About the Role
We partner with global enterprises to design and build large-scale data platforms that power the products and operations at the center of their business.
Most of that data is export-controlled, and the platform has to be both secure and affordable from day one. Access cannot be a per-table exercise here. It has to derive from classification. Running costs cannot be a surprise at the end of the month either. It has to be attributed, capped, and visible from the first workload.
You will own that operational layer. You will implement the Unity Catalog governance foundation designed by the architect, put compute and cost controls in place, and give the stakeholders clear visibility into who is using what, what it costs, and whether the controls are working.
What You'll Do
- Configure the Unity Catalog foundation, including catalogs, schemas, and baseline role-based access controls across all environments.
- Implement the data classification and tagging approach, including governed tags that drive program-level CUI and part-level ITAR handling.
- Implement row filters and column masks where classification requires them, so access is enforced by policy rather than by hand-built views.
- Configure lineage capture for ingestion pipelines and make lineage usable for audit and impact analysis.
- Implement cluster policies, budget policies, and serverless spend controls that keep compute within agreed limits without blocking engineers.
- Design and implement cost-attribution tagging and a chargeback model by program, team, and workload.
- Build cost and usage dashboards on Databricks system tables and AWS billing data, and report spend trends and anomalies to stakeholders.
- Set up data quality monitoring and alerting standards for the pipelines the engineers build.
- Support the architect in presenting governance and access controls to enterprise security reviewers, with documentation of policies and evidence that they work.
- Document governance and cost standards, including catalog and column documentation, so the client can operate the platform after handoff.
What We're Looking For
- 5+ years in data platform engineering, cloud engineering, or platform administration.
- Hands-on Databricks administration in production.
- Practical Unity Catalog experience: access controls, governed tags, lineage, and, ideally, row filters and column masks.
- Experience implementing classification-driven access, where tags decide access.
- Demonstrated ownership of platform cost: you have written cluster and budget policies, implemented tagging standards, and built a chargeback or showback model.
- Experience with AWS cost management, such as Cost Explorer, Cost and Usage Reports, and budgets.
- Strong SQL and working Python, with experience querying system tables or billing data to build reporting.
- Clear written communication. Governance standards, cost reports, and runbooks are core deliverables here.
- Ability to complete the client's background check and onboarding and to work on client-furnished equipment.
- US citizenship.
- Fluent English, both written and spoken.
Nice to Have
- Experience with Databricks on AWS GovCloud.
- Experience with Delta Sharing across regions or regulatory boundaries.
- Infrastructure as code for Databricks, such as Terraform or Databricks Asset Bundles.
- FinOps Certified Practitioner or a Databricks Platform Administrator accreditation.
- Experience with Lakehouse Monitoring or other data quality tooling.
- Prior work in a defense, aerospace, or FedRAMP environment, or with CUI or ITAR-controlled data.
Why Lumenalta is an amazing place to work at
At Lumenalta, you can expect that you will:
- Be 100% dedicated to one project at a time so that you can innovate and grow.
- Be a part of a team of talented and friendly senior-level developers.
- Work on projects that allow you to use leading tech.
For Databricks practitioners specifically, we are a Databricks partner with Champions and MVPs on our team, and that carries three concrete things:
- Delivery Partner Program qualification. Databricks co-delivers its Professional Services engagements through a short list of approved partner organizations, and practitioners have to be individually qualified before they can work on them. The qualification is granted once at the individual level and does not expire, so it stays with you. Partner organizations are the route in, so the qualified pool stays small. That scarcity is most of the value, and we sponsor it.
- Champion path. Databricks Champion is an individual recognition with its own badge, a dedicated Databricks solutions architect as your mentor, access to product teams, confidential roadmap briefings, and an invitation to the internal Tech Summit. Nomination has to come from a partner organization, which puts it out of reach for independents and most contractors. We nominate actively and regularly, and the Champions already on our team mentor candidates through it.
- Certifications covered. We pay the exam fee for any Databricks certification you want to take.
Our Process
A screening call, a technical interview, and a HackerRank assessment. The technical interview is a conversation rather than a whiteboard exam. We will ask you to walk through a governance design you have shipped, a federate-versus-ingest call you made, what you would change, and what you would expect security reviewers to push hardest on. We will also ask for a writing sample. Relevant project references matter more to us than certifications.
Location
This is a fully remote position. This position supports a U.S. Government contract that requires all personnel to possess U.S. Citizenship. This role is remote within the United States only. Candidates must reside in the United States while assigned to our client and be physically located within the United States when performing project work or accessing project systems or data. Availability to work overlapping Pacific, Central, or Eastern U.S. time zones.
Application Deadline
Applications will be accepted until October 4th, 2026. Candidates can expect feedback by October 12th, 2026.

