Staff Principal Software Engineer Infrastructure Security
You will set technical direction for cloud, identity, and build-runtime security; design workload identity, least-privilege IAM, network segmentation, secrets management, and production-access guardrails; harden the software supply chain; and mentor engineers on security practices.
Responsibilities
- Set technical direction for cloud, identity, and build/runtime security
- Design and ship workload identity guardrails
- Implement least-privilege IAM
- Implement network segmentation
- Manage secrets and production access
- Harden the software supply chain from developer laptop to production deployment
- Partner with Platform, SRE, and applications platform stakeholders
- Mentor engineers across the organization
- Raise the security standard by default
Requirements
- 8+ years of experience in infrastructure or cloud security
- At least 3 years at staff or principal level
- Deep expertise in GCP, AWS, and Cloudflare security primitives
- Experience with IAM, network security, KMS, workload identity, and edge security
- Hands-on experience with Kubernetes, Terraform, Wiz, GitHub Actions, and CI/CD
- Knowledge of supply-chain security, including SLSA, Sigstore, and SBOMs
- Ability to write Go, Python, or Rust
- Track record of reducing security blast radius at a high-growth company
- Bonus: experience securing multi-tenant platforms or LLM/agent-driven infrastructure
- Application must be submitted in English