[All remote jobs](https://jobicy.com/jobs.md)[![Databricks logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/12/4e3f864ba9cf3c62d471e1c62414d098.jpg)](https://jobicy.com/company/databricks.md)[Databricks](https://jobicy.com/company/databricks.md)

# Staff Security Engineer, Incident Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/databricks.md)ShareRemote from[UK](https://jobicy.com/job-region/uk.md), [Spain](https://jobicy.com/job-region/spain.md), [Germany](https://jobicy.com/job-region/germany.md)+8 more, [France](https://jobicy.com/job-region/france.md), [Netherlands](https://jobicy.com/job-region/netherlands.md), [Italy](https://jobicy.com/job-region/italy.md), [Sweden](https://jobicy.com/job-region/sweden.md), [Finland](https://jobicy.com/job-region/finland.md), [Switzerland](https://jobicy.com/job-region/switzerland.md), [Belgium](https://jobicy.com/job-region/belgium.md), [Denmark](https://jobicy.com/job-region/denmark.md)SalaryUndisclosedDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished11 Oct 2026Apply before10 Nov 2026Listing views43Application actions4Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

Databricks is seeking a senior individual contributor to investigate, contain, and remediate security incidents across its enterprise and cloud environment. The role participates in a distributed 24x7 on-call operation and performs alert triage, digital forensics, timeline analysis, and impact assessment. The engineer will also build incident-response tooling and AI-enabled or agentic automation to improve the scale and speed of the IR function. Candidates need substantial incident response experience, multi-cloud security knowledge, SIEM/SOAR familiarity, scripting ability, and strong technical leadership and communication skills.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a staff-level incident response role requiring deep DFIR expertise, broad cloud-security capability, and the ability to lead technical direction during high-priority incidents. The 24x7 on-call model, cross-functional influence, and expectation to create AI-enabled automation make the role highly demanding.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$220,000US market range$180k–$260k0$286k

AI insightNo actual salary, pay range, or other candidate compensation is disclosed in the posting. These figures are estimated USD yearly US-market base-salary benchmarks for a Staff Security Engineer specializing in incident response; actual pay may vary by location, level calibration, bonus, and equity.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Digital Forensics](https://jobicy.com/jobs?search_keywords=Digital%20Forensics.md)[DFIR](https://jobicy.com/jobs?search_keywords=DFIR.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[AWS](https://jobicy.com/jobs?search_keywords=AWS.md)[GCP](https://jobicy.com/jobs?search_keywords=GCP.md)[Azure](https://jobicy.com/jobs?search_keywords=Azure.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[SOAR](https://jobicy.com/jobs?search_keywords=SOAR.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)

Sample interview questionsDescribe how you would investigate a suspected cloud account compromise.I would first validate the alert and scope the affected identity, accounts, resources, and time window. I would preserve relevant audit logs, review authentication and API activity, identify privilege changes and data-access events, contain the account through credential revocation or session controls, and document a timeline, impact assessment, and remediation plan.

How have you used automation to improve an incident response process?

I identify repetitive, high-confidence actions such as enrichment, indicator correlation, evidence collection, and ticket creation. I build tested workflows with clear approval gates for destructive actions, measure time-to-triage and false-positive rates, and continuously refine the automation based on responder feedback and post-incident reviews.

What is your approach to conducting forensics across multiple data sources?

I normalize timestamps, establish reliable sources of truth, and correlate endpoint, identity, cloud-control-plane, network, and application telemetry. I maintain evidence integrity, form and test hypotheses against the data, and produce an auditable timeline that distinguishes verified facts from assumptions.

How would you evaluate an AI or agentic system proposed for security operations?

I would assess the system’s data access, permissions, prompt-injection resilience, output reliability, auditability, and failure modes. I would begin with low-risk assistive use cases, require human review for consequential actions, evaluate quality against representative incident data, and implement monitoring and rollback controls.

How do you provide technical leadership as an individual contributor during incidents?

I create clarity around ownership, priorities, evidence, and decision points while remaining hands-on with investigation work. I communicate concise updates to technical and business stakeholders, guide containment choices using risk-based tradeoffs, and turn lessons learned into durable improvements through tooling, documentation, and mentoring.

Opportunity details

## About this role.

RDQ327R180

Staff Security Engineer, Incident Response

The Incident Response team’s mission is to respond to security threats, incidents and investigations to protect our customers, employees and enterprise data in a fast, efficient and standardised manner. We’re a tight-knit team of security incident responders and incident handlers doing “Security for Databricks on Databricks”, using our own platform to create near-real-time log analytics, alerting and forensics.

You will be an individual contributor on the security Incident Response (IR) team at Databricks, reporting to the regional IR manager. You will be responsible for conducting security analysis and forensics, responding to high-priority alerts and contributing to automations and agentic capabilities. You will be a security multiplier and help the team scale security incident response at Databricks.

The impact you will have:

* You will respond to incidents as part of a distributed 24×7 operations and on-call schedule.
* You will triage and respond to security events and alerts, ensuring quick and effective containment.
* You will conduct analysis and forensics across a range of data sources to determine the timeline and impact of security events.
* You will provide technical leadership and influence team direction.
* You will develop solutions, including leveraging AI and agentic platforms, to deliver autonomous capabilities, expedite your work and scale the impact of the team.
* You will communicate technical decisions through design docs and tech talks, and mentor junior security responders via security guidance, design reviews and code reviews.

What we look for:

* Bachelor’s Degree AND 7+ years experience in Incident Response work OR Master’s Degree AND 5+ years experience.
* Cloud security expertise in at least 1 of AWS, GCP or Azure, and proficiency in the others.
* Proficiency in AI/LLM and agentic capabilities. Prefer experience with building and operating agentic systems in a security setting.
* Broad security subject matter expertise.
* Expertise in a few core IR skills (DFIR , Reverse Engineering, Traditional Network Security, Storage and access security, Sandboxing, Compute security, etc.).
* Experience with Enterprise Security and SaaS applications.
* Working knowledge of a SIEM and SOAR.
* Experience building Incident Response Tooling, scripting language skills and experience with AI coding tools.

About Databricks

Databricks is the Data and AI company. More than 20,000 organizations worldwide — including adidas, AT&T, Bayer, Block, Mastercard, Rivian, Unilever, and 70% of the Fortune 500 — rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics and agents. Headquartered in San Francisco with 30+ offices around the globe, Databricks offers a unified platform that includes Genie, Lakebase, Agent Bricks, Lakeflow, Lakehouse, and Unity Catalog. To learn more, follow Databricks on [LinkedIn](https://www.linkedin.com/company/databricks), [X](https://x.com/databricks), [YouTube](https://www.youtube.com/@Databricks), and [Instagram](https://www.instagram.com/databricksinc/?hl=en).

Benefits

At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click [here](https://docs.google.com/document/d/154un3e8Xav4BceOSlcYFZRGEuQI54xMxVydRwQn54eQ/edit?usp=sharing).

Our Commitment to Diversity and Inclusion

At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

Compliance

If access to export-controlled technology or source code is required for performance of job duties, it is within Employer’s discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

Show more

[Apply now >](https://jobicy.com/jobs/155021-staff-security-engineer-incident-response.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs Oct 11  New

### [Senior / Staff Intelligence Analyst, Environmental Crimes](https://jobicy.com/jobs/155032-senior-staff-intelligence-analyst-environmental-crimes.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![Resilience logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/e67f0de9-221.png)
Resilience Oct 11  New

### [Tabletop Exercise (TTX) Specialist – Cybersecurity Focus](https://jobicy.com/jobs/154999-tabletop-exercise-ttx-specialist-cybersecurity-focus.md)

About Us At Resilience, we’re creating a new category that integrates cybersecurity, cyber insurance, and cyber risk management. Founded in 2016 by experts from across the highest tiers of the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 11  New

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 11  New

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 11  New

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 11  New

### [Blockchain Security Expert – Anti Defect Track](https://jobicy.com/jobs/152966-blockchain-security-expert-anti-defect-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia Oct 11  New

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel Oct 10  New

### [Security Engineer, Cloud](https://jobicy.com/jobs/152929-security-engineer-cloud.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius Oct 10  New

### [Detection Engineering & Response Lead](https://jobicy.com/jobs/148918-detection-engineering-response-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Tremendous logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/01/c2bd8be5-221.jpeg)
Tremendous Oct 10  New

### [Head of Security](https://jobicy.com/jobs/152862-head-of-security.md)

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We’re trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and…

[Browse all jobs](https://jobicy.com/jobs.md)