<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>791144c2-47c</externalid>
      <Title>Sr Staff Production Engineer- Public Sector</Title>
      <Description><![CDATA[<p>At Databricks, we are looking for a Sr Staff Production Engineer- Public Sector to join our team. In this role, you will own and evolve the secure infrastructure, access patterns, and guardrails that keep Databricks&#39; global platform safe and compliant in production. You will be responsible for the &#39;sovereign layer&#39; of our infrastructure, ensuring that our Data Intelligence Platform operates with 100% reliability and security in highly regulated, air-gapped, and sovereign environments.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Design, automate, and operate the IAM, account/subscription, and project lifecycle across AWS, Azure, and GCP, enforcing least-privilege and standardized access patterns at scale.</li>
</ul>
<ul>
<li>Review, implement, and continuously improve cloud identity and access policies (IAM, Okta, Opal) to align with Databricks security standards and audit requirements.</li>
</ul>
<ul>
<li>Build and maintain reliable, observable automation and tooling to apply cloud changes (roles, policies, accounts, networking) safely and repeatedly.</li>
</ul>
<ul>
<li>Treat operational and security issues as software problems: eliminate toil, drive root-cause analysis, and codify fixes into infrastructure and tooling.</li>
</ul>
<ul>
<li>Own and improve security and audit logging data pipelines from cloud providers into our internal systems, ensuring timely, accurate data for detection, investigations, and audits.</li>
</ul>
<ul>
<li>Partner with Security, Compliance, and Audit teams to provide evidence, clarifications, and policy updates that keep our environments aligned with evolving standards.</li>
</ul>
<ul>
<li>Operate and improve specialized, highly regulated environments (e.g., FedRAMP / GovCloud) including release management, patching cadences, and supporting secure access workflows (e.g., SAW).</li>
</ul>
<ul>
<li>Ensure high availability and resiliency for critical security and access infrastructure across these environments.</li>
</ul>
<ul>
<li>Participate in a 24x7 on-call rotation for high-severity incidents impacting cloud accounts, IAM, or security data pipelines.</li>
</ul>
<ul>
<li>Act as a key partner to product engineering, security engineering, and field teams during incidents to restore service and harden systems for the future.</li>
</ul>
<p>Requirements:</p>
<ul>
<li>Candidates must be eligible for a Top Secret / Sensitive Compartmented Information (TS/SCI) security clearance.</li>
</ul>
<ul>
<li>Possession of a current polygraph (Counterintelligence or Full Scope) is highly desired and considered a significant plus.</li>
</ul>
<ul>
<li>Education- BS, MS, or PhD in Computer Science, Engineering, or a related technical field, or equivalent practical experience.</li>
</ul>
<ul>
<li>Experience: 12+ years of experience, including leading the strategy for cloud IAM, account architecture, or security-critical infrastructure across multiple environments or business units.</li>
</ul>
<ul>
<li>Cloud &amp; Infrastructure Expertise</li>
</ul>
<ul>
<li>Deep hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) in areas such as IAM, networking, accounts/subscriptions/projects, and audit logging.</li>
</ul>
<ul>
<li>Strong background in Infrastructure-as-Code and automation (e.g., Terraform, CloudFormation, or similar) and CI/CD for infrastructure changes.</li>
</ul>
<ul>
<li>Security &amp; Compliance Mindset</li>
</ul>
<ul>
<li>Proven experience working in or with security-sensitive or regulated environments (e.g., SOC2, FedRAMP, ISO 27001, financial services, public sector) and translating requirements into concrete technical controls.</li>
</ul>
<ul>
<li>Familiarity with access review processes, policy baselines, and audit evidence for cloud environments.</li>
</ul>
<ul>
<li>Operational Excellence</li>
</ul>
<ul>
<li>Demonstrated success running high-availability, security-critical services, including on-call responsibilities and incident management.</li>
</ul>
<ul>
<li>Strong debugging and problem-solving skills across distributed systems, with the ability to navigate ambiguous issues spanning multiple teams and platforms.</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience with Okta, Opal, or similar identity/access tooling.</li>
</ul>
<ul>
<li>Background operating secure admin workstations (SAW) or comparable hardened access patterns.</li>
</ul>
<ul>
<li>Experience migrating cloud accounts or subscriptions during M&amp;A or large-scale reorganizations.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$195,400-$268,600 USD</Salaryrange>
      <Skills>Cloud IAM, Cloud infrastructure, Infrastructure-as-Code, Automation, CI/CD, Security and compliance, Access review processes, Policy baselines, Audit evidence, High-availability services, Security-critical services, On-call responsibilities, Incident management, Debugging and problem-solving skills, Distributed systems, Okta, Opal, Identity/access tooling, Secure admin workstations, Hardened access patterns, Cloud account migration, Subscription migration</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified and democratized data, analytics, and AI platform to over 10,000 organizations worldwide.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/8519396002</Applyto>
      <Location>Virginia</Location>
      <Country></Country>
      <Postedate>2026-04-24</Postedate>
    </job>
  </jobs>
</source>