Job Title: Senior Azure Databricks Platform Security Engineer
Location: Navi Mumbai
Working Hours: 9:00 AM – 6:00 PM
Mode of Interview: Face-to-Face at Navi Mumbai
Headcount: 1 Position
Position Summary
The Senior Azure Databricks Platform Security Engineer is an individual contributor role responsible for the end-to-end security of the Azure Databricks platform and the Lakehouse data estate. The incumbent will harden Azure Databricks workspaces, govern Unity Catalog, seamlessly integrate Databricks with Azure tenant-level security controls, and build custom Microsoft Sentinel threat detections and automated playbooks for all Databricks workloads.
Requirements
Key Responsibilities
Azure Databricks Platform Security & Unity Catalog Governance:
Harden Azure Databricks workspaces using VNet injection, Secure Cluster Connectivity (No Public IP), Private Link, Customer-Managed Keys (CMK), and Personal Access Token (PAT) / Service Principal governance.
Configure and govern Unity Catalog metastores, catalogs, schemas, external locations, storage credentials,
and fine-grained row/column-level access controls.
Define and enforce cluster policies, init-script security controls, Azure Key Vault-backed secret scopes, and library allow-lists.
Audit access across ADLS Gen2, Delta Lake, and external data sources while enforcing encryption-at-rest (CMK) and Private Endpoint connectivity.
Azure Cloud Tenant Security Controls:
Configure Microsoft Entra ID security controls supporting Databricks, including Conditional Access policies, Multi-Factor Authentication (MFA), and automated SCIM user/group provisioning.
Operate Azure Privileged Identity Management (PIM) for Databricks workspace and resource-group privileged roles, leading periodic access reviews.
Apply and enforce Azure Policy initiatives across Databricks deployments to ensure compulsory VNet injection, disabled public access, CMK usage, and active diagnostic logging.
Sentinel Threat Detections & Response Automation:
Onboa