1 month ago
Remote, United StatesStaff+
Responsibilities
- Lead end-to-end security architecture for distributed storage platforms, including data path, control plane, protocol, and ecosystem layers.
- Partner with engineering teams to secure high-performance data movement, storage tiers, APIs, and S3/POSIX interfaces.
- Lead threat modeling, security reviews, and Secure Software Development Lifecycle practices.
- Define IAM integrations, authentication and authorization workflows, RBAC/ABAC policies, SSO, MFA, federation, and tenant lifecycle management.
- Design encryption, key management, multi-tenant isolation, least-privilege controls, and segregation-of-duties mechanisms.
- Drive logging, auditing, observability, monitoring, anomaly detection, and data-exfiltration detection strategies.
- Provide technical leadership and mentorship across cross-functional engineering teams.
Requirements
- Bachelor’s or master’s degree in Computer Science, Engineering, or a related field.
- 12+ years of experience in security architecture, infrastructure security, or distributed systems.
- Experience designing security for large-scale distributed systems or storage platforms.
- Deep expertise in encryption, key management systems, cryptographic frameworks, and external KMS integration using KMIP or similar protocols.
- Strong knowledge of IAM, RBAC, ABAC, SSO, MFA, federation, LDAP, Active Directory, and OIDC.
- Experience with secure API design, TLS 1.3, mutual TLS, request signing such as SigV4, and multi-tenant isolation.
- Preferred experience with S3, POSIX/NFS, KV cache systems, memory tiering, AI/ML data infrastructure, BYOK, tenant-scoped key management, zero trust, cryptographic erasure, anomaly detection, and security analytics.
- Knowledge of SOC 2, ISO 27001, NIST, or FedRAMP compliance frameworks.
- Ability to collaborate with protocol, storage, platform, and other engineering teams.