Lead Snowflake Platform Engineer
U.S. BankAbout the role
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.
Job Description
Job Description
Be a part of transformational change where integrity matters, success inspires and great teams collaborate and innovate. As the fifth-largest bank in the United States, we’re one of the country's most respected, innovative, ethical and successful financial institutions. We’re looking for people who want more than just a job – they want to make a difference! U.S. Bank is seeking a Software Engineer who will contribute toward the success of our technology initiatives in our digital transformation journey.
About the Team
The Enterprise Data Platform team builds and operates secure, compliant, and scalable data platforms that power analytics, reporting, and operational insights across the organization. We function as a platform engineering organization, enabling domain teams to move fast through self‑service infrastructure, strong governance, and automation‑first design.
We partner closely with Cloud Engineering, IAM, Information Security, Networking, and FinOps to ensure our Snowflake platform meets regulatory expectations while delivering a high‑quality developer experience. Our mission is to remove friction for data teams while enforcing enterprise standards through code, pipelines, and policy—not manual processes.
Job Responsibilities
Design, build, and operate the enterprise Snowflake data platform supporting multiple business domains (Finance, HR, Supply Chain)
Own the Snowflake platform lifecycle, including account topology, RBAC, network architecture, governance, CI/CD automation, and disaster recovery
Build and maintain multi‑account Snowflake environments (PROD / NONPROD / DEV) on Snowflake Business Critical edition
Implement secure Azure Private Link connectivity, including private endpoints, Private DNS Zones, and network policy enforcement
Develop and maintain Terraform modules to automate provisioning of Snowflake resources (databases, schemas, warehouses, roles, tags, monitors, integrations)
Enable self‑service platform consumption through validated YAML manifests deployed via Shield CI/CD pipelines
Integrate Snowflake with Entra ID (Azure AD) using SAML SSO, SCIM provisioning, and enterprise RBAC patterns
Manage service account authentication, secrets, and key rotation using HashiCorp Vault and Azure Key Vault
Enforce security and compliance controls, including data masking, row‑level security, object tagging, audit logging, and policy‑as‑code
Embed infrastructure and supply‑chain security scanning into CI/CD pipelines (Checkov, tfsec, Semgrep, Snyk)
Design for resiliency and cost efficiency, including warehouse sizing, resource monitors, cost allocation tags, and chargeback reporting
Own cross‑region disaster recovery, replication strategies, and RPO/RTO adherence
Govern secure data sharing patterns and monitor data sharing usage and approvals
Partner with Cloud, IAM, Security, and FinOps teams to ensure alignment with enterprise standards and regulatory requirements
Basic Qualifications
- Bachelor’s degree, or equivalent work experience
- Six to eight years of relevant experience
Preferred Skills & Experience
5+ years of software engineering experience with a strong focus on infrastructure, platform, or cloud‑native systems
2+ years of Snowflake administration at the account/platform level (beyond SQL development)
Advanced Terraform expertise, including reusable module design, remote state management, provider versioning, and CI/CD integration
Deep experience with Azure networking, including Private Link, VNet peering, Private DNS Zones, and Network Security Groups (NSGs)
Strong background in identity and access management, including Entra ID (Azure AD), SAML, SCIM, and OAuth 2.0
Hands‑on experience with secrets management using HashiCorp Vault and/or Azure Key Vault
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s