Overview
RDQ227R1175
Full job description
RDQ227R1175 While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered. About Databricks Databricks is the data and AI company. More than 12,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. About the Team The Continuous Monitoring (ConMon) team at Databricks builds and operates the engineering infrastructure that keeps Databricks' security control posture visible, measurable, and defensible at all times. We build automation that continuously assesses whether security controls are actually working across cloud environments, SaaS platforms, identity systems, and enterprise applications — surfacing drift, coverage gaps, and control failures as they happen rather than at the next audit. Our work sits at the intersection of security engineering and GRC: we turn control requirements into code, evidence collection into automation, and security posture into intelligence that drives decisions. The ConMon team also maintains security tooling and scanning infrastructure to aid control evaluation. This includes scanning for secret leaks, asset vulnerabilities, and SAST. As Databricks' security program, cloud footprint, and regulatory obligations all scale, the Continuous Monitoring team is responsible for ensuring the company's control posture is always verifiable, always current, and never a surprise. The Role Databricks is looking for a Senior Manager to lead the Continuous Monitoring team. You will own the engineering function that measures whether Databricks' security controls are working — across cloud infrastructure, identity, SaaS, and enterprise systems — and turns that measurement into something the Security organization, and its auditors, can rely on. That includes demonstrating control posture against the frameworks the business carries (SOC 2, ISO 27001, FedRAMP, PCI DSS, and emerging AI governance requirements), but the underlying question is broader: are the controls Databricks depends on actually in place and operating everywhere they are supposed to be? This is an engineering management role. The team writes production Python, operates data pipelines against cloud and SaaS APIs, and integrates with GRC and security tooling. Success is measured in control coverage, the accuracy and timeliness of what the team reports, and how quickly gaps get to the people who can close them. The role requires enough technical depth to review that work credibly, and enough judgement to prioritize the controls where measurement actually reduces risk. As the leader of Continuous Monitoring, you'll be responsible for growing and developing the team; setting a clear vision, priority, and strategy; making the case for the headcount and tooling the program needs; and building durable partnerships across GRC (SAC, SAF, Governance, Risk Management, TPRM), IT, Legal, and Engineering — the organizations that own the controls your team monitors. The Impact You Will Have Team Building & People Leadership Hire strong Security Software Engineers who bring genuine engineering skill to compliance automation. Support engineers in their career development with clear, specific feedback; develop senior ICs into technical leaders and grow the next generation of security engineering managers. Set and hold a high bar for engineering quality: code review standards, reliability and observability expectations for automation pipelines, and documentation that remains useful across audit cycles and team changes. Build a team that combines GRC domain knowledge with software engineering discipline, and hire for both. Control Measurement Program Ownership Own the strategy and roadmap for Databricks' continuous monitoring platform — control state collection at cloud scale, continuous posture assessment, security and GRC tooling integration, and remediation tracking. Define what the program measures and why: prioritize the controls whose failure would matter most to Databricks' security posture, rather than defaulting to the set a given framework happens to enumerate. Ensure coverage keeps pace with the business — new cloud environments, new products and services, new certifications and regulatory obligations, and AI governance controls that current tooling does not yet assess. Reduce manual evidence collection systematically; set and track targets for automated control coverage, freshness, and audit burden on Engineering teams. Own the accuracy of the team's output, including false positive rates; findings should be reliable enough that control owners act on them without re-verification. Posture Visibility & Executive Intelligence Own the security posture dashboards, metrics, and reporting that give Security and GRC leadership an accurate, timely view of control health across the company. Define the metrics the program reports on — control coverage, drift, time-to-remediate, and where the organization is exposed — and build the reporting that leadership uses to make security investment and prioritization decisions. Present the team's findings to senior leadership: control gaps and drift, their risk implications, and the effort required to remediate them. Make the same measurement data serve both audiences: evidence an auditor will accept, and signal the company can act on. Cross-Functional Partnership & Execution Establish productive working relationships with GRC (SAC, SAF, Governance, Risk Management, TPRM), Enterprise Security, Product Security, Security Operations, IT, Legal, and Engineering leadership — the teams who own the controls, the evidence, and the remediation. Partner with Enterprise Security and Product Security so control measurement reflects how systems are actually built and configured, and feed coverage gaps back to the teams who own those controls. Partner with SAC and SAF to ensure monitoring output meets auditor and 3PAO evidence standards, and with Governance to keep control monitoring aligned to policy as standards evolve. Coordinate with Risk Management and Security Operations on metric definitions and reporting boundaries so the organization gets one coherent picture of control health rather than three overlapping ones. Coordinate execution across teams to unblock cross-cutting initiatives: telemetry gaps in Engineering-owned systems, GRC platform migrations, and multi-quarter automation programs. Make effective priority and resourcing decisions within the team; be accountable for defining and achieving the team's OKRs and KPIs. Technology Decisions Lead build-vs.-buy evaluations for CSPM, SSPM, GRC automation, and security posture tooling; assess platforms on integration capability, measurement fidelity, maintenance cost, and fit with existing pipelines, and make the recommendation to Security and GRC leadership. Keep the program's operating costs defensible — cloud spend, tooling, and the engineering time monitoring consumes — and be able to explain the tradeoff between monitoring coverage and what it costs to run at scale. Track what the program will need to measure next — changes in Databricks' architecture and threat exposure, new SOC 2 criteria, FedRAMP continuous monitoring changes, and AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) — and translate them into roadmap decisions early enough to build for them. What We Look For 2+ years of prior management experience leading Engineering or Security engineering teams. Typically 12+ years of experience, or an advanced degree plus 8 years, preferably focused on security engineering, security posture monitoring, or compliance automation. Sufficient technical depth to review the work of the team: can read and critique Python automation, evaluate an integration architecture, and assess whether a monitoring approach will hold up in production. Solid understanding of security controls and where they fail in practice — identity and access, configuration management, logging coverage, vulnerability management, and data protection — enough to judge whether a given measurement is telling you anything useful. Solid cloud security knowledge across at least one major platform (AWS, Azure, GCP) — IAM, audit logging, CSPM concepts, and cloud-native security services. Working knowledge of compliance frameworks (SOC 2, ISO 27001, FedRAMP, or equivalent) at a level sufficient to assess whether a control monitoring design will satisfy an auditor. Previous experience building security posture monitoring or compliance automation at scale, with attention to accuracy, coverage, and cost tradeoffs (experience with Databricks is preferred). Focused on defining and driving efficiencies and improvements within the team; accountable for defining and achieving targets (e.g. OKRs, KPIs). Makes effective priority decisions on resourcing and alignment within the team. Strong communicator across technical, GRC, and executive audiences — can explain automation architecture to auditors and compliance requirements to engineers. Nice to Have Experience with cloud security posture management (CSPM/SSPM) platforms at an architecture level. Experience with FedRAMP continuous monitoring programs at a leadership level. Hands-on background with GRC automation platforms (Vanta, Drata, ServiceNow GRC, Archer, or equivalent) at an implementation or architecture level. Experience building automated monitoring for AI system controls and AI governance frameworks. Track record of building or scaling a security measurement or compliance engineering function from early-stage to mature operations. Background in security operations, detection engineering, or security architecture that informs which controls are worth measuring. Experience with front-end development. CISSP, CISM, CISA, or equivalent certifications. Pay Range Transparency Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here . Zone 1 Pay Range $228,600 — $314,250 USD Zone 2 Pay Range $205,700 — $282,800 USD Zone 3 Pay Range $194,200 — $267,100 USD Zone 4 Pay Range $182,900 — $251,450 USD About Databricks Databricks is the Data and AI company. More than 20,000 organizations worldwide — including adidas, AT&T, Bayer, Block, Mastercard, Rivian, Unilever, and 70% of the Fortune 500 — rely on the Databricks Data + AI Platform to build and scale data and AI apps, analytics and agents. Headquartered in San Francisco with 30+ offices around the globe, Databricks offers a unified platform that includes Genie, Lakebase, Agent Bricks, Lakeflow, Lakehouse, and Unity Catalog. To learn more, follow Databricks on LinkedIn , X , YouTube , and Instagram . Benefits At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here . Our Commitment to Diversity and Inclusion At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics. Compliance If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Databricks (greenhouse) ↗Browse current Job and Scholarship listings from Databricks (greenhouse) →