</ul>
<ul>
<li>Strong skills on scripting and automation on exploits.</li>
</ul>
<ul>
<li>Fuzzing skills are good to have.</li>
</ul>
<ul>
<li>Exploit writing skills are a positive and greatly required.</li>
</ul>
<p>Pay Range Transparency:</p>
<p>Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above.</p>
<p>For more information regarding which range your location is in visit our page here.</p>
<p>Zone 1 Pay Range: $190,000 - $261,250 USD</p>
<p>Zone 2 Pay Range: $171,000 - $235,200 USD</p>
<p>Zone 3 Pay Range: $161,500 - $222,100 USD</p>
<p>Zone 4 Pay Range: $152,000 - $209,000 USD</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$190,000 - $261,250 USD</Salaryrange>
      <Skills>threat modeling, security design reviews, manual code reviews, exploit writing, exploit chain creation, incident response, vulnerability response, SAST tools, DAST tools, automation, FedRamp, PCI, HIPAA, risk management, security processes, productivity, SDLC process, web security, cloud security, systems security, applied cryptography, programming languages, scripting, fuzzing</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified platform for data, analytics, and AI. It was founded by the original creators of Lakehouse, Apache Spark, Delta Lake, and MLflow.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/7882009002</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>4b414123-045</externalid>
      <Title>Product Security Engineer II</Title>
      <Description><![CDATA[<p>We are seeking a Product Security Engineer II to join our growing security team. This role will be critical in ensuring the security of our products across the entire software development lifecycle (SDLC) and provide support on different security initiatives.</p>
<p>You will work closely with engineering, product, and operations teams to embed security best practices from design through to deployment.</p>
<p>Key responsibilities include:</p>
<p>Supporting the execution of a comprehensive product security strategy that aligns with the company&#39;s goals and risk appetite.
Working hands-on across code, infrastructure, and CI/CD to create agents, services, and pipelines that detect, prevent, and remediate risks leveraging AI where it adds value.
Designing, building, and operating security automation for the SDLC (code scanning, dependency risk management, secrets detection, policy-as-code) integrated into CI/CD.
Performing manual design and implementation reviews of Greenlight products and services from a security perspective.
Establishing and enforcing secure development standards (i.e., API security, security patterns, IaC, etc.) and best practices across the organization.
Serving as a subject matter expert on the practical security of our AI and LLM ecosystem. Leading threat modeling exercises for novel AI systems applying advanced security and privacy best practices.
Leveraging automations and tools to continuously test, fuzz, and validate products and platform components for security issues.
Performing penetration testing and retesting to validate fixes.
Responsible for triaging findings from security researchers and leading incident response for PSIRT.
On-call support for incident response and leading product-related security events and vulnerabilities.
Fostering a culture of security awareness and ownership across the Engineering and Product organizations.
Staying current with the latest security threats, vulnerabilities, and industry best practices to continuously evolve our security controls and processes.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI, AWS, MySQL, DynamoDB, Redis, Kubernetes, Ambassador, Helm, Rancher, SAST, DAST, IAST, Penetration testing, Fuzzing, Scripting, Automation, Exploit writing, Cloud security principles, Security assessment of IoT hardware/firmware, Contribution to security community, Experience at Fintech or similar regulated companies, Startup Agility</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Greenlight</Employername>
      <Employerlogo>https://logos.yubhub.co/greenlight.com.png</Employerlogo>
      <Employerdescription>Greenlight is a family fintech company serving over 6 million parents and kids with its award-winning banking app for families.</Employerdescription>
      <Employerwebsite>https://www.greenlight.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/greenlight/6daa8340-f262-454c-be7d-e3adc813fe0e</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
  </jobs>
</source>