Back to jobs

Sr Technical Data Security Architect- Remote (Anywhere in the U.S.)

Remote

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Position Summary

We are seeking an experienced and strategic Senior Technical Data Security Architect to join our growing data platform team. In this highly visible role, you will be responsible for designing, implementing, and governing enterprise-grade data security frameworks across the Microsoft data ecosystem and Databricks lakehouse platform. You will serve as the authoritative technical expert on data protection, privacy, access governance, and compliance, partnering closely with engineering, architecture, and business stakeholders to embed security by design at every layer of the data stack.

Key Responsibilities

Data Security Architecture & Strategy

  • Design and maintain end-to-end data security architecture across Microsoft Azure, Microsoft Fabric, Azure Synapse Analytics, Azure Data Lake Storage (ADLS Gen2), and Databricks Lakehouse Platform.
  • Define and enforce enterprise data classification, labeling, and handling standards aligned with Microsoft Purview Information Protection.
  • Develop reference architectures and security blueprints for data ingestion, transformation, storage, and consumption layers.
  • Lead threat modeling sessions for data pipelines and analytics workloads, identifying and mitigating risks proactively.
  • Establish a Zero Trust data security model across all data platforms and integration points.

Microsoft Data Technologies - Security Focus

  • Architect and govern data security controls within Microsoft Fabric, including workspace-level and item-level permissions, sensitivity labels, and OneLake security.
  • Design role-based access control (RBAC) and attribute-based access control (ABAC) strategies across Azure Data Factory, Azure Synapse, Azure Databricks, and Azure SQL.
  • Implement and operationalize Microsoft Purview for data catalog governance, data lineage, and automated sensitivity classification across hybrid and multi-cloud data estates.
  • Configure and manage Azure Private Endpoints, VNet integration, and network security groups for data services to eliminate public exposure.
  • Oversee encryption strategies including Azure Key Vault integration, customer-managed keys (CMK), and data-at-rest / data-in-transit encryption standards.
  • Partner with identity teams to enforce Entra ID Conditional Access policies, Privileged Identity Management (PIM), and managed identities for data service authentication.
  • Lead the implementation and tuning of Microsoft Defender for Cloud data security posture management (DSPM) capabilities.

Databricks Security Architecture

  • Architect and implement Unity Catalog as the enterprise-wide data governance layer across Databricks workspaces, including metastore design, catalog/schema/table-level permissions, and row/column-level security.
  • Design Databricks workspace security including network isolation (no-public-IP, vNet injection, private link), cluster policies, and IP access lists.
  • Define and enforce Databricks credential passthrough, service principal governance, and OAuth integration with Azure Entra ID.
  • Implement dynamic data masking and column-level security policies within Unity Catalog to protect PII, PHI, and sensitive financial data.
  • Establish Delta Lake security patterns including table ACLs, fine-grained access control, and audit logging strategies via Databricks system tables.
  • Oversee the security of Databricks workflows, notebooks, and job clusters, including secrets management integration with Azure Key Vault-backed secret scopes.
  • Conduct security reviews of MLflow models and Feature Store configurations to address data leakage risks in ML pipelines.

Compliance, Audit & Risk Management

  • Ensure data platform compliance with relevant regulatory frameworks including GDPR, CCPA, HIPAA, SOC 2 Type II, and PCI-DSS where applicable.
  • Design and maintain audit trail and data access logging architectures across Microsoft and Databricks platforms.
  • Conduct regular security risk assessments, gap analyses, and maturity evaluations of the data security program.
  • Develop and maintain security runbooks, policies, and standards documentation for data platform operations.
  • Coordinate with legal, compliance, and privacy teams to respond to data subject access requests (DSARs) and regulatory inquiries.

Cross-Functional Collaboration & Leadership

  • Serve as the primary security advisor to data engineering, analytics engineering, and BI teams throughout the development lifecycle.
  • Lead security architecture review boards for new data initiatives, third-party data integrations, and major platform changes.
  • Develop and lead a structured mentoring program for junior and mid-level engineers and architects, providing one-on-one coaching, career guidance, and skills development roadmaps tailored to each individual’s growth goals.
  • Conduct regular knowledge-sharing sessions, lunch-and-learns, and internal workshops to upskill teams on evolving data security threats, tooling, and compliance requirements across the Microsoft and Databricks ecosystems.
  • Partner with engineering managers and HR to define data security competency frameworks, leveling guides, and certification pathways that support talent development and retention across the data platform organization.
  • Establish and maintain a community of practice around data security, fostering peer learning, documentation culture, and cross-team collaboration on shared security challenges and architectural patterns.
  • Collaborate with SecOps and SOC teams to build data-specific detection rules, incident response playbooks, and forensic investigation capabilities.
  • Present security posture, risk findings, and remediation roadmaps to executive leadership and board-level stakeholders.

Required Qualifications

  • 5+ years of experience in data engineering, data architecture, or information security, with at least 5 years focused on data security architecture.
  • Deep hands-on expertise with Microsoft Azure data services: Azure Data Lake Storage Gen2, Azure Synapse Analytics, Azure Data Factory, Azure SQL Database, and Microsoft Fabric.
  • Demonstrated expertise in designing and implementing Databricks Unity Catalog, including workspace federation, metastore design, and fine-grained access control.
  • Strong proficiency with Microsoft Purview, including data map configuration, classification rules, sensitivity labels, and policy enforcement.
  • Expert-level knowledge of Azure identity and access management: Entra ID, Managed Identities, Conditional Access, PIM, and service principal governance.
  • Hands-on experience with Azure Key Vault, customer-managed encryption keys, and secrets management integration with data platforms.
  • Solid understanding of data governance frameworks and data security principles including Zero Trust, least privilege, and data minimization.
  • Experience with regulatory compliance programs (GDPR, CCPA, HIPAA, SOC 2, PCI-DSS) as applied to data platforms.
  • Proficiency in SQL and at least one programming/scripting language (Python, PySpark, PowerShell, or Terraform) used for security automation.
  • Strong written and verbal communication skills with the ability to articulate complex security concepts to technical and non-technical audiences.
  • Demonstrated experience securing data workloads across multi-cloud environments (Azure, AWS, and/or GCP), including cross-cloud data governance, identity federation, and consistent enforcement of security policies across heterogeneous cloud estates.
  • Hands-on experience with Snowflake data security, including Snowflake RBAC/DAC models, column-level and row-level security policies, dynamic data masking, network policies, Private Link configuration, and Snowflake Data Sharing governance controls.
  • Proven ability to support presales activities, including leading technical discovery sessions, contributing to RFP/RFI responses, delivering solution demonstrations, and authoring security architecture sections of client-facing proposals and statements of work.

Preferred Qualifications

  • Active certifications: Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Certified: Azure Data Engineer Associate (DP-203), Databricks Certified Data Engineer Professional, or equivalent CISSP / CISM.
  • Experience with Microsoft Sentinel for SIEM integration with data platform audit logs and anomaly detection.
  • Familiarity with Databricks Delta Sharing, Cleanroom, and cross-cloud governance patterns.
  • Experience with infrastructure-as-code (Terraform, Bicep) for automated, policy-compliant data platform deployments.
  • Background in data mesh or federated data governance operating models.
  • Exposure to AI/ML security considerations including model governance, training data security, and responsible AI frameworks within Azure ML or Databricks.
  • Experience in financial services, healthcare, or other highly regulated industries.

Technical Skills Summary

Category

Technologies & Tools

Microsoft Data Platform

Microsoft Fabric, Azure Synapse Analytics, Azure Data Lake Storage Gen2, Azure Data Factory, Azure SQL, Azure Cosmos DB, Power BI

Databricks

Unity Catalog, Delta Lake, Databricks Workflows, MLflow, Feature Store, Databricks SQL, PySpark

Snowflake & Multi-Cloud

Snowflake RBAC/DAC, Dynamic Data Masking, Row-Level Security, Network Policies, Private Link, Data Sharing Governance, AWS (S3 Security, IAM, Lake Formation), GCP (BigQuery Security, IAM, VPC Controls)

Security & Governance

Microsoft Purview, Microsoft Defender for Cloud, Azure Key Vault, Entra ID, Conditional Access, PIM

Networking & Isolation

Azure Private Link, VNet Integration, Network Security Groups, Databricks VNet Injection, IP Access Lists

IaC & Automation

Terraform, Azure Bicep, ARM Templates, PowerShell, Azure DevOps, GitHub Actions

Compliance Frameworks

GDPR, CCPA, HIPAA, SOC 2, PCI-DSS, NIST CSF, ISO 27001

Monitoring & SIEM

Microsoft Sentinel, Azure Monitor, Databricks System Tables, Log Analytics Workspace

 

 

 

 

 

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

Create a Job Alert

Interested in building your career at GuidePoint Security? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in GuidePoint Security’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.