Senior Software Engineer - Security - Elasticsearch

Elastic $133.1K - $210.6K/year Posted 3 days ago

100% remote US only · US (remote)

About the role

Elastic is seeking a Senior Software Engineer to join the Elasticsearch Security team. You will contribute to the architecture and design of Elasticsearch's main security features, including authentication, authorization, and tenant isolation, working with engineering and product leaders to provide high-performance security at all levels and ensure the distributed data store has top-quality security at scale.

Responsibilities

  • Contribute to core security initiatives from architecture to production, focusing on delivery of new critical features, and participate in the technical design, planning, and execution of major security components inside the Elasticsearch core engine.
  • Develop the foundational security models for features, and optimize security performance at scale in distributed systems environments.
  • Apply cryptographic solutions to genuine customer use cases, and ensure robust data isolation within shared infrastructure supporting disparate customers.
  • Monitor and apply the latest advancements in security across authentication, identity management, cryptography, and data access management.
  • Collaborate with peers across the company to embed security into new customer features from the outset.
  • Drive vulnerability management with the InfoSec team, and leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation.

Qualifications

  • Deep knowledge of Java internals and JVM memory management, with the ability to write high-performance, thread-safe, lock-free code in large open-source and enterprise codebases.
  • Experience building authorization systems that scale under high concurrency and large permission sets: designing access models, validating credentials and tokens at scale, and keeping authorization decisions consistent across a distributed system.
  • Solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation.
  • Deep knowledge of edge identity protocols (OAuth 2.0, SAML).
  • A proven track record of using AI to accelerate development, debug complex systems, and optimize code.
  • Comfortable working autonomously in a distributed team via asynchronous, direct, and transparent communication.
  • Bonus: cipher suites, TLS handshakes and PKI lifecycle management, Post-Quantum Cryptography readiness, mapping engine-level controls to FedRAMP, FIPS 140, and SOC 2, and experience inside a data store or search engine.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on Elastic's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

Elastic team? Claim this listing or ask us to remove it.