{"schemaVersion":"jobsearcher.job.v1","id":"87101c81604dfd09e1e567bd","url":"https://jobsearcher.com/jobs/87101c81604dfd09e1e567bd","canonicalUrl":"https://jobsearcher.com/jobs/87101c81604dfd09e1e567bd","title":"Senior Snowflake Platform Engineer","description":"WHO WE AREWe are a value-based precision medicine company working in health IT, real-world data, and digital health for specialty providers, payers, and life sciences. Our platform closes gaps in care and generates real-world evidence. Snowflake is where that data lives, which makes this role load-bearing.THE ROLEYou will own and operate our multi-account Snowflake platform as the primary technical authority on its security, access architecture, account administration, and Azure integration. This is a platform ownership role, not a data engineering role with administration attached, and not an architecture role that directs other people to implement. You will be the person in the console, in the Terraform, and in the incident.You will operate across multiple Snowflake accounts, enforce governance at scale in a HIPAA-regulated environment, and set the technical bar for every team that depends on the platform. You write Python fluently, you use AI tooling as a normal part of how you work, and you do not wait to be told what to fix.FIRST 90 DAYSDays 1-30: inherit the account inventory, RBAC model, resource monitors, and credential estate. Produce a written gap assessment of access risk and cost exposure.Days 31-60: close the top three access findings yourself. Take ownership of the Terraform modules and the Azure DevOps pipelines for schema migration.Days 61-90: own the credential rotation calendar, the network policy baseline, and the cost governance reporting line to engineering leadership.WHAT YOU WILL OWNSnowflake platformMulti-account administration: account configuration, organizational hierarchy, resource monitors, replication and failover, cross-account data sharing.Access architecture: multi-tier custom RBAC, grant hierarchies, functional versus access role separation, enforcement and drift detection across accounts.Identity and credentials: SAML federation and SCIM through Entra ID, OAuth security integrations with BLOCKED_ROLES_LIST and token policy, key-pair auth with scheduled rotation into Azure Key Vault, user lifecycle including TYPE classification and service-account naming.Network and connectivity: account and user level network policies, Private Link endpoints, coordination with network and security teams.Cost governance: warehouse sizing, autoscaling policy, resource monitor alerting, credit burn analysis and reporting.Automation and deliveryPython automation with snowflake-connector-python and Snowpark; Terraform modules for warehouses, databases, roles, and integrations.Azure DevOps pipelines for schema migration, dbt promotion, and environment-to-environment deployment.Azure integration: ADLS Gen2 storage integrations and external stages, Key Vault, Data Factory, Azure Monitor. Maintenance and migration of existing JavaScript stored procedures, with new work in Python and SQL.Governance, operations, and leadershipAudit logging, object tagging, access history analysis, data classification, and lifecycle policy in a HIPAA-regulated environment.dbt workflow support, MageAI or equivalent orchestration operations, and Snowflake vendor escalation and release monitoring.Daily use of AI tooling such as GitHub Copilot, Claude, or Cursor is expected rather than optional. Governed adoption of Snowflake Cortex AI with cost controls in place.Set the bar through code review, pairing, runbooks, and architecture documentation. Own platform standards and drive adoption across data, analytics, and application engineering without formal authority.WHAT WE NEED YOU TO HAVE DONEThis role calls for hands-on ownership, not adjacent experience. In our first conversation, we'd like you to walk us through six things you've built yourself:Custom RBAC designed from scratch — a role hierarchy you built from a blank slate: functional roles versus access roles, grant hierarchy, object ownership model. Extending a hierarchy someone else designed, or assigning built-in roles, is a different kind of experience than this.Key-pair auth you own end to end — implemented for service accounts and rotated on a defined schedule, with private keys held in a managed secrets vault.OAuth security integrations — Snowflake OAuth, internal or external, including BLOCKED_ROLES_LIST and token policy.Network policies at account and user level — Snowflake IP allowlists implemented and enforced at both levels, and you can explain how policy inheritance resolves.SSO and SCIM configured, not just consumed — SAML federation and SCIM provisioning stood up end to end against an enterprise IdP. Entra ID, Okta, and Ping all count equally.Production Python, weekly — snowflake-connector-python, Snowpark, or both, in real automation you maintain.Alongside these:4+ years hands-on Snowflake administration in production; 8+ years total engineering experience.Advanced SQL including Snowflake-specific constructs: Time Travel, zero-copy cloning, dynamic data masking, row access policies.Production infrastructure-as-code experience. Terraform with the Snowflake provider preferred; Terraform elsewhere, or equivalent IaC, welcome.CI/CD pipelines you have built and maintained for database or schema deployment. Azure DevOps preferred; GitLab CI or GitHub Actions welcome.Azure fundamentals in practice: Entra ID app registrations and conditional access, Key Vault secrets and rotation, ADLS Gen2 access patterns.A platform-level initiative you've owned end to end, including vendor escalation and cross-team alignment.Delivery in a regulated environment (HIPAA, HITRUST, SOX, PCI, FedRAMP, or similar) with compliance constraints on tooling and access.Clear written and verbal communication. You will write the runbook and then explain it to people who do not administer Snowflake.If you're strong on the six items above but a few tools don't match ours exactly — your IdP was Okta or Ping rather than Entra ID, your IaC experience isn't with the Snowflake Terraform provider, your CI/CD is GitLab CI or GitHub Actions, you've owned one Snowflake account deeply rather than an org hierarchy, or your stored procedures are Python and SQL rather than JavaScript — please apply anyway. Those are ramp items, and we're glad to work through them together. What we can't teach is judgment about access, credentials, and blast radius in a regulated environment, which is why we lead with those six.PREFERREDSnowPro Advanced: Administrator. Weighted above SnowPro Advanced: Architect for this role, because we are hiring an operator.Snowflake Private Link or private endpoint configuration experience.Multi-account organizational hierarchy ownership, including ORGADMIN-level operations.Azure certification (AZ-104 or DP-203); dbt Cloud or dbt Core in production; MageAI, Airflow, or Prefect on AKS.Hands-on Snowflake Cortex AI, and healthcare, life sciences, or oncology data experience.This role operates in a HIPAA-regulated environment. All candidates must be comfortable with compliance-driven constraints on tooling, access, and data handling. This is a direct W-2 position. We do not accept C2C arrangements or third-party agency submissions.Benfits:Integra Connect, LLC provides a comprehensive benefits planMedical/Dental/Vision Insurance beginning the 1st of the month following your date of hirePaid Time Off401k with employer matchPaid Holidays and Floating HolidayEqual Opportunity EmployerPlease note that the deadline for submitting applications is September 30, 2026. All applications must be received by this date to be considered.","company":"Integra Connect","rawCompany":"integra connect","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-22T12:05:07.165Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1243.01","title":"Data Warehousing Specialists","slug":"data-warehousing-specialists"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Snowflake Platform Engineer","description":"WHO WE AREWe are a value-based precision medicine company working in health IT, real-world data, and digital health for specialty providers, payers, and life sciences. Our platform closes gaps in care and generates real-world evidence. Snowflake is where that data lives, which makes this role load-bearing.THE ROLEYou will own and operate our multi-account Snowflake platform as the primary technical authority on its security, access architecture, account administration, and Azure integration. This is a platform ownership role, not a data engineering role with administration attached, and not an architecture role that directs other people to implement. You will be the person in the console, in the Terraform, and in the incident.You will operate across multiple Snowflake accounts, enforce governance at scale in a HIPAA-regulated environment, and set the technical bar for every team that depends on the platform. You write Python fluently, you use AI tooling as a normal part of how you work, and you do not wait to be told what to fix.FIRST 90 DAYSDays 1-30: inherit the account inventory, RBAC model, resource monitors, and credential estate. Produce a written gap assessment of access risk and cost exposure.Days 31-60: close the top three access findings yourself. Take ownership of the Terraform modules and the Azure DevOps pipelines for schema migration.Days 61-90: own the credential rotation calendar, the network policy baseline, and the cost governance reporting line to engineering leadership.WHAT YOU WILL OWNSnowflake platformMulti-account administration: account configuration, organizational hierarchy, resource monitors, replication and failover, cross-account data sharing.Access architecture: multi-tier custom RBAC, grant hierarchies, functional versus access role separation, enforcement and drift detection across accounts.Identity and credentials: SAML federation and SCIM through Entra ID, OAuth security integrations with BLOCKED_ROLES_LIST and token policy, key-pair auth with scheduled rotation into Azure Key Vault, user lifecycle including TYPE classification and service-account naming.Network and connectivity: account and user level network policies, Private Link endpoints, coordination with network and security teams.Cost governance: warehouse sizing, autoscaling policy, resource monitor alerting, credit burn analysis and reporting.Automation and deliveryPython automation with snowflake-connector-python and Snowpark; Terraform modules for warehouses, databases, roles, and integrations.Azure DevOps pipelines for schema migration, dbt promotion, and environment-to-environment deployment.Azure integration: ADLS Gen2 storage integrations and external stages, Key Vault, Data Factory, Azure Monitor. Maintenance and migration of existing JavaScript stored procedures, with new work in Python and SQL.Governance, operations, and leadershipAudit logging, object tagging, access history analysis, data classification, and lifecycle policy in a HIPAA-regulated environment.dbt workflow support, MageAI or equivalent orchestration operations, and Snowflake vendor escalation and release monitoring.Daily use of AI tooling such as GitHub Copilot, Claude, or Cursor is expected rather than optional. Governed adoption of Snowflake Cortex AI with cost controls in place.Set the bar through code review, pairing, runbooks, and architecture documentation. Own platform standards and drive adoption across data, analytics, and application engineering without formal authority.WHAT WE NEED YOU TO HAVE DONEThis role calls for hands-on ownership, not adjacent experience. In our first conversation, we'd like you to walk us through six things you've built yourself:Custom RBAC designed from scratch — a role hierarchy you built from a blank slate: functional roles versus access roles, grant hierarchy, object ownership model. Extending a hierarchy someone else designed, or assigning built-in roles, is a different kind of experience than this.Key-pair auth you own end to end — implemented for service accounts and rotated on a defined schedule, with private keys held in a managed secrets vault.OAuth security integrations — Snowflake OAuth, internal or external, including BLOCKED_ROLES_LIST and token policy.Network policies at account and user level — Snowflake IP allowlists implemented and enforced at both levels, and you can explain how policy inheritance resolves.SSO and SCIM configured, not just consumed — SAML federation and SCIM provisioning stood up end to end against an enterprise IdP. Entra ID, Okta, and Ping all count equally.Production Python, weekly — snowflake-connector-python, Snowpark, or both, in real automation you maintain.Alongside these:4+ years hands-on Snowflake administration in production; 8+ years total engineering experience.Advanced SQL including Snowflake-specific constructs: Time Travel, zero-copy cloning, dynamic data masking, row access policies.Production infrastructure-as-code experience. Terraform with the Snowflake provider preferred; Terraform elsewhere, or equivalent IaC, welcome.CI/CD pipelines you have built and maintained for database or schema deployment. Azure DevOps preferred; GitLab CI or GitHub Actions welcome.Azure fundamentals in practice: Entra ID app registrations and conditional access, Key Vault secrets and rotation, ADLS Gen2 access patterns.A platform-level initiative you've owned end to end, including vendor escalation and cross-team alignment.Delivery in a regulated environment (HIPAA, HITRUST, SOX, PCI, FedRAMP, or similar) with compliance constraints on tooling and access.Clear written and verbal communication. You will write the runbook and then explain it to people who do not administer Snowflake.If you're strong on the six items above but a few tools don't match ours exactly — your IdP was Okta or Ping rather than Entra ID, your IaC experience isn't with the Snowflake Terraform provider, your CI/CD is GitLab CI or GitHub Actions, you've owned one Snowflake account deeply rather than an org hierarchy, or your stored procedures are Python and SQL rather than JavaScript — please apply anyway. Those are ramp items, and we're glad to work through them together. What we can't teach is judgment about access, credentials, and blast radius in a regulated environment, which is why we lead with those six.PREFERREDSnowPro Advanced: Administrator. Weighted above SnowPro Advanced: Architect for this role, because we are hiring an operator.Snowflake Private Link or private endpoint configuration experience.Multi-account organizational hierarchy ownership, including ORGADMIN-level operations.Azure certification (AZ-104 or DP-203); dbt Cloud or dbt Core in production; MageAI, Airflow, or Prefect on AKS.Hands-on Snowflake Cortex AI, and healthcare, life sciences, or oncology data experience.This role operates in a HIPAA-regulated environment. All candidates must be comfortable with compliance-driven constraints on tooling, access, and data handling. This is a direct W-2 position. We do not accept C2C arrangements or third-party agency submissions.Benfits:Integra Connect, LLC provides a comprehensive benefits planMedical/Dental/Vision Insurance beginning the 1st of the month following your date of hirePaid Time Off401k with employer matchPaid Holidays and Floating HolidayEqual Opportunity EmployerPlease note that the deadline for submitting applications is September 30, 2026. All applications must be received by this date to be considered.","datePosted":"2026-08-22T12:05:07.165Z","dateModified":"2026-08-22T12:05:07.165Z","hiringOrganization":{"@type":"Organization","name":"Integra Connect","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"87101c81604dfd09e1e567bd"},"url":"https://jobsearcher.com/jobs/87101c81604dfd09e1e567bd"}}