Назад
Company hidden
10 часов назад

Principal Engineer – Security Architecture

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Engineer – Security Architecture (Distributed Storage Security): Defining secure-by-design architecture for S3-compatible object storage, POSIX/NFS file systems, and KV cache-based data services with an accent on distributed systems security, cryptography, IAM, and multi-tenant isolation. Focus on designing encryption and key management, secure APIs and protocols, Zero Trust controls, and security observability for high-throughput AI-driven infrastructure.

Location: Remote - California; work arrangement: Hybrid

Company

hirify.global develops next-generation distributed storage platforms, including S3-compatible object storage, POSIX-compliant file systems, and KV cache-based data services for high-performance AI-driven infrastructure.

What you will do

  • Define the long-term security architecture strategy and secure-by-design standards across data paths, control planes, orchestration, and protocol layers.
  • Design security for high-performance data movement, including encryption, integrity verification, secure I/O handling, and low-latency protection mechanisms.
  • Architect enterprise IAM and fine-grained authorization using LDAP, Active Directory, OIDC, Keycloak, SSO, MFA, federation, RBAC, and ABAC.
  • Design multi-tenant isolation, tenant-scoped access controls, secure APIs, authentication workflows, and platform governance controls.
  • Lead encryption and key management strategies covering BYOK, KMIP, external KMS interoperability, data-at-rest and data-in-transit protection.
  • Drive threat modeling, SSDLC, Zero Trust adoption, security observability, anomaly detection, and cross-functional architectural execution.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Engineering, Cybersecurity, or a related technical field.
  • 12+ years of experience in security architecture, distributed systems security, infrastructure security, or large-scale platform engineering.
  • Proven experience securing large-scale distributed systems, storage platforms, or cloud-native infrastructure.
  • Deep expertise in cryptography, PKI, secure key management, KMIP or equivalent protocols, IAM, RBAC, ABAC, SSO, MFA, federation, and policy-driven access control.
  • Experience with secure API design, TLS 1.3, mutual TLS, request signing such as SigV4, service-to-service authentication, and secure multi-tenant platforms.
  • Ability to influence technical direction and lead cross-functional security architecture initiatives.

Nice to have

  • Experience securing S3-compatible object storage, POSIX/NFS file systems, or high-performance distributed storage.
  • Familiarity with AI/ML infrastructure security, KV cache architectures, memory tiering, GPU-centric environments, and high-throughput low-latency systems.
  • Experience with BYOK, tenant-scoped key management, cryptographic erasure, Zero Trust, anomaly detection, and behavioral analytics.
  • Knowledge of SOC 2, ISO 27001, NIST, FedRAMP, and enterprise security governance standards.
  • Experience with Linux, scripting, automation, DevSecOps workflows, and infrastructure security tooling.

Culture & Benefits

  • Collaborate with storage architects, protocol engineers, platform teams, and security stakeholders.
  • Work across globally distributed engineering organizations.
  • Provide technical leadership, mentorship, and architectural guidance across engineering teams.
  • Represent security architecture initiatives in executive, customer, compliance, and strategic partner discussions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →