Skip to content
← Back to job listings

Principal Software Engineer (Security - Elasticsearch)

Elastic · United States

External listingfull-time7 days ago

About The Role

Join Elastic as a Principal Software Engineer in the Elasticsearch Security team. You will lead the architecture and design of key security features, optimize security performance, and collaborate with various teams to embed security into new customer features. You will also mentor and coach other engineers, fostering a culture of technical excellence and security-first development. Enjoy benefits such as fully paid health coverage, flexible location and schedule, generous vacation days, parental leave, volunteer time off, and charitable donation matching.

  • Lead the architecture and design of Elasticsearch's main security features, including authentication, authorization, and tenant isolation.
  • Own core security initiatives from architecture to production, focusing on the delivery of new critical features and leading the technical design.
  • Collaborate with peers across the company to embed security into new customer features from the outset and drive vulnerability management efforts.
  • You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases
  • You can work autonomously, drive decisions, and lead a distributed team by leveraging asynchronous, direct, and transparent communication
  • You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities
  • You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML)
  • You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation
  • You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still owning the final outcomes
  • You have proven experience in designing and building systems for authorization that can scale. This includes deep experience designing scalable RBAC/ABAC models and token validation pipelines. It includes permission compilation and distributed cache invalidation strategies
  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management
  • Cryptographic methods considering memory usage and delays
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms
  • Experience working on the internals of a data store or search engine
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements

This is an external listing. JobSpring does not represent or verify the employer. Report this listing