Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
The Lead Databricks Data Security Engineer will design and implement access control models, including RBAC and ABAC, within the Databricks Lakehouse environment. This role involves establishing security architecture, defining engineering standards, and automating compliance controls using infrastructure-as-code practices.
Northrop Grumman is seeking a Lead Databricks Data Security Engineer to lead the design, implementation, and governance of access control across our Databricks Lakehouse environment. This role will serve as the senior technical owner of the data access control model, defining the architecture, establishing engineering standards, and translating security and compliance requirements into scalable technical controls. The selected candidate will play a key role in building the Databricks security function and will work closely with data engineering, platform engineering, and enterprise stakeholders. This is a hands-on software engineering and architecture role that requires both strategic leadership and direct technical implementation.
The primary location of this position will be Falls Church, VA. We will allow for fulltime telework as well.
Key Responsibilities:
Lead the design and implementation of RBAC and ABAC within Databricks Unity Catalog, including data structure, access models, and tagging standards.
Define the security architecture for data access, including dynamic views, row-level security, and column masking.
Develop the identity governance approach for Databricks, including service principals, workload identities, and integration with enterprise identity providers.
Translate regulatory, contractual, and compliance requirements into practical technical controls within the platform.
Establish and maintain data classification standards and tagging structures that support scalable access control.
Implement grants, catalogs, tags, and access controls as code using Terraform and/or Databricks Asset Bundles to support version control and audit readiness.
Work closely with workspace administrators and platform engineers to align workspace, compute, secrets, and network controls with the broader data access strategy.
Create guardrails, templates, and streamlined workflows that allow data engineers to manage access appropriately while maintaining strong security controls.
Basic Qualifications
Bachelor's degree in a relevant discipline and at least 8 years as a Software Engineer or Data Engineer with a heavy focus on data platform security and security automation; Master's degree and at least 6 years of relevant experience.
At least 2 years of hands on experience implementing Databricks Unity Catalog security features.
Demonstrated experience designing and implementing RBAC and ABAC models at scale, including hands on experience with Databricks Unity Catalog, grants, dynamic views, row and column level filtering and masking.
Fluency with identity and federation patterns including SCIM, service principals, and integration with enterprise identity providers such as Entra ID.
Experience applying infrastructure-as-code practices, preferably Terraform to access, tagging, and policy management in Databricks.
Proficiency in Python and SQL for automation, monitoring, and compliance.
Preferred Qualifications
The ability to obtain a government security clearance
Working onsite full time in Falls Church, VA
Master's degree
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Security Engineer
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”