Skip to main content
Elastic

Principal Software Engineer - Security - Elasticsearch

RemoteUnited States only· except Belarus, Cuba, Iran +3 more
Published
Role
Security
Experience
Principal
Employment
Full-time
Company size
Enterprise
$159.8k–$252.8k/yr
Check eligibility

Open to US only · except BY, CU, IR, KP, SY, RU. Set where you work from to check your eligibility.

No BS summary

Principal Java/JVM engineer for Elasticsearch security, focused on authentication, authorization, tenant isolation, and distributed systems security. Must have deep Java internals/JVM memory knowledge, scalable authorization/RBAC/ABAC experience, OAuth 2.0/SAML, and experience using AI tools in development. US role with export-control restrictions for sanctioned countries/regions.

Core skills

JavaElasticsearchDistributed systems security

Required skills

JVMRBACABACOAuth 2.0SAMLAI tools

Optional skills

TLSPKIPost-Quantum CryptographyFedRAMPFIPS 140SOC 2

What you'll do

  • Lead the architecture and design of Elasticsearch security features including authentication, authorization, and tenant isolation
  • Provide high-performance security at all levels for a distributed data store at scale
  • Own core security initiatives from architecture to production, focusing on delivery of new critical features
  • Lead the technical design, plan, and execution for major security components inside the Elasticsearch core engine
  • Develop foundational security models for intricate features
  • Optimize security performance at scale in distributed systems environments
  • Apply cryptographic solutions to address genuine customer use cases
  • Ensure robust data isolation within shared infrastructure supporting disparate customers
  • Monitor and apply the latest advancements and best practices in security, including authentication, identity management, cryptography, and data access management
  • Collaborate with peers across the company to embed security into new customer features from the outset
  • Drive vulnerability management efforts by collaborating with the InfoSec team to proactively identify, assess, and remediate security risks
  • Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation
  • Mentor and coach other engineers, fostering technical excellence and security-first development

What they require

  • Deep knowledge of Java internals and JVM memory management
  • Understanding of concurrency models
  • Ability to write high-performance, thread-safe, and lock-free code
  • Experience working with large open-source and enterprise codebases
  • Proven experience designing and building scalable authorization systems
  • Deep experience designing scalable RBAC/ABAC models and token validation pipelines
  • Experience with permission compilation and distributed cache invalidation strategies
  • Solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation
  • Deep knowledge of edge identity protocols including OAuth 2.0 and SAML
  • Proven track record of using AI to accelerate development, debug complex systems, and optimize code while owning final outcomes
  • Ability to collaborate across functions and teams and transition between different projects, codebases, or teams based on business priorities
  • Ability to work autonomously, drive decisions, and lead a distributed team using asynchronous, direct, and transparent communication
  • Preferred: Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management
  • Preferred: Knowledge of cryptographic methods considering memory usage and delays
  • Preferred: Familiarity with Post-Quantum Cryptography implications and readiness to support migration to quantum-resistant cryptographic algorithms
  • Preferred: Hands-on experience mapping engine-level technical controls to FedRAMP Moderate/High, FIPS 140, and SOC 2 requirements
  • Preferred: Experience working on the internals of a data store or search engine

Benefits

  • Eligible to participate in Elastic's stock program
  • Company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings
  • Total rewards package with emphasis on employee well-being
  • Competitive pay based on the work done at Elastic and not previous salary
  • Health coverage for employee and family in many locations
  • Flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Donation and service matching up to $2000 or local currency equivalent
  • Up to 40 hours each year for volunteer projects
  • Minimum of 16 weeks of parental leave

distributed, scalable, and highly available real-time search platform with a RESTful API

TechnologyEnterpriseelastic.co/elasticsearch/

What people say about this company

3.8/ 5

Details

Apply routeDom
$159.8k–$252.8k/yr