Staff Product Security Engineer
Staff Security Software Engineer leading architecture, standards, and development of AI security tooling, threat detection, and red-teaming platforms at Databricks. Requires 7-10 years security engineering experience, expert Python skills, and deep AI/ML security expertise.
About the job
AI Security Engineering Architecture
- Define the architecture and technical strategy for Databricks' AI security tooling platform spanning adversarial testing, behavioral monitoring, threat detection, and automated assessment of AI components.
- Set engineering standards for the team including design review processes, reliability requirements, observability practices, security properties of the tooling, and integration patterns.
- Own technical decisions on scaling systems to cover growing AI surface, integration with product security and detection pipelines, and build vs. buy vs. open-source choices.
AI Threat Detection at Scale
- Lead design and development of AI platform capabilities at production scale including behavioral analysis, detection of prompt injection, and anomaly detection on agentic workflows.
- Define methodology for AI security assessment: systematic evaluation of new AI capabilities against threat models before deployment and continuous monitoring after.
- Drive technical strategy for AI red-teaming tooling: automated adversarial testing platforms simulating real attacker abuse of AI systems.
Cross-Organizational Technical Leadership
- Serve as technical authority on AI security engineering for Product Security, SITH, IR, and ConMon teams, ensuring tooling integrates into their workflows.
- Represent AI Security Engineering in architecture reviews, platform security decisions, and cross-team discussions.
- Establish AI security engineering standards and reusable patterns for teams building AI-connected systems.
Mentorship & Team Capability
- Mentor senior and mid-level engineers on AI security engineering architecture, adversarial threat modeling, and technical leadership.
- Lead design reviews, define team engineering practices, and drive continuous improvement in quality and reliability of AI security tooling.
Requirements
- 7–10 years of experience in security software engineering, security engineering, or closely related discipline with demonstrated technical leadership of security tooling programs and organizational-level impact.
- Expert Python engineering: designs and delivers production systems at scale; understands observability, reliability engineering, and integration into security operations.
- Deep expertise in AI/ML security including adversarial ML, prompt injection, model security, agentic framework trust boundaries at both research-informed and engineering-practical levels.
- Experience designing security tooling architectures that span multiple teams and systems, defining platform structure, scale, and maintenance.
- Strong technical communicator able to align engineering and security leadership on architectural direction and drive cross-team adoption.
- Track record of shipping high-quality security tooling that other teams depend on in production.
Nice to Have
- Research contributions or deep familiarity with adversarial ML, AI safety, or AI red-teaming methodology.
- Experience with MLOps platforms, AI serving infrastructure, or AI platform security at cloud scale.
- Familiarity with AI governance standards (NIST AI RMF, ISO/IEC 42001, EU AI Act technical provisions) as they apply to security engineering.
- Open-source contributions or publications in AI security, adversarial ML, or security tooling.
Skills
Python, Ai/Ml Security, Adversarial Ml, Prompt Injection, Model Security, Threat Modeling, Threat Detection, Anomaly Detection, MLOps, Observability, Reliability Engineering, Security Tooling, Ai Red Teaming
Similar jobs
Security Engineering jobsStaff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.