
Staff Software Engineer-Security Products
DigitalOcean2 months ago
Bengaluru, IndiaStaff+
Responsibilities
- Own multi-year technical strategy and architecture across IAM, KMS, CSPM, and ISPM.
- Define agent identity and trust architecture for AI systems, inference pipelines, and service-to-service workloads.
- Resolve cross-domain security platform decisions involving identity assertions, key material, posture signals, authorization, and audit evidence.
- Shape posture discovery, evaluation, remediation, and adaptive policy enforcement across CSPM and ISPM.
- Lead adoption of OIDC, SAML, SCIM, WIMSE, OAuth Token Exchange, KMIP, PKCS#11, and emerging NIST PQC standards.
- Establish cryptographic engineering, identity protocol, policy authoring, and posture evaluation standards.
- Partner with compliance and executive leadership on HIPAA, SOC 2, and emerging regulatory requirements.
- Mentor IC3 and IC4 engineers and increase technical capability across Security Products teams.
Requirements
- 10+ years of software engineering experience, including 5+ years focused on security-critical systems across at least two relevant security domains.
- Expert-level proficiency in Go and experience building and operating high-scale, security-critical distributed services in production.
- Deep knowledge of OIDC, OAuth2, SAML, SCIM, RBAC, ABAC, and PBAC, including designing workload and agent identity systems.
- Applied cryptography expertise covering symmetric and asymmetric primitives, key derivation, authenticated encryption, and envelope encryption.
- Experience designing or operating CSPM or ISPM systems, including resource discovery, policy evaluation, misconfiguration detection, and risk aggregation.
- Familiarity with cloud resource models and control frameworks such as DigitalOcean, AWS, GCP, Azure, CIS Benchmarks, and NIST CSF.
- Proven ability to design and operate cloud-scale distributed systems involving consensus, replication, partitioning, and failure recovery.
- Track record of aligning multiple engineering teams, resolving architectural conflicts, establishing standards, and influencing roadmaps.
- Ability to communicate security platform strategy, business impact, and compliance posture to executive and board-level audiences.
- Experience with OPA, Rego, SPIFFE/SPIRE, WIMSE, HSMs, PKCS#11, KMIP, NIST post-quantum cryptography standards, or production key management platforms is preferred.
- Background with open-source security projects, standards bodies, AI-native or inference-heavy workloads, or HIPAA, SOC 2, ISO 27001, or FedRAMP programs is preferred.
Benefits
- Located in Bengaluru, India with a hybrid work arrangement.
- Reimbursement for relevant conferences, training, and education.
- Access to LinkedIn Learning courses.
- Employee Assistance Program, local employee meetups, and flexible time off.
- Potential bonus, equity compensation, and Employee Stock Purchase Program are mentioned without stated amounts.
About DigitalOcean
DigitalOcean provides cloud infrastructure and platform services for developers, startups, and small to mid-sized businesses, including virtual machines (Droplets), managed Kubernetes and databases, object/block storage, networking, and GPUs for AI workloads. It operates a usage-based, self-service public cloud with APIs, CLI, and a marketplace to deploy and scale applications. Founded in 2012 and headquartered in Broomfield, Colorado, DigitalOcean is a public company listed on the NYSE.