About this role
About the Role Databricks is seeking a Sr Staff Production Engineer for the Public Sector to own the sovereign layer of the platform, ensuring secure, highly available production infrastructure across multi-cloud and regulated environments. The role focuses on cloud operations, IAM, and automation to maintain strict access controls and compliance.
What You'll Do
- Design, automate, and operate the IAM, account/subscription, and project lifecycles across AWS, Azure, and GCP with least-privilege principles.
- Review and improve cloud identity and access policies (IAM, Okta, Opal) to align with security standards and audit requirements.
- Build and maintain reliable automation and tooling to apply cloud changes (roles, policies, accounts, networking) safely and repeatedly.
- Treat operational and security issues as software problems: eliminate toil, drive root-cause analysis, and codify fixes into infrastructure and tooling.
- Own and improve security and audit logging data pipelines from cloud providers into internal systems, ensuring timely, accurate data for detection, investigations, and audits.
- Partner with Security, Compliance, and Audit teams to provide evidence, clarifications, and policy updates that keep environments aligned with evolving standards.
- Operate and improve specialized, highly regulated environments (e.g., FedRAMP / GovCloud) including release management, patching cadences, and supporting secure access workflows (e.g., SAW). Ensure high availability and resiliency for critical security and access infrastructure across these environments.
- Participate in a 24x7 on-call rotation for high-severity incidents impacting cloud accounts, IAM, or security data pipelines; collaborate with product engineering, security engineering, and field teams to restore service and harden systems for the future.
What We're Looking For
- Current TS/SCI security clearance (active or currently held in an editable/re-activatable status within the 2-year window).
- Nice to have: current polygraph (Counterintelligence or Full Scope) is highly desired.
- Education: BS, MS, or PhD in Computer Science, Engineering, or related field, or equivalent practical experience.
- Experience: 12+ years leading the strategy for cloud IAM, account architecture, or security-critical infrastructure across multiple environments or business units.
- Cloud & Infrastructure Expertise: deep hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) in IAM, networking, accounts/subscriptions/projects, and audit logging.
- Strong background in Infrastructure-as-Code and automation (Terraform, CloudFormation, or similar) and CI/CD for infrastructure changes.
- Security & Compliance Mindset: experience working in or with security-sensitive or regulated environments (SOC2, FedRAMP, ISO 27001, financial services, public sector) and translating requirements into concrete technical controls. Familiarity with access review processes, policy baselines, and audit evidence for cloud environments.
- Operational Excellence: demonstrated success running high-availability, security-critical services, including on-call responsibilities and incident management. Strong debugging and problem-solving skills across distributed systems, with the ability to navigate ambiguous issues spanning multiple teams and platforms.
- Bonus: experience with Okta, Opal, or similar identity/access tooling. Background operating secure admin workstations (SAW) or comparable hardened access patterns. Experience migrating cloud accounts or subscriptions during M&A or large-scale reorganizations.
Nice to Have
- Okta, Opal, or similar identity/access tooling
- SAW or comparable hardened access patterns
- M&A/subscription migrations experience
Compensation & Benefits
- Databricks is committed to fair and equitable compensation practices.
- Pay range not disclosed in posting. Actual compensation will be based on factors including skills, experience, certifications, and location.