Skip to main content
DDN

Staff Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff-level security architect/engineer with 12+ years in security architecture, infrastructure security, or distributed systems. Needs deep distributed storage security expertise, cryptography/KMS, IAM, RBAC/ABAC, SSO/MFA/federation, LDAP/Active Directory/OIDC, TLS/mTLS, secure APIs, and multi-tenant isolation. Remote role limited to California.

Core skills

IAMSecurity ArchitectureDistributed Storage Security

Required skills

S3POSIXKV cacheSSDLCLDAPActive DirectoryOIDCKeycloakSSOMFARBACABACKMSKMIPTLS 1.3mutual TLSSigV4SIEM

Optional skills

NFSBYOKSOC 2ISO 27001NISTFedRAMP

What you'll do

  • Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.
  • Partner with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.
  • Lead threat modeling, security reviews, and Secure Software Development Lifecycle practices across the platform.
  • Define identity and access management integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.
  • Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.
  • Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.
  • Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.
  • Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.
  • Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies.
  • Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.
  • Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.
  • Define and drive security architecture across data path, control plane, and protocol layers of distributed storage systems.
  • Partner with engineering teams to embed security into S3, POSIX, and KV cache data services.
  • Build scalable encryption, identity, and access control frameworks for multi-tenant environments.
  • Strengthen tenant isolation, auditability, and compliance across the platform.
  • Ensure secure integration across ecosystem components and external services.
  • Lead cross-team security initiatives that influence system design, implementation, and long-term platform evolution.

What they require

  • Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.
  • 12+ years of experience in security architecture, infrastructure security, or distributed systems.
  • Proven experience designing security for large-scale distributed systems or storage platforms.
  • Strong understanding of data path vs. control plane architectures and their security implications.
  • Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.
  • Experience integrating with external KMS solutions using KMIP or similar protocols.
  • Strong knowledge of identity and access management, including RBAC, ABAC, SSO, MFA, and federation.
  • Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.
  • Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms such as SigV4.
  • Experience designing multi-tenant systems with strong isolation and policy enforcement.
  • Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.
  • Ability to collaborate effectively with protocol, storage, and platform engineering teams.
  • Preferred: Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.
  • Preferred: Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.
  • Preferred: Hands-on experience with BYOK models and tenant-scoped key management.
  • Preferred: Experience implementing ABAC using metadata, tags, and classification attributes.
  • Preferred: Background in zero trust architecture and distributed system security design.
  • Preferred: Experience with secure deletion techniques, including cryptographic erasure.
  • Preferred: Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.
  • Preferred: Experience designing security for high-performance, low-latency distributed systems.
  • Preferred: Familiarity with anomaly detection, security analytics, and alerting systems.

DDN

DDN is positioned as NVIDIA’s storage and data intelligence partner for AI factories and the NVIDIA AI Data Platform.

Data Storageddnet.org/

What people say about this company

4.0/ 5

Details

Apply routeDom
Salary not disclosed