Remote job
Software Engineer - Infrastructure Security
Job details
About this role
Role overview This role sits on an infrastructure security team that treats itself as a platform engineering group with a security mandate. The mission is to give product engineers trustworthy primitives for service-to-service authentication and authorization, abstracting the hard parts away so that the secure path is also the easy path. Work centers on workload identity, short-lived credentials, and a unified authorization layer across internal applications and their dependencies.
Responsibilities - Build workload identity infrastructure so short-lived credentials become a default part of every application's runtime, partnering closely with application platform owners. - Roll out identity-based authentication to major internal services, supporting identity certificates, defining the golden path for newly onboarding applications, and driving migration of existing services off older mechanisms. - Replace static passwords and long-lived service tokens with short-lived identity credentials, including identity-authenticated egress proxies and managed-secret API abstractions for external dependencies that still require them. - Design and ship a single authorization interface and framework so that policies can be defined centrally and enforced consistently across the company. - Drive cross-team adoption of new platform capabilities, including leading large-scale migrations and retiring legacy patterns. - Use AI-assisted tooling and automation to reduce operational toil and scale platform work.
Requirements - Five or more years of software engineering experience with a focus on security-related platform, infrastructure, or distributed systems. - Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems. - Hands-on familiarity with the Kubernetes ecosystem and authentication or authorization technologies such as JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA. - Track record of building and operating production infrastructure that other teams depend on, with deliberate attention to availability and failure modes. - Demonstrated ability to drive adoption of platform capabilities across many teams or lead large migrations. - Comfort reasoning about bootstrapping, circular dependencies, and failure modes in infrastructure that everything else relies on.
Benefits and work setup - Fully remote working arrangements with paid time off, parental leave, and a focus on personal and familial well-being. - Healthcare coverage including medical, dental, and vision, plus FSA, short- and long-term disability, voluntary life, and fertility benefits. - Competitive equity, a 401(k) with matching, and unlimited paid time off for vacation plus ten holidays and unlimited sick leave. - Twelve weeks of fully paid parental leave. - Monthly stipends for fitness and wellness activities, commuter benefits for hybrid employees in San Francisco and New York, and generous usage of internal AI tokens.