Senior Platform Engineer- Snowflake (Azure / Entra ID)

Summary

Senior Snowflake platform owner operating a multi-account, HIPAA-regulated environment on Azure—designing custom RBAC, Entra ID SSO/SCIM, OAuth, and Private Link connectivity, and shipping Python (Snowpark) and JavaScript automation with Terraform/Azure DevOps CI/CD.

You will own and operate our multi-account Snowflake platform as the primary technical authority on its security, access architecture, account administration, and Azure integration. This is a platform ownership role, not a data engineering role with administration attached, and not an architecture role that directs other people to implement. You will be the person in the console, in the Terraform, and in the incident.

You will operate across multiple Snowflake accounts, enforce governance at scale in a HIPAA-regulated environment, and set the technical bar for every team that depends on the platform. You write Python fluently, you use AI tooling as a normal part of how you work, and you do not wait to be told what to fix.

FIRST 90 DAYS

  • Days 1-30: inherit the account inventory, RBAC model, resource monitors, and credential estate. Produce a written gap assessment of access risk and cost exposure.
  • Days 31-60: close the top three access findings yourself. Take ownership of the Terraform modules and the Azure DevOps pipelines for schema migration.
  • Days 61-90: own the credential rotation calendar, the network policy baseline, and the cost governance reporting line to engineering leadership.

WHAT YOU WILL OWN

Snowflake platform

  • Multi-account administration: account configuration, organizational hierarchy, resource monitors, replication and failover, cross-account data sharing.
  • Access architecture: multi-tier custom RBAC, grant hierarchies, functional versus access role separation, enforcement and drift detection across accounts.
  • Identity and credentials: SAML federation and SCIM through Entra ID, OAuth security integrations with BLOCKED_ROLES_LIST and token policy, key-pair auth with scheduled rotation into Azure Key Vault, user lifecycle including TYPE classification and service-account naming.
  • Network and connectivity: account and user level network policies, Private Link endpoints, coordination with network and security teams.
  • Cost governance: warehouse sizing, autoscaling policy, resource monitor alerting, credit burn analysis and reporting.

Automation and delivery

  • Python automation with snowflake-connector-python and Snowpark; Terraform modules for warehouses, databases, roles, and integrations.
  • Azure DevOps pipelines for schema migration, dbt promotion, and environment-to-environment deployment.
  • Azure integration: ADLS Gen2 storage integrations and external stages, Key Vault, Data Factory, Azure Monitor. Maintenance and migration of existing JavaScript stored procedures, with new work in Python and SQL.

Governance, operations, and leadership

  • Audit logging, object tagging, access history analysis, data classification, and lifecycle policy in a HIPAA-regulated environment.
  • dbt workflow support, MageAI or equivalent orchestration operations, and Snowflake vendor escalation and release monitoring.
  • Daily use of AI tooling such as GitHub Copilot, Claude, or Cursor is expected rather than optional. Governed adoption of Snowflake Cortex AI with cost controls in place.
  • Set the bar through code review, pairing, runbooks, and architecture documentation. Own platform standards and drive adoption across data, analytics, and application engineering without formal authority.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available