Databricks is a leading data and AI company that empowers organizations worldwide to unify data, analytics, and AI. They are seeking an L5 Enterprise Security Engineer to enhance security coverage across enterprise applications and integrations, focusing on risk identification and secure design. The role involves collaboration with various stakeholders to ensure security practices are embedded in technology and workflows.
Responsibilities:
- Strengthen security practices across enterprise application and integration reviews by identifying key risks early, improving requirement quality, and helping teams address security issues earlier in the lifecycle
- Strengthen Enterprise Security’s capability to assess and guide AI-adjacent security, MCP and integration security, and cross-system data flow risk, while improving the consistency and scale of security reviews
Requirements:
- 7+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field
- Experience conducting security design or architecture reviews for enterprise applications, SaaS platforms, integrations, or internally developed systems
- Strong understanding of authentication, authorization, SSO, federation, SCIM, API security, token handling, secrets management, and least privilege design
- Experience assessing data flows, third-party integrations, trust boundaries, logging and monitoring, and security controls across interconnected systems
- Ability to evaluate risk in modern enterprise environments, including automation platforms, AI-adjacent workflows, and emerging integration patterns such as MCP
- Strong written and verbal communication skills, including the ability to translate technical risk into clear requirements and actionable guidance
- Experience driving security outcomes through engineering judgment, influence, and scalable process improvement
- Familiarity with cloud platforms, enterprise identity systems, and core control domains such as audit logging, encryption, access control, data retention, and incident response