Job Description
We are seeking an experienced Snowflake Security Engineer to support enterprise-wide security initiatives within a large-scale Snowflake environment. This individual will be responsible for implementing and enhancing Snowflake security controls, including role-based access control, privileged access processes, data masking, encryption, secure connectivity, authentication integrations, anomaly detection, and policy enforcement.
This role is ideal for someone who has hands-on experience implementing security capabilities within Snowflake for a large enterprise environment. The right candidate does not need to have built the Snowflake RBAC model completely from scratch, but they must have strong experience implementing, modifying, improving, and operationalizing Snowflake security frameworks in a complex organization.
The individual will work closely with data, cloud, infrastructure, application, cybersecurity, and governance teams to ensure Snowflake security practices align with broader company-wide security initiatives.
Responsibilities include:
- Implement and support Snowflake security controls across an enterprise-level data environment.
- Design, configure, and maintain role-based access control structures within Snowflake.
- Ensure privileged access follows a controlled process and does not rely on broad or blanket administrative permissions.
- Implement and manage privileged access management processes for Snowflake administrators, application teams, data users, and service accounts.
- Configure and support secure authentication methods, including:
• Single Sign-On
• Multi-Factor Authentication
• LDAP / directory-based authentication
• Identity provider integrations
• Federated authentication models
-Support implementation of Snowflake security policies, including:
• Data masking policies
• Row access policies
• Network policies
• Session policies
• Authentication policies
• Access control policies
-Develop and maintain masking and access policies for sensitive data, including PII — personally identifiable information.
- Partner with data governance and security teams on data classification, sensitive data identification, tagging, and policy enforcement.
- Implement encryption-related controls and ensure Snowflake encryption capabilities align with enterprise security standards.
- Support anomaly detection, monitoring, and response processes related to Snowflake activity.
- Support enterprise processes for quarantining applications, users, or integrations when anomalous or risky behavior is detected.
- Collaborate with global teams across data engineering, infrastructure, application security, identity/access management, and enterprise security.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
-7+ years of experience as a Snowflake Security Engineer or Snowflake DBA supporting enterprise level security initiatives and implementation
-5+ years of experience implementing Snowflake RBAC (role-based access control) structures
-5+ years implementing security controls including data masking, encryption, and policy-based access control within Snowflake
-Strong experience with anomaly detection and quarantine of applications
-Expertise in implementing Snowflake authentication policies (single sign on, multi factor identification, LDAP, etc.) and implementation of secure connections
-5+ years applying these security policies across a large enterprise company (5k+ employees)
-Experience working with sensitive data classification including PII (personally identifiable information), confidential data, regulated data, or enterprise data classification frameworks.
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.