DigitalOcean

Staff Software Engineer-Security Products

DigitalOcean
Apply
5 hours ago
Bengaluru, IndiaStaff+
H1B Sponsor

Responsibilities

  • Own multi-year technical strategy and architecture across IAM, KMS, CSPM, and ISPM.
  • Define agent identity and trust architecture for AI systems, inference pipelines, and service-to-service workloads.
  • Resolve cross-domain security platform decisions involving identity assertions, key material, posture signals, authorization, and audit evidence.
  • Shape posture discovery, evaluation, remediation, and adaptive policy enforcement across CSPM and ISPM.
  • Lead adoption of OIDC, SAML, SCIM, WIMSE, OAuth Token Exchange, KMIP, PKCS#11, and emerging NIST PQC standards.
  • Establish cryptographic engineering, identity protocol, policy authoring, and posture evaluation standards.
  • Partner with compliance and executive leadership on HIPAA, SOC 2, and emerging regulatory requirements.
  • Mentor IC3 and IC4 engineers and increase technical capability across Security Products teams.

Requirements

  • 10+ years of software engineering experience, including 5+ years focused on security-critical systems across at least two relevant security domains.
  • Expert-level proficiency in Go and experience building and operating high-scale, security-critical distributed services in production.
  • Deep knowledge of OIDC, OAuth2, SAML, SCIM, RBAC, ABAC, and PBAC, including designing workload and agent identity systems.
  • Applied cryptography expertise covering symmetric and asymmetric primitives, key derivation, authenticated encryption, and envelope encryption.
  • Experience designing or operating CSPM or ISPM systems, including resource discovery, policy evaluation, misconfiguration detection, and risk aggregation.
  • Familiarity with cloud resource models and control frameworks such as DigitalOcean, AWS, GCP, Azure, CIS Benchmarks, and NIST CSF.
  • Proven ability to design and operate cloud-scale distributed systems involving consensus, replication, partitioning, and failure recovery.
  • Track record of aligning multiple engineering teams, resolving architectural conflicts, establishing standards, and influencing roadmaps.
  • Ability to communicate security platform strategy, business impact, and compliance posture to executive and board-level audiences.
  • Experience with OPA, Rego, SPIFFE/SPIRE, WIMSE, HSMs, PKCS#11, KMIP, NIST post-quantum cryptography standards, or production key management platforms is preferred.
  • Background with open-source security projects, standards bodies, AI-native or inference-heavy workloads, or HIPAA, SOC 2, ISO 27001, or FedRAMP programs is preferred.

Benefits

  • Located in Bengaluru, India with a hybrid work arrangement.
  • Reimbursement for relevant conferences, training, and education.
  • Access to LinkedIn Learning courses.
  • Employee Assistance Program, local employee meetups, and flexible time off.
  • Potential bonus, equity compensation, and Employee Stock Purchase Program are mentioned without stated amounts.
DigitalOcean

About DigitalOcean

1,001-5,000 employees

DigitalOcean is the AI-Native Cloud purpose-built for the inference and agentic era. Its five-layer integrated platform—spanning GPU and CPU infrastructure, core cloud, inference, data, and managed agent orchestration—is open throughout with no vendor lock-in, giving builders everything they need to start fast, scale production AI workloads, and improve unit economics. More than 650,000 customers and millions of developers globally trust DigitalOcean to build, ship, and scale their applications.