Senior Software Engineer (Security - Elasticsearch)
Elastic · United States
About The Role
Join the Elasticsearch Security team as a Senior Software Engineer. In this role, you will contribute to the architecture and design of Elasticsearch's main features, including authentication, authorization, and tenant isolation. You will work with engineering and product leaders at Elastic, focusing on delivering high-performance security at all levels. Your responsibilities will include developing foundational security models, optimizing security performance, applying cryptographic solutions, and collaborating with peers across the company. You will also drive vulnerability management efforts and leverage AI-driven tools to streamline security workflows.
- Contribuer à l'architecture et à la conception des principales fonctionnalités d'Elasticsearch, y compris l'authentification, l'autorisation et l'isolation des locataires.
- Participer à la mise en œuvre des initiatives de sécurité, de l'architecture à la production, en se concentrant sur la livraison de nouvelles fonctionnalités critiques.
- Collaborer avec des pairs à travers l'entreprise pour intégrer la sécurité dans les nouvelles fonctionnalités pour les clients dès le départ.
- You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases
- You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML)
- You can work autonomously, supporting decisions and results in a distributed team by leveraging asynchronous, direct, and transparent communication
- You have experience building authorization systems that are scalable and performant under high concurrency and large permission sets, including designing access models, validating credentials/tokens at scale, and keeping authorization decisions consistent across a distributed system
- You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still collaborating on the final outcomes
- You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities
- You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance and cluster state propagation
- Cryptographic methods considering memory usage and delays
- Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management
- Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms
- Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements
- Experience working on the internals of a data store or search engine
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring