Sr. Manager, Security — Continuous Monitoring v 2.0
Job Description
RDQ227R1175
While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered.
About Databricks
Databricks is the data and AI company. More than 12,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI.
Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow.
About the Team
The Continuous Monitoring (ConMon) team at Databricks builds and operates the engineering infrastructure that keeps Databricks' security control posture visible, measurable, and defensible at all times.
We build automation that continuously assesses whether security controls are actually working across cloud environments, SaaS platforms, identity systems, and enterprise applications — surfacing drift, coverage gaps, and control failures as they happen rather than at the next audit.
Our work sits at the intersection of security engineering and GRC: we turn control requirements into code, evidence collection into automation, and security posture into intelligence that drives decisions.
The ConMon team also maintains security tooling and scanning infrastructure to aid control evaluation. This includes scanning for secret leaks, asset vulnerabilities, and SAST.
As Databricks' security program, cloud footprint, and regulatory obligations all scale, the Continuous Monitoring team is responsible for ensuring the company's control posture is always verifiable, always current, and never a surprise.
The Role
Databricks is looking for a Senior Manager to lead the Continuous Monitoring team.
You will own the engineering function that measures whether Databricks' security controls are working — across cloud infrastructure, identity, SaaS, and enterprise systems — and turns that measurement into something the Security organization, and its auditors, can rely on.
That includes demonstrating control posture against the frameworks the business carries (SOC 2, ISO 27001, FedRAMP, PCI DSS, and emerging AI governance requirements), but the underlying question is broader: are the controls Databricks depends on actually in place and operating everywhere they are supposed to be?
This is an engineering management role. The team writes production Python, operates data pipelines against cloud and SaaS APIs, and integrates with GRC and security tooling. Success is measured in control coverage, the accuracy and timeliness of what the team reports, and how quickly gaps get to the people who can close them.
The role requires enough technical depth to review that work credibly, and enough judgement to prioritize the controls where measurement actually reduces risk.
As the leader of Continuous Monitoring, you'll be responsible for growing and developing the team; setting a clear vision, priority, and strategy; making the case for the headcount and tooling the program needs; and building durable partnerships across GRC (SAC, SAF, Governance, Risk Management, TPRM), IT, Legal, and Engineering — the organizations that own the controls your team monitors.
The Impact You Will Have
Team Building & People Leadership
- Hire strong Security Software Engineers who bring genuine engineering skill to compliance automation.
- Support engineers in their career development with clear, specific feedback; develop senior ICs into technical leaders and grow the next generation of security engineering managers.
- Set and hold a high bar for engineering quality: code review standards, reliability and observability expectations for automation pipelines, and documentation that remains useful across audit cycles and team changes.
- Build a team that combines GRC domain knowledge with software engineering discipline, and hire for both.
RDQ227R1175
While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered.
About Databricks
Databricks is the data and AI company. More than 12,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI.
Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow.
About the Team
The Continuous Monitoring (ConMon) team at Databricks builds and operates the engineering infrastructure that keeps Databricks' security control posture visible, measurable, and defensible at all times.
We build automation that continuously assesses whether security controls are actually working across cloud environments, SaaS platforms, identity systems, and enterprise applications — surfacing drift, coverage gaps, and control failures as they happen rather than at the next audit.
Our work sits at the intersection of security engineering and GRC: we turn control requirements into code, evidence collection into automation, and security posture into intelligence that drives decisions.
The ConMon team also maintains security tooling and scanning infrastructure to aid control evaluation. This includes scanning for secret leaks, asset vulnerabilities, and SAST.
As Databricks' security program, cloud footprint, and regulatory obligations all scale, the Continuous Monitoring team is responsible for ensuring the company's control posture is always verifiable, always current, and never a surprise.
The Role
Databricks is looking for a Senior Manager to lead the Continuous Monitoring team.
You will own the engineering function that measures whether Databricks' security controls are working — across cloud infrastructure, identity, SaaS, and enterprise systems — and turns that measurement into something the Security organization, and its auditors, can rely on.
That includes demonstrating control posture against the frameworks the business carries (SOC 2, ISO 27001, FedRAMP, PCI DSS, and emerging AI governance requirements), but the underlying question is broader: are the controls Databricks depends on actually in place and operating everywhere they are supposed to be?
This is an engineering management role. The team writes production Python, operates data pipelines against cloud and SaaS APIs, and integrates with GRC and security tooling. Success is measured in control coverage, the accuracy and timeliness of what the team reports, and how quickly gaps get to the people who can close them.
The role requires enough technical depth to review that work credibly, and enough judgement to prioritize the controls where measurement actually reduces risk.
As the leader of Continuous Monitoring, you'll be responsible for growing and developing the team; setting a clear vision, priority, and strategy; making the case for the headcount and tooling the program needs; and building durable partnerships across GRC (SAC, SAF, Governance, Risk Management, TPRM), IT, Legal, and Engineering — the organizations that own the controls your team monitors.
The Impact You Will Have
Team Building & People Leadership
- Hire strong Security Software Engineers who bring genuine engineering skill to compliance automation.
- Support engineers in their career development with clear, specific feedback; develop senior ICs into technical leaders and grow the next generation of security engineering managers.
- Set and hold a high bar for engineering quality: code review standards, reliability and observability expectations for automation pipelines, and documentation that remains useful across audit cycles and team changes.
- Build a team that combines GRC domain knowledge with software engineering discipline, and hire for both.
Control Measurement Program Ownership
- Own the strategy and roadmap for Databricks' continuous monitoring platform — control state collection at cloud scale, continuous posture assessment, security and GRC tooling integration, and remediation tracking.
- Define what the program measures and why: prioritize the controls whose failure would matter most to Databricks' security posture, rather than defaulting to the set a given framework happens to enumerate.
- Ensure coverage keeps pace with the business — new cloud environments, new products and services, new certifications and regulatory obligations, and AI governance controls that current tooling does not yet assess.
- Reduce manual evidence collection systematically; set and track targets for automated control coverage, freshness, and audit burden on Engineering teams.
- Own the accuracy of the team's output, including false positive rates; findings should be reliable enough that control owners act on them without re-verification.
Posture Visibility & Executive Intelligence
- Own the security posture dashboards, metrics, and reporting that give Security and GRC leadership an accurate, timely view of control health across the company.
- Define the metrics the program reports on — control coverage, drift, time-to-remediate, and where the organization is exposed — and build the reporting that leadership uses to make security investment and prioritization decisions.
- Present the team's findings to senior leadership: control gaps and drift, their risk implications, and the effort required to remediate them.
- Make the same measurement data serve both audiences: evidence an auditor will accept, and signal the company can act on.
Cross-Functional Partnership & Execution
- Establish productive working relationships with GRC (SAC, SAF, Governance, Risk Management, TPRM), Enterprise Security, Product Security, Security Operations, IT, Legal, and Engineering leadership — the teams who own the controls, the evidence, and the remediation.
- Partner ...