Principal Software Engineer (Java) - Security - Elasticsearch
Principal Software Engineer (Java) - Security - Elasticsearch
Requirements
You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases.
You have proven experience in designing and building systems for authorization that can scale. This includes deep experience designing scalable RBAC/ABAC models and token validation pipelines. It includes permission compilation and distributed cache invalidation strategies.
You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation.
You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML).
You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still owning the final outcomes.
You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities
You can work autonomously, drive decisions, and lead a distributed team by leveraging asynchronous, direct, and transparent communication.
What You'll Be Doing
Owning core security initiatives from architecture to production, focusing on the delivery of new critical features. Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine.
Developing the foundational security models for intricate features.
Optimizing security performance at scale in distributed systems environments.
Applying cryptographic solutions to address genuine customer use cases.
Ensuring robust data isolation within shared infrastructure supporting disparate customers.
Monitoring and applying the latest advancements and best practices in security. This includes authentication, identity management, cryptography, and data access management.
Collaborating with peers across the company to embed security into new customer features from the outset.
Drive vulnerability management efforts by collaborating closely with the InfoSec team to proactively identify, assess, and remediate security risks.
Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation, streamlining security workflows and reducing manual intervention.
Mentoring and coaching other engineers, fostering a culture of technical excellence and security-first development.
Bonus Points
Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
Cryptographic methods considering memory usage and delays.
Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
Experience working on the internals of a data store or search engine.
Perks and Benefits
Competitive pay based on the work you do here and not your previous salary
Health coverage for you and your family in many locations
Ability to craft your calendar with flexible locations and schedules for many roles
Generous number of vacation days each year
Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
Up to 40 hours each year to use toward volunteer projects you love
Embracing parenthood with a minimum of 16 weeks of parental leave