Sr. Security Engineer
Location
United States
Posted
59 days ago
Salary
0
Seniority
Senior
Job Description
Sr. Security Engineer
Databricks
Role Description Databricks is hiring an L5 Enterprise Security Engineer to expand Enterprise Security coverage across a rapidly evolving enterprise environment. This role will focus on securing enterprise applications, cross-system integrations, data flows, and emerging AI-adjacent use cases. The scope includes modern access patterns such as MCP, integration, and trust boundary security, and broader security engineering support across enterprise platforms and services. This engineer will help identify risk, define practical security requirements, and improve security outcomes through strong technical judgment and cross-functional partnership. This role sits at the intersection of enterprise architecture, security engineering, and business enablement. The engineer will: - Review new technologies, integrations, and workflows with an emphasis on secure design, authentication and authorization, data handling, logging, third-party connectivity, API and token security, and operational resilience. - Partner closely with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support scalable adoption of secure patterns. - Help shape how Enterprise Security supports SaaS, internal platforms, automation, and AI-connected systems as the environment continues to grow in complexity. Qualifications - 7+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field. - Experience conducting security design or architecture reviews for enterprise applications, SaaS platforms, integrations, or internally developed systems. - Strong understanding of authentication, authorization, SSO, federation, SCIM, API security, token handling, secrets management, and least privilege design. - Experience assessing data flows, third-party integrations, trust boundaries, logging and monitoring, and security controls across interconnected systems. - Ability to evaluate risk in modern enterprise environments, including automation platforms, AI-adjacent workflows, and emerging integration patterns such as MCP. - Strong written and verbal communication skills, including the ability to translate technical risk into clear requirements and actionable guidance. - Experience driving security outcomes through engineering judgment, influence, and scalable process improvement. - Familiarity with cloud platforms, enterprise identity systems, and core control domains such as audit logging, encryption, access control, data retention, and incident response. Requirements - Strengthen security practices across enterprise application and integration reviews by identifying key risks early, improving requirement quality, and helping teams address security issues earlier in the lifecycle. - Strengthen Enterprise Security’s capability to assess and guide AI-adjacent security, MCP and integration security, and cross-system data flow risk, while improving the consistency and scale of security reviews. Benefits - At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please visit mybenefitsnow.com/databricks .
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Data Security Services Compliance Manager
EntrustEntrust Corporation is a software development company on a mission to keep the world moving safely by enabling trusted experiences for payments, identities, and digital infrastruct
• Ensure Entrusts Public Key Infrastructure Certificate Authority (PKI CA) products meet applicable compliance frameworks, customer contractual requirements, and emerging standards across multiple communities of trust. • Provide support as needed to ensure that other DSS products remain in compliance with the applicable frameworks, regulatory requirements and customer contractual requirements for each. • Escalate compliance issues that arise in production service environments to the Entrust Policy Management Authority (EPMA) while maintaining on-going ownership of the issues and supporting PA/EPMA direction through issue resolution. • Facilitate external auditor engagements, organize required compliance evidence, schedule required resources, submit required reports, and manage audit timelines. • Closely monitor and advise product and development teams on regulatory priorities and emerging PKI use cases from multiple communities of trust (e.g., financial services, healthcare, government). • Feedback and monitor requirements and/or requirements change for each community of trust to the internal teams, ensuring alignment with Entrust’s compliance strategy. • Represent Entrust and take the lead on standards body engagement, as directed. • Make recommendations and follow-up to mitigate compliance risks and drive continuous improvement. • Oversee and drive the end-to-end operational security compliance and audit programs for WTCA and other applicable frameworks. • Review and make recommendations on operational procedures to ensure they efficiently and effectively comply with all relevant requirements. • Contribute applicable metrics to product compliance scorecards. • Facilitate timely identification, communication, and recommended resolution of compliance risks. • Serve as the internal and customer-facing subject matter expert on compliance frameworks (including WTCA and others). • Advise customers and internal stakeholders on best practices, compliance, and audit processes across multiple standards.
• Contribute to service engagements focused on securing AI systems and applying AI tools • Assess, develop, and modernize cybersecurity programs to enhance security posture • Perform technical analysis to identify and secure AI workloads • Perform threat modeling to evaluate the risk posed by new tools and architectures • Identify and develop use cases for automation and "agentification" of security workflows • Produce high-quality written and verbal reports, presentations, recommendations, and findings
Senior Enterprise Cloud Security Architect
GCI Communication CorpAt GCI, we foster an environment where the unique perspectives of our employees, customers, and fellow Alaskans are celebrated. We add value to our community by nurturing and empowering each member of our workforce, ensuring equal opportunities for every Trailblazer. GCI is an equal opportunity employer. Qualified applicants are considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, marital status, mental or physical disability, veteran status, or any other status or classification protected under applicable state or federal law.
GCI's Senior Enterprise Cloud Security Architect will be responsible for evaluating new solutions and developing the security controls required to incorporate new technologies in a safe and secure manner. GCI currently maintains many complex applications and your focus on security for infrastructure systems and business applications will be paramount to our success. The ideal candidate will have extensive experience in cloud-based development and security management in IaaS, PaaS, and SaaS environments. Responsible for gathering technical requirements, architecting solutions, and executing deliverables while addressing GCI policies for public and private cloud solutions. Lead and coordinate the work of an integrated project team comprised of multiple technical disciplines, including developers, subject matter experts, database administrators, system administrators, and system architects to implement and maintain enterprise-level information technology applications. Serve as an advisor to leadership concerning the planning, development, design, procurement, maintenance, and implementation of enterprise-level Cloud systems. Perform the necessary leadership, facilitation, analysis, and design tasks related to the development of Enterprise Security architectures; enabling the business to operate securely, protect its people, defend its assets, and preserve shareholder value. Responsible for the security related domains within Enterprise Architecture frameworks. Guides and approves the deployment of new security solutions while playing a key role in managing enterprise technology life cycles on a broad basis. Development and implementation of a comprehensive vision and strategy that drives “security by design.” ESSENTIAL DUTIES AND RESPONSIBILITIES AT ALL LEVELS: - Provide technical security architecture guidance and serve as an information security advisor on business applications and infrastructure supporting GCI’s corporate and external networks, including cloud. - Establish multi-cloud cybersecurity architecture with a focus on proactive threat detection, security control enforcement and incident response. - Determine security requirements by evaluating business strategies and requirements, applying security policies and security best practices. - Support the organization as subject matter expert by providing mentorship and cross-training. - Develop high-level actions plans to mitigate risk potential within individual departments and throughout the organization. - Develops strategy and roadmaps of the enterprise security portfolio. - Function as a solutions architect for the implementation of security tools within GCI. Design, integrate, and implement information systems security infrastructure. Assess potential systems and process vulnerabilities to determine security infrastructure requirements. Recommend and implement changes to enhance systems security and prevent unauthorized access. - Collaborate with enterprise and domain architects to develop cloud solutions and an Enterprise Cloud Strategy, frameworks, policies, standards, and guidance. - Champion the implementation of industry leading cloud security standards and best practices across the enterprise. - Provides advice, analysis, and recommendation on the security products in the cloud security space. - Reports to Senior and Executive Management on technical status of Enterprise Security initiatives. COMPETENCIES: - ACCOUNTABILITY- Takes ownership for actions, decisions, and results; openly accepts feedback and demonstrates a willingness to improve. - Own and manage priorities and individual tasks without direct supervision. Take initiative and seek out opportunities. Assess and accept risks and learn from mistakes. - BASIC PRINCIPLES - Interacts with people in a way that builds mutual trust, confidence, and respect; adheres to GCI’s Code of Conduct for Employees – the Basic Principles. - COLLABORATION - Works effectively with others to accomplish common goals and objectives; maintains positive relationships even under difficult circumstances. - Strong influencing, negotiation, and conflict resolution skills – able to convince and obtain commitment when dealing with business stakeholders and third-party suppliers. - Ability to interact with GCI's personnel at all levels and across all business units and organizations, and to comprehend business imperatives. - COMMUNICATION- Conveys thoughts and expresses ideas appropriately and professionally. - Excellent verbal and written communication skills and the ability to interact professionally with a diverse group of executives, managers, and subject matter experts. - Strong Consulting, Facilitation, Negotiation, and Presentation skills. - COMPLIANCE - Follows internal controls; protects confidential information; abides by GCI’s Code of Business Conduct & Ethics. - CUSTOMER FOCUS - Demonstrates commitment to service excellence; gives high priority to customer satisfaction. - RELIABILITY - Consistently follows through on assigned tasks as expected; demonstrates timely attendance at meetings, training, and other work obligations. - RESULTS - Uses a combination of job knowledge, initiative, sound decision making, innovation, adaptability, and problem solving. - Support the thought leadership of the discipline of Enterprise Security Architecture across the technology, operations, and business areas. - Clearly document findings and recommendations, to a variety of audiences - Superior analytical and problem solutions skills with the ability to apply multiple technical solutions to business problems. - Ability to quickly comprehend the functions and capabilities of new technologies. - Strong business acumen to understand enterprise strategy, desired outcomes, opportunities, and risks with the ability to ability to estimate the financial impact of technical architecture alternatives. - Lead by example on all fronts. Guide architecture, design and development teams in a manner that creates success and allows for future self-sufficiency. - SAFETY & SECURITY - Supports a safe work environment by following all workplace safety rules and guidelines; complies with applicable Security policies and procedures. Technical Competencies: - Proficient computer skills and MS Office knowledge (e.g., Outlook, Teams, Word, Excel) to complete job duties effectively. - Deep understanding of Cloud Security Architectures as they relate to Azure, AWS, and other cloud platforms. - Familiar with security solutions and risks associated with SaaS, PaaS, and IaaS cloud deployment models. - Knowledge of how to apply native cloud security and monitoring services in the cloud in concert with established security design principles. - Common regulatory controls, such as: ISO 27001, NIST 800-53, SOX, PCI, SOC 2, HIPPA, COSO and COBIT. - Experience with assessment, development, implementation, optimization, and documentation of a comprehensive and broad set of security technologies and processes, such as: Secure software development, application security, data protection, cryptography, key management, identity and access management (IAM). - Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, etc.). - Proven knowledge and hands-on experience using DevOps technologies (e.g., Jenkins, Gitlab, GitHub, Artifactory, etc.), Chef, Puppet, BOSH, or related automated/orchestration tools. - Experience working with cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies. - Experience performing threat modeling and design reviews to assess security implications and requirements for introduction of new technologies. - Experience representing technical viewpoints to diverse audiences and in making timely and prudent technical risk decisions. - Knowledge of virtualization, containers, service-mesh, and enterprise service bus. - Experience with structured Enterprise Architecture practices, hybrid cloud deployments, and on-premises-to-cloud migration deployments. - Strong foundation on TOGAF or equivalent architecture framework. Additional Job Requirements: This is a senior level Architect requiring a specific level of expertise; must be an expert in the discipline with the ability to make technical decisions independently on significant design problems. Capable of working on most complex projects to manage small to medium projects. Expected to serve as a liaison with multiple business units and teams providing technical leadership and oversight. - Participate in setting architectural direction - Advise on matters related to enterprise strategy and its development, addressing both business and departmental needs. - Support the further development and extension of Enterprise Architecture and its related documentation, templates, processes and communication. - Develop and enhance standards, principles, policies and guidelines and secure their endorsement by appropriate review bodies. Additional Competencies: - Strong project and program management skills. - Excellent troubleshooting and problem-solving skills. - Demonstrate strong organizational and time management skills. Minimum Qualifications: Required: *A combination of relevant work experience and/or education sufficient to perform the duties of the job may substitute to meet the total years required on a year-for-year basis - High School diploma or equivalent. - Bachelor’s degree in Computer Science, Engineering, Cyber Security, or related field. * - Minimum of six (6) years of progressively responsible experience with Cloud platforms such as Amazon Web Services (AWS), Azure, or VMware NSX. * Preferred: - Project Management or Telecommunication experience. - Relevant telecom industry or job specific certifications. - CCSP: Certified Cloud Security Professional - CCSK: Certificate of Cloud Security Knowledge - TOGAF 9 Enterprise Architecture Certification - AWS Certified Solutions Architect - Professional - CISM: Certified Information Systems Manager - CRISC: Certified in Risk and Information Systems Control - CISSP: Certified Information Systems Security Professional - GSLC: GIAC Security Leadership - GMON: GIAC Continuous Monitoring - SABSA Chartered Security Architect certification DRIVING REQUIREMENTS: - This position may require access to reliable transportation for occasional travel between retail store locations, offices, worksites, or other locations as needed. PHYSICAL REQUIREMENTS and WORKING CONDITIONS: - Work is primarily sedentary, requiring daily routine computer usage. - Ability to work shifts as assigned, work in standard office/home office setting, and operate standard office equipment. - Ability to accurately communicate information and ideas to others effectively. - Physical agility and effort sufficient to perform job duties safely and effectively. - Ability to make valid judgments and decisions. - Must be willing and able to work a flexible schedule, including additional time on weekends, holidays, before or after normal work hours to meet goals and deadlines. - Must work well in a team environment and be able to work with a diverse group of people and customers. - Virtual workers must comply with remote work policies and agreements. The company and its subsidiaries operate in a 24/7 environment providing critical services to Alaskans and may need to respond to public health and safety matters or other business emergencies. Due to business needs employees may be contacted outside of the core business hours to respond to an immediate emergency. As such, you will be requested to provide emergency after hours contact numbers, to include your home and cell phone numbers if you have those services. Culture, Engagement, and Connection: At GCI, we foster an environment where the unique perspectives of our employees, customers, and fellow Alaskans are celebrated. We add value to our community by nurturing and empowering each member of our workforce, ensuring equal opportunities for every Trailblazer. EEO: GCI is an equal opportunity employer. Qualified applicants are considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, marital status, mental or physical disability, veteran status, or any other status or classification protected under applicable state or federal law. DISCLAIMER: The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. All employees of GCI work in support of the GCI Mission Statement and Declaration of Principles which are located on the GCI Career page and Employee portal. Headquartered in Alaska with additional locations throughout the U.S., GCI has worked for more than 40 years to deliver communication and technology services to some of the most remote communities and in some of the most challenging conditions in North America. GCI is a pioneer in its field, bringing telemedicine and online education capabilities to communities across the state and continuing efforts to connect the Arctic globally as well as providing strong services to consumer and business markets. GCI’s introduction of 1 GIG internet speeds in the state as well as its innovative partnership with Apple are among the countless ways the company has transformed communication and quality of life for Alaskans. EEO: We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or another characteristic protected by law.
• Serve as strategic advisor and trusted partner to the CISO, providing executive support on high-priority initiatives and enterprise security strategy. • Partner with finance, procurement, and leadership teams to develop and manage annual operating budgets, resource allocation, and vendor relationships. • Coordinate and facilitate alignment across divisions, business units, and key stakeholders to ensure seamless execution of security initiatives. • Develop executive-level communications, presentations, and reporting materials for stakeholders including the Executive Leadership Team, Board, and Senior Leadership. • Lead strategic planning processes, including annual planning cycles, quarterly business reviews, and organizational assessments. • Collect, analyze, and report on security metrics, operational data, and key performance indicators to provide actionable insights for strategic decision-making. • Design, implement, and lead enterprise-wide security awareness training programs to strengthen organizational security posture. • Coordinate with partners to ensure consistency and completeness of security policies, procedures, and documentation, and drive compliance with regulatory requirements and internal standards.



