What are the responsibilities and job description for the Data Architect position at TechMind RPO?
Position Summary
We are seeking a hands-on Data Architect to design and lead delivery of a secure, scalable Azure data and analytics platform. The client is an Azure-first organization planning to use Azure Databricks as a core component of its lakehouse, data engineering, reporting, and future AI/ML environment.
This role requires strong data architecture, Azure infrastructure, security, and integration expertise. A critical responsibility is designing secure, supportable interfaces that load approved data from commercial Azure databases and applications into a Microsoft Government Community Cloud (GCC), GCC High, or Government Azure tenant.
Responsibilities
- Design the target-state Azure data platform, including data ingestion, storage, transformation, governance, security, analytics, reporting, and operational support.
- Define lakehouse architecture and standards using Azure Databricks, Delta Lake, Azure Data Lake Storage Gen2, and related Azure services.
- Establish patterns for batch, near-real-time, and event-driven ingestion from databases, enterprise applications, SaaS systems, files, and APIs.
- Define logical and physical data models, data quality, reconciliation, metadata, lineage, retention, access-control, and data-governance standards.
- Design secure commercial Azure-to-GCC/Government integration patterns for API, database, application, file, and message-based data exchange.
- Design and lead API-based processes that extract approved data from commercial Azure sources and load it into GCC/Government applications, databases, data lakes, or integration services.
- Define end-to-end API data-load processes: source extraction, transformation, validation, payload/data-contract design, secure transmission, target ingestion, acknowledgments, error handling, retry/replay, reconciliation, monitoring, and support.
- Establish secure machine-to-machine authentication using Microsoft Entra ID, OAuth 2.0 client credentials, application registrations, service principals, certificates, token validation, scopes, audiences, and least-privilege RBAC.
- Define API security and gateway patterns, including Azure API Management or approved equivalent services, TLS, mutual TLS where required, API policies, firewall/WAF controls, private connectivity, IP allowlists, throttling, rate limits, and certificate/secret rotation.
- Partner with infrastructure, network, cybersecurity, compliance, application, database, data engineering, and BI teams to validate designs and lead implementation.
- Produce architecture diagrams, data flows, API/interface specifications, security designs, data mappings, deployment standards, and support runbooks.
Required Qualifications
- 7 years of experience in data architecture, data engineering, database architecture, data warehousing, analytics architecture, or integration architecture.
- 3 years designing and implementing cloud data platforms in Microsoft Azure.
- Demonstrated experience with Azure Databricks, Apache Spark, Delta Lake, and/or modern lakehouse architecture.
- Strong SQL and data-modeling expertise, including dimensional, operational, analytical, and lakehouse data models.
- Hands-on experience designing enterprise integrations involving databases, APIs, ETL/ELT pipelines, files, messaging, and cloud services.
- Demonstrated experience building or leading secure API integrations across separate tenants, cloud environments, network boundaries, security zones, or regulated environments.
- Strong REST API knowledge, including JSON/XML payloads, schema validation, API versioning, pagination, error handling, idempotency, retry behavior, rate limiting, and asynchronous processing.
- Experience with Python, PySpark, Azure Data Factory or Synapse Pipelines, Azure API Management, Azure Functions, Logic Apps, Service Bus, Event Hubs, or comparable integration technologies.
- Experience with Git, Azure DevOps or GitHub, CI/CD, deployment automation, and infrastructure-as-code concepts.
Azure, GCC, and Security Requirements
- Strong knowledge of Microsoft Entra ID, application registrations, enterprise applications, service principals, managed identities, RBAC, OAuth 2.0, OpenID Connect concepts, token acquisition/validation, certificate-based authentication, and secrets management.
- Understanding of commercial Azure and GCC/Government differences, including separate tenant boundaries, identity authorities, token/resource audiences, endpoints, service availability, network restrictions, and compliance requirements.
- Working knowledge of Azure networking and secure connectivity: VNets, subnets, NSGs, private endpoints, private DNS, Azure Firewall, VPN/ExpressRoute, routing, proxies, IP restrictions, and controlled ingress/egress.
- Experience securing Azure Databricks, ADLS Gen2, Azure SQL, APIs, and external connectivity using Azure Key Vault or an approved secrets-management platform, encryption in transit and at rest, audit logging, monitoring, and least-privilege controls.
- Ability to assess data classification and determine approved cross-boundary data-transfer methods; establish logging, audit evidence, data-quality controls, exception processing, reconciliation, disaster recovery, and operational ownership.
Preferred Qualifications
- Experience with GCC, GCC High, Azure Government, or another regulated cloud environment.
- Familiarity with FedRAMP, NIST 800-53/800-171, CJIS, HIPAA, CMMC, ITAR, or comparable compliance frameworks.
- Azure and/or Databricks certifications.
- Experience with Unity Catalog, Microsoft Purview, Power BI, Microsoft Fabric, Terraform, Bicep, ARM templates, and Azure DevOps YAML pipelines.