DDN
Lead Engineer – Security Architecture
Remote - California · Principal
Sponsorship not specifiedDetected 6 days ago
Distributed SystemsLinuxPlatform EngineeringAPI DevelopmentRESTMachine LearningCybersecuritySIEMComplianceDesign SystemsAuditingZero TrustLeadershipMentoring
About the role
- You will influence long-term architectural direction, establish foundational security standards, and guide implementation across globally distributed engineering organizations.
Responsibilities
- Define and lead the long-term security architecture strategy for distributed storage platforms, including S3-compatible object storage, POSIX/NFS file systems, and KV cache-based data services.
- Establish security architecture standards and secure-by-design principles across data path, control plane, orchestration, and protocol layers.
- Partner with Data Path engineering teams to secure high-performance data movement across storage tiers, including encryption, integrity verification, secure I/O handling, and low-latency protection mechanisms.
- Drive security architecture reviews, threat modeling, and Secure Software Development Lifecycle (SSDLC) practices across platform engineering initiatives.
- Design and govern fine-grained authorization systems leveraging RBAC, ABAC, metadata-aware policy enforcement, and tenant-scoped access controls.
- Collaborate with Control Plane engineering teams to design secure APIs, authentication workflows, policy orchestration, tenant lifecycle management, and platform governance controls.
- Partner with Protocol and Ecosystem teams to secure S3, POSIX/NFS, and related interfaces, including request signing, session security, endpoint hardening, and protocol-level protections.
- Lead platform-wide encryption and key management strategies for data at rest and in transit, including BYOK, tenant-scoped keys, dataset-level encryption policies, KMIP integration, and external KMS interoperability.
- Drive adoption of Zero Trust security principles across distributed systems and infrastructure components.
- Represent security architecture initiatives in executive, customer, compliance, and strategic partner discussions as needed.
Requirements
- Bachelor's or Master's degree in Computer Science, Engineering, Cybersecurity, or a related technical field.
- 12+ years of experience in security architecture, distributed systems security, infrastructure security, or large-scale platform engineering.
- Proven track record designing and securing large-scale distributed systems, storage platforms, or cloud-native infrastructure.
- Extensive expertise in cryptography, encryption frameworks, secure key management systems, and PKI architectures.
- Advanced knowledge of IAM frameworks, including RBAC, ABAC, SSO, MFA, federation, delegated authorization, and policy-driven access control systems.
- Experience integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and SAML-based systems.
- Experience designing secure multi-tenant platforms with strong isolation, governance, and policy enforcement mechanisms.
- Strong understanding of security observability, logging, auditability, SIEM integration, and compliance-driven monitoring architectures.
Nice to have
- Experience securing S3-compatible object storage, POSIX/NFS file systems, or high-performance distributed storage environments.
- Familiarity with AI/ML infrastructure security, KV cache architectures, memory tiering systems, and GPU-centric distributed environments.
- Experience integrating and managing security solutions across large-scale infrastructure platforms, including cloud, network, and application security domains.
- Hands-on experience with BYOK architectures, tenant-scoped key management, and cryptographic isolation models.
- Experience implementing ABAC using metadata classification, tagging, and contextual policy evaluation.
- Strong background in Zero Trust architecture and distributed systems security engineering.
- Knowledge of secure deletion techniques, including cryptographic erasure and secure lifecycle management.
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST, FedRAMP, and enterprise security governance standards.
This listing is sourced directly from DDN's careers page and normalized into a canonical job model.