Staff Security Software Engineer, AI Security
Навыки
- AI-агенты
- AI-инструменты в работе
- API (интеграции)
- AWS
- Azure
- CI/CD
- Data Governance
Ещё 16
- Data Lake
- Дообучение моделей
- Google Cloud
- Java
- Лидерство
- LLM
- Machine Learning
- MLOps
- OWASP
- Пентест
- Python
- RAG
- Rust
- Scala
- SOLID и паттерны
- Iceberg / Delta Lake
О компании и продукте
- The AI Security team at Databricks sits at the frontier of securing the AI/ML services in the Databricks platform. As we ship AI capabilities at the leading edge of the industry, including Agent Bricks, the Genie suite, AI Model Serving, MLflow, and Unity AI Gateway, the AI Security team ensures these systems are designed, built, and operated securely. Our work also extends to securing our own usage of AI: building the right guardrails that enable Databricks employees to innovate and deliver securely.
- The team combines offensive security depth with AI/ML engineering knowledge to identify novel threats, build scalable defenses, and influence how AI products are architected from the ground up. We lead AI Red Team exercises, build security tooling for AI workloads, and partner directly with AI Product teams to embed security into the development lifecycle.
- As a Staff Security Software Engineer on the AI Security team, you are a senior technical leader who sets the standards for how Databricks secures its AI and ML capabilities. You combine deep offensive security expertise with practical knowledge of AI/ML systems to identify and drive resolution of the most significant security risks in Databricks' AI platform.
Задачи
- AI Red Team & Adversarial Testing
- Lead AI red team engagements against Databricks' production AI systems, including Foundation Model APIs, Genie and natural language query systems, Model Serving infrastructure, MCP-connected agents, and RAG pipelines
- Design and execute adversarial attack scenarios: prompt injection, jailbreaking, memory poisoning, cross-tenant data leakage in multi-tenant serving, and sandbox bypasses
- Develop proof-of-concept exploits for AI-specific vulnerability classes and perform variant analysis to identify the full scope of exposure across the AI platform
- Contribute to the evolution of the Databricks AI Security Framework (DASF), maintaining and extending the risk taxonomy, control library, and testing methodology as AI capabilities evolve
- AI Product Security & Architecture Reviews
- Lead comprehensive security architecture reviews for complex AI features: threat modeling agentic workflows, RAG pipelines, multi-model serving chains, and MCP-based tool integrations
- Partner directly with AI and ML engineering teams to identify security risks early in the design process and define practical, scalable controls
- Assess and drive resolution of cross-cutting AI security risks: Unity Catalog permission enforcement in AI contexts, inference data isolation, model artifact integrity, fine-tuning pipeline security, and external model API governance via AI Gateway
- Identify recurring security patterns across AI features
- advocate for class-level architectural fixes rather than feature-by-feature point solutions
- AI Security Tooling & Automation
- Design and build automated AI security testing tooling, including adversarial prompt libraries, agent behavior analysis frameworks, and continuous testing harnesses
- Build AI-assisted automation that scales security reviews, threat modeling, and vulnerability triage for AI features
- Develop and maintain security guardrails and enforcement mechanisms: LLM-as-judge review, prompt delimiting, output validation, rate limiting, and audit logging
- Cross-Team Remediation & Standards
- Set technical standards for how AI security risks are assessed, prioritized, and remediated across the engineering organization
- Drive cross-team remediation for significant AI security findings, defining fix requirements, validating patches, and ensuring regression coverage in CI/CD pipelines
- Produce high-quality threat models, security advisories, and post-mortems that inform organizational risk decisions for AI products
- Mentorship & Community
- Mentor engineers on the AI Security team in adversarial ML techniques, AI threat modeling, and security tooling development
- Contribute to internal knowledge assets, including training materials, design patterns, and threat model templates, that raise AI security fluency across the engineering organization
- Represent Databricks in the external AI security community through publications, conference talks, or open-source contributions
Требования
- 7–10 years of combined experience in offensive security, AI/ML security research, or product security engineering, with demonstrated leadership in securing complex systems
- Subject matter expert in at least two of the following AI security domains
- LLM and generative AI security (prompt injection, jailbreaking, training data extraction)
- AI agent and orchestration security (MCP, memory sharing, multi-agent systems)
- ML infrastructure and serving security (model serving multi-tenancy risks, training infrastructure security)
- AI data governance and privacy (fine-grained access control, data residency, inference data isolation)
- Demonstrated ability to design and execute adversarial attacks against production AI systems
- Deep understanding of AI/ML platform architecture- how models are trained, served, and integrated, and where the trust boundaries between components lie
- Expert in at least one major cloud platform (AWS, Azure, GCP) and its AI/ML security model
- Proficient in Python
- able to read and analyze ML model code, training scripts, and API serving code
- working knowledge of at least one additional language (Go, Java, Scala, Rust)
- Track record of driving cross-team AI security improvements and influencing product architecture decisions
- Experience building automated security tooling for AI systems
- Strong communicator- translates AI security risks into actionable guidance for engineers, product managers, and leadership
- Pragmatic approach to risk- distinguishes real-world exploitable AI risk from theoretical concerns
Будет плюсом
- Published research on AI/ML security topics or experience presenting at AI security venues (DEF CON AI Village, NeurIPS workshops, Black Hat)
- Experience with OWASP Top 10 for LLMs, MITRE ATLAS, or similar AI security frameworks
- Familiarity with MLflow, Unity Catalog, Delta Lake, or Databricks platform internals
- OSCP or equivalent offensive security certification
- Academic or research background in machine learning, adversarial ML, or AI safety
- Why Databricks
- On the AI Security team, you'll work on a class of security problem that didn't exist five years ago, and that the industry is still figuring out
- You'll run red team engagements against a live AI platform used by over 12,000 organizations, build tooling that has no precedent to copy, and drive security decisions that shape how AI products are built across the company
- The problems are novel, the stakes are real, and the team working on them is exceptional
Условия
- At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees
Паспорт вакансии
История публикации
Появилась в Вакандии29 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 29 дней назад
Среди похожихНет данных148 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего
Откуда что взялось
Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.
ГрейдLeadвычитано из текста вакансии
Формат работыУдалённо
ГеографияСШАвычитано из текста вакансии
Зарплата≈ 19 772 USD в месяцнаша оценка, в вакансии не названа
Почему на этом месте в выдаче
Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.
Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка
Проверка Вакандии
Источники и свежесть
- Тип источника
- Карьерный сайт работодателя
- Найдено публикаций
- 1
Посмотреть публикации и даты
- greenhouseОсновная публикация · 2025-09-09
Работодатель
Databricks
50 активных вакансий · вилка работодателя указана в 21%
Открыть профиль компанииБезопасность
Отклик уходит на сайт источника
Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайте — databricks.com.
Признаки мошенничества
- Просят предоплату, «залог» или деньги за обучение и оборудование.
- Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
- Быстро уводят в мессенджер и торопят с решением.
- Обещают большой доход без опыта и без деталей задач.
Настоящий работодатель не просит денег и платёжных данных до трудоустройства.
Продолжить поиск
Похожие вакансии
Причина сходства указана на каждой карточке
Подробнее Подробнее - Подробнее
Почему похожа: похожая специализация
Fabrique — Python-разработчик (Django, DRF)
- Junior
- Удалённо из России
- Москва, Россия