DDN

Lead Engineer – Security Architecture

DDN
Apply
1 month ago
Remote, United StatesStaff+

Responsibilities

  • Define and lead the long-term security architecture strategy for distributed storage platforms.
  • Establish secure-by-design standards across data path, control plane, orchestration, and protocol layers.
  • Secure high-performance data movement through encryption, integrity verification, secure I/O handling, and low-latency protection mechanisms.
  • Lead security architecture reviews, threat modeling, and Secure Software Development Lifecycle practices.
  • Architect IAM frameworks and fine-grained authorization using enterprise identity providers, RBAC, ABAC, federation, SSO, MFA, and delegated authorization.
  • Design multi-tenant isolation, governance, policy enforcement, encryption boundaries, quotas, and least-privilege controls.
  • Design secure APIs, authentication workflows, policy orchestration, tenant lifecycle management, and platform governance controls.
  • Secure S3, POSIX/NFS, and related interfaces through request signing, session security, endpoint hardening, and protocol protections.
  • Lead encryption and key management strategies for data at rest and in transit, including BYOK, KMIP, tenant-scoped keys, and external KMS interoperability.
  • Define telemetry, logging, auditing, anomaly detection, and data-exfiltration monitoring strategies.
  • Drive Zero Trust security principles across distributed systems and infrastructure.
  • Provide technical leadership, mentorship, architectural guidance, and executive, customer, compliance, and partner representation.

Requirements

  • Bachelor’s or master’s degree in Computer Science, Engineering, Cybersecurity, or a related technical field.
  • 12+ years of experience in security architecture, distributed systems security, infrastructure security, or large-scale platform engineering.
  • Proven experience designing and securing large-scale distributed systems, storage platforms, or cloud-native infrastructure.
  • Deep understanding of distributed-system data path and control-plane security models.
  • Extensive expertise in cryptography, encryption frameworks, secure key management, and PKI architectures.
  • Strong experience integrating external KMS platforms using KMIP or equivalent protocols.
  • Advanced knowledge of IAM, RBAC, ABAC, SSO, MFA, federation, delegated authorization, and policy-driven access control.
  • Experience integrating LDAP, Active Directory, OIDC, and SAML-based identity systems.
  • Expertise in secure API design, TLS 1.3, mutual TLS, request signing such as SigV4, and service-to-service authentication.
  • Experience designing secure multi-tenant platforms with strong isolation, governance, and policy enforcement.
  • Strong understanding of security observability, logging, auditability, SIEM integration, and compliance monitoring.
  • Demonstrated ability to influence technical direction and lead cross-functional architectural initiatives.
  • Preferred experience with S3-compatible object storage, POSIX/NFS file systems, high-performance distributed storage, AI/ML infrastructure security, KV cache architectures, memory tiering, and GPU-centric distributed environments.
  • Preferred experience with BYOK, tenant-scoped key management, cryptographic isolation, ABAC metadata classification, Zero Trust, secure deletion, anomaly detection, behavioral analytics, and security telemetry platforms.
  • Familiarity with SOC 2, ISO 27001, NIST, FedRAMP, Linux systems, scripting, automation, DevSecOps workflows, and infrastructure security tooling.

Tech Stack

Categories

DDN

About DDN

1,001-5,000 employees
Contact me