Skip to main content
Temporal

Staff Cloud Security Engineer

RemoteUnited States, Canada only
Published
Role
Security
Experience
Staff
Employment
Full-time
$225k–$275k/yr
Check eligibility

Open to US, CA only. Set where you work from to check your eligibility.

No BS summary

Staff-level cloud security engineer to secure a multi-cloud SaaS platform. Must have 5+ years in cloud security, strong Kubernetes and multi-tenant architecture experience, and proficiency in Go. Remote for US or Canada applicants only.

Core skills

KubernetesgRPCCloud security

Required skills

AWSGCPAzureRBACadmission controlmTLSIstioEnvoyHashiCorp VaultAWS Secrets ManagerGoPythonWiz

Optional skills

TemporalCadenceFedRAMPSOC 2 Type IIISO 27001AppSec

What you'll do

  • Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others).
  • Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems.
  • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries.
  • Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.
  • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.
  • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy.
  • Help shape how we use AI responsibly in both infrastructure and engineering processes.
  • Participate in on-call rotation.

What they require

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
  • 5+ years in cloud security or a related role.
  • Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.
  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
  • Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
  • Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc).
  • A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages.
  • Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
  • Proficiency in Go; familiarity with Python.
  • Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).
  • Excellent communication and ability to explain complex security concepts to non-technical stakeholders.
  • Excellent collaboration and communication skills.
  • Able to participate in on-call rotation.
  • Preferred: Prior experience with Temporal, Cadence, or similar workflow orchestration platforms and an understanding of workflow history, replay semantics, and scheduling internals.
  • Preferred: FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.
  • Preferred: Open Source automation or automation projects.
  • Preferred: Expertise in other areas of security (AppSec, CorpSec, GRC).
  • Preferred: Security conference talks or published research.

Benefits

  • This role is eligible to participate in Temporal's equity plan.
  • Unlimited PTO
  • 12 Holidays + 2 Floating Holidays
  • 100% Premiums Coverage for Medical, Dental, and Vision
  • AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
  • Empower 401K Plan
  • Additional Perks for Learning & Development, Lifestyle Spending, Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more
  • International benefits and PTO vary by country and are issued in partnership with Remote.com
  • Perks to international employees for learning & career development, a lifestyle spending account, home office setup, professional memberships, work-from-home meals, and access to the Calm app for mental wellness
  • Occasional travel may be required for company events and team offsites

Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on delivering features faster. The company is building a reliable foundation for developers' toolboxes and focuses on developer experience, open-source software, and communities.

TechnologyMid-size

What people say about this company

4.1/ 5

  • Employees enjoy a supportive work culture that encourages collaboration.
  • There are ample opportunities for professional development and career advancement.
  • Many reviews highlight the company's innovative approach to technology.
$225k–$275k/yr