Principal Data Protection & Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
- Lead the design and implementation of enterprise data protection and security architectures across Azure and Databricks platforms, ensuring alignment with organizational security, privacy, and regulatory requirements.
- Define and implement data security controls including encryption, tokenization, obfuscation, data masking, row-level security, attribute/column-level security, access governance, and data loss prevention (DLP) capabilities.
- Architect secure data platform solutions leveraging Azure security services, Databricks Unity Catalog, identity and access management controls, key management, auditing, monitoring, and compliance frameworks.
- Partner with business, security, compliance, architecture, and engineering teams to establish security patterns, standards, reference architectures, and implementation roadmaps for modern data platforms.
- Conduct security architecture reviews, threat assessments, data protection impact assessments, and control effectiveness reviews to identify risks and recommend mitigation strategies.
- Define enterprise-wide governance models for sensitive data classification, access management, data sharing, lineage, retention, and regulatory compliance.
- Provide technical leadership and subject matter expertise for strategic initiatives involving cloud modernization, analytics platforms, AI/ML environments, and data product ecosystems.
- Lead client and stakeholder discussions related to platform security strategy, security architecture decisions, compliance requirements, and remediation planning.
- Establish security best practices and secure-by-design principles across the data platform lifecycle, including development, testing, deployment, and operations.
- Mentor engineering, architecture, and security teams while driving adoption of enterprise security standards and operational excellence.
Requirements
- 12+ years of experience in Data Security, Information Security, Cloud Security, Data Architecture, or related technical leadership roles.
- Deep hands-on expertise in Databricks security architecture, including Unity Catalog, RBAC/ABAC, data masking, row-level security, secure data sharing, lineage, and governance capabilities.
- Strong experience with Microsoft Azure security services, including Microsoft Entra ID (Azure AD), Azure Key Vault, Managed Identities, Private Link, Networking, Storage Security, and Monitoring solutions.
-
Proven experience implementing enterprise data protection controls such as:
- Encryption at rest and in transit
- Customer-managed keys (CMK)
- Tokenization
- Data masking and obfuscation
- Row-level and column-level access controls
- Data classification and governance
- Data loss prevention (DLP)
Strong understanding of data privacy, regulatory, and compliance frameworks including GDPR, CCPA, PCI-DSS, SOX, GLBA, HIPAA, or similar regulatory standards.
Experience securing modern cloud-based data platforms involving Databricks, Azure Data Lake, Synapse, Snowflake, or other enterprise analytics platforms.
Demonstrated ability to develop security reference architectures, governance frameworks, security standards, and implementation roadmaps.
Experience conducting security assessments, architecture reviews, threat modeling, and risk management activities for enterprise data platforms.
Strong understanding of DevSecOps, Infrastructure as Code (Terraform preferred), CI/CD, secrets management, and cloud-native security practices.
Excellent stakeholder management, consulting, communication, and presentation skills with the ability to engage in senior technology and business leadership.
Experience working in highly regulated industries such as Banking, Financial Services, Insurance, Healthcare, or similar regulated environments preferred.
Preferred Certifications
- Databricks Certified Professional (Data Engineer and/or Security/Governance-related credentials)
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
- CISSP, CCSP, CCSK, SABSA, or equivalent security certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again