Principal Software Engineer
Digital Ocean $235.2K - $294K/year Posted 3 days ago
About the role
Join DigitalOcean's Customer Trust & Engineering organization as the technical owner of Identity & Access Management and Key Management Services. IAM and KMS are the bedrock of trust at DigitalOcean: these services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency, and securing the cryptographic material that protects every customer workload on the platform. At this level you will define what the identity and key management platforms become over the next two to three years, drive architectural strategy across multiple teams, and set the standard for how DigitalOcean thinks about identity at hyperscale.
Key Responsibilities:
- Define and drive the multi-year technical roadmap for IAM and KMS, including authentication, authorization, secrets management, and cryptographic key lifecycle across a global, multi-tenant cloud platform.
- Design high-availability, low-latency identity and key management services in Go that handle massive, sustained load across global regions with strong consistency and full auditability.
- Architect secure token exchange patterns and identity context injection for agentic AI workflows, building the IAM foundations for DigitalOcean's emerging AI/ML platform offerings.
- Design and deliver a robust multi-tenant KMS, including envelope encryption, customer-managed key patterns, and HSM-backed key material.
- Drive the evolution of the Policy Engine (Rego/OPA) to support advanced resource-level permissions, dynamic scoping, and network-aware access conditions.
- Partner with Inference, Billing, DOKS, and Platform Security teams to resolve architectural gaps that span multiple teams.
- Establish cryptographic and identity engineering standards adopted org-wide, lead design reviews for cross-cutting changes, and author RFCs that shape technical direction.
- Mentor and develop senior and mid-level engineers across IAM and adjacent teams.
Qualifications:
- 10+ years of software engineering experience, with at least 4+ years focused on Identity (AuthN/AuthZ), Key Management, or high-scale distributed systems in a cloud or IaaS environment.
- Expert-level proficiency in Go and deep experience with gRPC microservices architecture.
- Deep knowledge of identity protocols (OIDC, OAuth2, SAML, SCIM) and access control models (RBAC, ABAC, PBAC) delivered at cloud scale.
- Hands-on experience designing or operating key management infrastructure, including envelope encryption, HSM integration, and BYOK/CMEK patterns.
- Proven ability to build systems that handle consensus, replication, and partitioning at scale, plus deep experience with Kubernetes, SQL (MySQL), and Terraform.
- Nice to have: SPIFFE/SPIRE or workload identity federation, secrets management platforms like HashiCorp Vault, and open-source identity or cryptography contributions.
Skills
How to apply
Apply directly on the employer's application page. Your application goes straight to them.
Republished listing
This opportunity was discovered on Digital Ocean's public careers page and is republished here for discovery purposes. Applications are handled by the employer.
Digital Ocean team? Claim this listing or ask us to remove it.