Work you'll do/Responsibilities We are looking for an experienced Azure Databricks Developer to join our data engineering team. In this role, you will be responsible for designing, building, and maintaining scalable data pipelines and analytics solutions on the Azure platform. You will work closely with data scientists, analysts, and other engineers to enable data-driven innovation and decision-making across the organization..
- Design and implement secure, scalable Databricks platform architectures on AWS, including workspace deployment, networking, IAM, and PrivateLink connectivity.
- Build and maintain Terraform-based infrastructure automation for AWS and Databricks resources to support standardized and repeatable platform delivery.
- Define and apply platform security patterns across identity, access control, secret management, network security, encryption, and data protection.
- Lead architecture discussions, technical workshops, and enablement sessions with customer and internal teams to guide solution design and implementation.
- Architect multi-account and multi-workspace environments that support strong isolation, shared services, and environment separation across dev, test, and production.
- Partner with stakeholders across security, infrastructure, and data teams to support governance, resiliency, compliance, and operational readiness.
- Provide technical guidance and support to other team members.
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
- Communicate regularly with Engagement Managers (Directors), project team members, and representatives from various functional and / or technical teams, including escalating any matters that require additional attention and consideration from engagement management
- Independently and collaboratively lead client engagement workstreams focused on improvement, optimization, and transformation of processes including implementing leading practice workflows, addressing deficits in quality, and driving operational outcomes
The Team AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements.
AI & Engineering - Industry Solutions teams works with the Customer group to bring a flexible capability and fluid capacity model to the delivery of small technology projects and enhancements.
Qualifications Required - Strong understanding of Databricks classic and serverless workspace deployments on AWS, including S3, IAM, VPC design, and both front-end and back-end PrivateLink connectivity
- 6yrs+ of hands-on Terraform experience across both AWS and Databricks resources to deploy, configure, and manage secure workspace infrastructure
- Working knowledge of Databricks platform security architecture, including workspace isolation, identity integration, cluster access controls, secret management, and network security patterns
- Strong communication skills with ability to independently lead architecture enablement sessions with large customer teams
- Threat model fluency - ability to articulate protect/detect/respond controls for all seven Databricks threat categories (account takeover, data exfiltration, insider threats, supply chain attacks, Databricks compromise, ransomware, resource abuse)Strong understanding of data warehousing concepts and ETL/ELT processes
- Bachelor's degree in Computer Science, Engineering, Information Systems, or related field.
- Limited immigration sponsorship may be available
- Ability to travel 10%, on average, based on the work you do and the clients and industries/sectors you serve
Preferred - Prior experience taking customer teams through Databricks security accreditation process
- Deep understanding of multi-workspace topologies - hub-and-spoke VPC designs, Transit Gateway integration, shared services VPCs, and cross-account network connectivity patterns for environment isolation (dev/staging/prod)
- Knowledge of data exfiltration prevention architectures - S3 VPC endpoint policies, restrictive bucket policies, STS condition keys, regional restrictions, and how Databricks data plane traffic flows interact with these controls
- Expertise in AWS PrivateLink at scale-including endpoint services, interface endpoints, DNS resolution chains (Route 53 Private Hosted Zones, inbound/outbound resolvers), and troubleshooting connectivity failures across complex multi-account Landing Zone architectures
- Deep knowledge of IAM trust chains in Databricks deployments-cross-account assume-role patterns, instance profiles vs. credential passthrough, IAM Roles for Service Accounts (IRSA) where applicable, and the Databricks-managed IAM role boundary model
- Understanding of credential vending and Unity Catalog's storage credential architecture - how temporary credentials are scoped, session policies, external location grants, and how these map to S3 access patterns auditable by CloudTrail
- Expertise in encryption architecture - CMK (Customer Managed Keys) for workspace storage, DBFS root, managed services (notebook/secret encryption), EBS encryption, and S3 SSE-KMS with key policies restricting decrypt to specific principals; understanding of key rotation implications
- Understanding of data classification and governance controls - Unity Catalog row/column-level security, attribute-based access control patterns, dynamic views, and how these satisfy regulatory requirements (OCC, FFIEC, SOX)
- Understanding of Databricks control plane / data plane separation - what data leaves the customer's AWS account, what metadata is stored in the Databricks-managed control plane, and how to articulate this to security review boards
- Knowledge of disaster recovery and high availability patterns - workspace regional failover considerations, metastore replication, cross-region S3 replication for underlying data, and RTO/RPO implications for Databricks-dependent pipelines
- Familiarity with patch management and image hardening-including the Databricks Runtime AMI lifecycle, custom container support (Docker on Databricks), CIS benchmark applicability, and addressing vulnerability scanning findings on ephemeral compute
- Understanding of multi-tenancy isolation guarantees - how Databricks isolates workloads between customers at the compute, storage, and network layers, and the additional controls available (dedicated VPCs, dedicated control plane for very large deployments)
- Knowledge of identity federation patterns - SCIM provisioning, SAML/OIDC integration, token lifecycle management, and how Databricks PAT/OAuth tokens interact with enterprise session management
- Enterprise Secrets Vault Integration: Practical experience architecting interim and native secrets retrieval pipelines, specifically leveraging HashiCorp Vault or CyberArk to manage rotated service principal client secrets and runtime on-premises database credentials.
- Very strong understanding of terraform modules for databricks and aws.
Recruiting tipsFrom developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
BenefitsThis position is aligned with the Project Delivery Model. To view the associated benefit package, please reference this document USBenefitsJourneyProjectandCenterTAM