Staff Software Engineer-Security Products

DigitalOcean

Bengaluru

On-site

INR 4,200,000 - 6,400,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity compensation
Bonus program

Job summary

DigitalOcean is seeking a Staff Software Engineer (IC5) to lead Security Products across IAM, KMS, CSPM, and ISPM from Bengaluru, India. You will set multi-year architecture, foster cross-domain integration, and mentor engineers in security-first design.

You will own the identity for non-human workloads, manage trust for agent systems, and shape enforcement policies across posture and access controls. This is a high-impact role at scale.

Qualifications

  • Over 10 years of software engineering experience, with 5+ years in security-critical systems.
  • Expert-level Go language production experience.
  • Strong knowledge of identity protocols (OIDC, OAuth2, SAML, SCIM) and access models (RBAC/ABAC/PBAC).

Responsibilities

  • Define multi-year security products architecture across IAM, KMS, CSPM, and ISPM.
  • Lead identity for non-human workloads, including agent identity and trust.
  • Resolve cross-team security platform decisions spanning domains.
  • Shape posture strategy and adopt security standards across the platform.

Skills

Go
Security architecture
Cloud security
Distributed systems
Cross-domain integration

Tools

SPIFFE/SPIRE
Open Policy Agent (OPA)
WIMSE
KMIP
PKCS#11
HSMs

Job description

Job Description:

Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.

We are seeking aStaff Software Engineer (IC5) to join our Security Products team, spanning Identity and Access Management (IAM), Key Management Systems (KMS), Cloud Security Posture Management (CSPM), and Identity Security Posture Management (ISPM). Security Products is the trust layer for DigitalOceans platform — the systems you will influence protect every customer workload, every cryptographic key, every identity assertion, and every access decision made across the platform, including our rapidly growing AI inference stack.

This is not a role scoped to a single product or team. As a Staff Engineer in Security Products, you will set the technical direction across the entire security products organization, resolve architectural conflicts that no individual team can resolve alone, and build the connective tissue between identity, key management, and posture systems that makes DigitalOceans security platform coherent rather than fragmented. You will be the primary technical partner to the Sr. Director of Security Products in shaping multi-year strategy, and you will be the engineering voice representing security architecture in DigitalOceans most consequential platform decisions.If you are a seasoned security engineer with a track record of technical leadership that spans organizational boundaries — and who wants to define what a modern cloud security platform looks like for the AI-native era — this is the role for you.

What Youll Do
  • Define Security Products Architecture: Own the multi-year technical strategy across IAM, KMS, CSPM, and ISPM — ensuring these systems compose coherently rather than operating as isolated products. Identify the seams where identity, key management, and posture signal must integrate, and drive the architectural decisions that close them.
  • Lead the Agent Identity & Trust Architecture: Define how DigitalOceans platform establishes, validates, and governs identity for non-human workloads — including agentic AI systems, inference pipelines, and service-to-service trust. This spans SPIFFE/SPIRE-style workload identity, short-lived credential issuance, scoped JWT attestation, and the policy engine that governs what agents are permitted to do and access.
  • Own Cross-Domain Security Platform Decisions: Serve as the primary technical arbitrator for decisions that span more than one Security Products team — including how key material is bound to identity assertions, how CSPM findings feed into access policy enforcement, how ISPM risk signals propagate into real-time authorization decisions, and how audit evidence flows across all four domains in a compliance-coherent way.
  • Shape DigitalOceans Security Posture Strategy: Define the technical architecture for how DigitalOcean discovers, evaluates, and remediates posture risk across its platform — spanning CSPM (misconfigured infrastructure) and ISPM (over-privileged identities, orphaned credentials, policy drift). Drive the integration of posture signal into identity and access enforcement so that policy is adaptive, not static.
  • Drive Protocol and Standards Adoption: Own the technical strategy for security standards adoption across the platform — evaluating and standardizing on OIDC, SAML, SCIM, WIMSE, OAuth Token Exchange, KMIP, PKCS#11, and emerging NIST PQC standards. Represent DigitalOceans technical interests in external standards conversations where relevant.
  • Establish Engineering Standards Across Security Products: Define and socialize cryptographic engineering practices, identity protocol patterns, policy authoring standards, and posture evaluation frameworks — raising the engineering floor across all Security Products teams and influencing the broader DO engineering organization.
  • Partner with Compliance and Executive Leadership: Translate security platform architecture into compliance posture and business impact for CISO, CPTO, and board-level audiences. Own the technical framing for HIPAA Covered Product expansion, SOC 2 control engineering, and emerging regulatory requirements as they intersect with identity and key management.
  • Mentor and Multiply: Coach IC3 and IC4 engineers across Security Products teams on system design, security engineering rigor, and cross-functional technical communication. Act as a technical multiplier — raising the capability of the organization, not just delivering individually.
What Youll Add to DigitalOcean
  • Experience: 10+ years of software engineering experience, with 5+ years of sustained focus on security-critical systems — spanning at least two of: Identity/IAM, cryptographic systems/KMS, cloud security posture, or infrastructure security — at cloud or enterprise scale.
  • Language Expert: Expert-level proficiency in Go, with deep experience building and operating security-critical, high-scale distributed services in production.
  • Identity Authority: Deep knowledge of identity protocols (OIDC, OAuth2, SAML, SCIM) and access control models (RBAC, ABAC, PBAC); able to design novel identity systems — including workload and agent identity — not just implement existing patterns.
  • Cryptography Authority: Sound applied cryptography fundamentals — symmetric and asymmetric primitives, key derivation hierarchies, authenticated encryption, envelope encryption patterns — and a track record of designing cryptographic systems correctly under real operational constraints.
  • Posture Systems: Experience designing or operating CSPM or ISPM systems — including resource discovery, policy evaluation at scale, misconfiguration detection, and risk signal aggregation. Familiarity with cloud resource models (DigitalOcean, AWS, GCP, or Azure) and the control frameworks that govern them (CIS Benchmarks, NIST CSF, or equivalent).
  • Cross-Domain Integration: Demonstrated ability to design systems where identity, key management, and posture signals compose — rather than operating in isolation. Candidates who have worked at the intersection of two or more of these domains are strongly preferred.
  • Distributed Systems Mastery: Proven ability to design and operate systems at cloud scale — handling consensus, replication, partitioning, and failure recovery under real production conditions — with security and auditability as first-class constraints.
  • Organizational Influence: Track record of driving technical alignment across multiple engineering teams or organizations — including resolving architectural conflicts, establishing cross-team standards, and influencing roadmaps beyond your direct area of ownership.
  • Communication: Demonstrated ability to translate complex security platform strategy into business impact and compliance posture for executive and board-level audiences.
Nice to Have
  • Experience with Open Policy Agent (OPA), Rego, or other policy-as-code frameworks at production scale.
  • Familiarity with SPIFFE/SPIRE, WIMSE, or other workload identity frameworks.
  • Experience with HSMs (Thales/Luna, AWS CloudHSM, or equivalent) and production-grade key management platforms.
  • Familiarity with post-quantum cryptography standards (NIST PQC: ML-KEM, ML-DSA) and migration planning for production key hierarchies.
  • Experience with PKCS#11, KMIP, or other KMS/HSM interoperability standards.
  • Background contributing to open-source security projects or engaging with standards bodies (IETF, OpenID Foundation, NIST).
  • Prior experience designing security platform strategy for AI-native or inference-heavy workloads.
  • Background supporting HIPAA, SOC 2, ISO 27001, or FedRAMP compliance programs from an engineering ownership perspective.

*This job is located in Bengaluru, India

JR: 2026-7959

#LI-Hybrid

Why You’ll Like Working for DigitalOcean
  • We innovate with purpose. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
  • We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learnings 10,000+ courses to support their continued growth and development.
  • We care about your well-being.Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
  • We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
  • DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

Requirements:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer II - Identity & Access Management
Senior Software Engineer II - Identity & Access Management

DigitalOcean • Bengaluru

On-site
INR 4,200,000 - 6,800,000
Equity
Bonus potential
Flexible time off
Director, Security Products
Director, Security Products

DigitalOcean • Bengaluru

On-site
INR 2,800,000 - 3,500,000
Competitive benefits package
Career development resources
Employee Stock Purchase Program
Software Engineer II - Identity & Access Management
Software Engineer II - Identity & Access Management

DigitalOcean • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Software Engineer I - Key Management Systems
Senior Software Engineer I - Key Management Systems

DigitalOcean • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Equity compensation
Employee Stock Purchase Program
Flexible time off
Senior Infrastructure Security Engineer
Senior Infrastructure Security Engineer

DigitalOcean • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Equity compensation
Bonus program
Employee Stock Purchase Program
+2
Software Engineer II - Key Management Systems
Software Engineer II - Key Management Systems

DigitalOcean • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Senior Application Security Engineer I, Security Platform
Senior Application Security Engineer I, Security Platform

DigitalOcean • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Career development resources
Flexible time off policy
Access to LinkedIn Learning courses
+1
Senior Software Engineer I - User & Accounts Systems
Senior Software Engineer I - User & Accounts Systems

DigitalOcean • Bengaluru

Hybrid
INR 3,500,000 - 7,000,000
Senior Software Engineer II - User & Accounts Systems
Senior Software Engineer II - User & Accounts Systems

Digitalocean • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Equity compensation
Bonus opportunities
Senior Software Engineer I - Identity & Access Management
Senior Software Engineer I - Identity & Access Management

Digitalocean • Bengaluru

On-site
INR 1,500,000 - 3,000,000