Jobiglo

No results.

Staff Software Engineer – Security Products

DigitalOcean · Bengaluru

New
🇬🇧 English
Go OIDC OAuth2 SAML SCIM RBAC ABAC PBAC cryptography CSPM ISPM Open Policy Agent Rego SPIFFE SPIRE WIMSE HSM PKCS#11 KMIP

Job description

About the role

DigitalOcean is looking for a Staff Software Engineer to lead the architecture of its Security Products portfolio, covering Identity and Access Management, Key Management, Cloud Security Posture Management and Identity Security Posture Management. You will shape the technical direction across multiple teams and ensure a coherent, secure platform for customers and AI workloads.

Key responsibilities

  • Define and own the multi‑year technical strategy for IAM, KMS, CSPM and ISPM, ensuring seamless integration across domains.
  • Lead the design of agent identity and trust architecture for non‑human workloads, including SPIFFE‑style identities and short‑lived credentials.
  • Serve as the primary technical arbitrator for cross‑team security decisions, such as binding key material to identity assertions and propagating posture signals into access policies.
  • Shape DigitalOcean’s security posture strategy, integrating CSPM and ISPM findings into adaptive authorization mechanisms.
  • Drive adoption and standardization of protocols like OIDC, SAML, SCIM, OAuth Token Exchange, KMIP, PKCS#11 and emerging post‑quantum cryptography standards.
  • Establish engineering standards for cryptography, identity protocols, policy authoring and posture evaluation across all security product teams.

Required profile

  • 10+ years of software engineering experience with at least 5 years focused on security‑critical systems.
  • Deep expertise in Go and building high‑scale, distributed services in production.
  • Strong knowledge of identity protocols (OIDC, OAuth2, SAML, SCIM) and access control models (RBAC, ABAC, PBAC).
  • Solid applied cryptography background, including symmetric/asymmetric primitives, key derivation and envelope encryption.
  • Experience designing or operating CSPM/ISPM systems and familiarity with cloud resource models and compliance frameworks (CIS Benchmarks, NIST CSF).
  • Proven ability to influence multiple engineering teams, resolve architectural conflicts and communicate strategy to executive audiences.

Required skills

  • Go programming language
  • OIDC, OAuth2, SAML, SCIM
  • RBAC, ABAC, PBAC access models
  • Symmetric and asymmetric cryptography, key derivation, envelope encryption
  • CSPM and ISPM system design
  • Cloud platforms (DigitalOcean, AWS, GCP, Azure) and compliance frameworks (CIS, NIST)
  • Open Policy Agent (OPA) and Rego
  • SPIFFE/SPIRE, WIMSE workload identity frameworks
  • Hardware Security Modules (HSM), PKCS#11, KMIP
  • Post‑quantum cryptography standards (ML‑KEM, ML‑DSA)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec DigitalOcean.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:greenhouse

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in India.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 7 hours ago

Expires 1 month from now

4 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

DigitalOcean

Bengaluru