Senior Platform Engineer- Snowflake (Azure / Entra ID)

Open 21d

We are seeking a Senior Snowflake Subject Matter Expert and Azure-native Platform Engineer to own and operate our multi-account Snowflake environment in a HIPAA-regulated setting. This is a hands-on platform ownership role, not data engineering with administrative responsibilities on the side. You will serve as the primary authority on Snowflake security, identity and access architecture, account administration, and Azure integration, and as the senior technical voice setting platform standards and direction. You write Python and JavaScript as core deliverables, leverage AI tooling as an embedded part of your engineering workflow, operate with a high degree of ownership, and identifying and resolving issues without waiting for direction.

Before You Apply, Non-Negotiables:

This is a senior, hands-on platform operator role. You must demonstrate, with specifics and examples, all of the following:

  • 7+ years hands-on Snowflake administration in production; administration, not data engineering with some admin on the side.
  • Multiple Snowflake accounts under an organizational hierarchy, not multiple databases inside one account.
  • Custom RBAC role hierarchies designed from scratch; functional vs. access roles, privilege grant design, not assigning built-in roles.
  • Snowflake SSO via Azure AD/Entra ID configured end-to-end — IdP setup and attribute mapping, not using SSO as an end user.
  • OAuth security integrations including BLOCKED_ROLES_LIST and token policy management.
  • Key pair authentication implemented and rotated for service accounts, with private keys stored in a vault.
  • Python and JavaScript as core deliverables, snowflake-connector-python / Snowpark automation and Snowflake JS stored procedures. Both are evaluated.
  • Daily, describable use of AI tooling in your engineering workflow. “I use ChatGPT sometimes” is not sufficient.
  • Own cost governance and resource controls at scale, warehouse sizing, auto-suspend/resume, and credit usage management across multiple accounts.
  • Private connectivity (e.g., Azure Private Link) implemented and operated, not public endpoint-only environments.
  • Infrastructure as code and deployment pipelines, Terraform modules and CI/CD for Snowflake and database changes (not manual administration).

Responsibilities:

  • Administer multiple Snowflake accounts: account-level configuration, org hierarchy, resource monitors, cross-account sharing/replication/failover, and cost governance (warehouse sizing, autoscaling, credit burn).
  • Design and enforce multi-tier RBAC, network policies (IP allowlisting at account and user level), and data governance (audit logging, object tagging, access history, classification, lifecycle).
  • Own identity and access end-to-end: SSO/SAML via Entra ID, SCIM provisioning/deprovisioning, OAuth security integrations, key pair auth with rotation in Azure Key Vault, and Private Link connectivity.
  • Write Python (snowflake-connector-python, Snowpark) and JavaScript stored procedures/UDFs for platform automation; build Terraform modules and Azure DevOps CI/CD for schema migrations, dbt promotion, and environment deployments.
  • Integrate Snowflake with Azure (ADLS Gen2, Key Vault, Data Factory, Monitor); support dbt workflows and MageAI or equivalent orchestration; liaise with Snowflake support on escalations.
  • Adopt Snowflake Cortex AI with cost controls; set the technical bar through code reviews, pairing, reference implementations, and Confluence runbooks—standards proven by shipping, not handed off as specs.