Remote
Sr. Manager, Security — Continuous Monitoring v 2.0
About this role
RDQ227R1175 While candidates in the listed location(s) are encouraged for this role, candidates in other locations will be considered. About Databricks Databricks is the data and AI company. More than 12,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow.
About the Team The Continuous Monitoring (ConMon) team at Databricks builds and operates the engineering infrastructure that keeps Databricks' security control posture visible, measurable, and defensible at all times. We build automation that continuously assesses whether security controls are actually working across cloud environments, SaaS platforms, identity systems, and enterprise applications — surfacing drift, coverage gaps, and control failures as they happen rather than at the next audit.
Our work sits at the intersection of security engineering and GRC: we turn control requirements into code, evidence collection into automation, and security posture into intelligence that drives decisions. The ConMon team also maintains security tooling and scanning infrastructure to aid control evaluation. This includes scanning for secret leaks, asset vulnerabilities, and SAST. As Databricks' security program, cloud footprint, and regulatory obligations all scale, the Continuous Monitoring team is responsible for ensuring the company's control posture is always verifiable, always current, and never a surprise.
The Role Databricks is looking for a Senior Manager to lead the Continuous Monitoring team. You will own the engineering function that measures whether Databricks' security controls are working — across cloud infrastructure, identity, SaaS, and enterprise systems — and turns that measurement into something the Security organization, and its auditors, can rely on. That includes demonstrating control posture against the frameworks the business carries (SOC 2, ISO 27001, FedRAMP, PCI DSS, and emerging AI governance requirements), but the underlying question is broader: are the controls Databricks depends on actually in place and operating everywhere they are supposed to be? This is an engineering management role.