Lead Engineer – Security Architecture

Data Direct Networks

California (MO)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Vacation plans
Paid holidays
Bonus programs
Tuition reimbursement
Employee referral program
Medical, dental & vision benefits
Paid leave programs
Anniversary & recognition awards

Job summary

Data Direct Networks is seeking a Lead Engineer – Security Architecture to define and drive security for next‑gen distributed storage platforms, including S3-like object storage, POSIX/NFS file systems, and KV data services.

You will partner with storage, protocol, and platform teams to embed secure-by-design practices, establish security standards, and guide cross‑functional engineering in implementing advanced security measures at scale.

Qualifications

  • 12+ years of experience in security architecture or large-scale platform engineering.
  • Proven track record securing distributed storage or cloud-native infrastructure.
  • Deep understanding of cryptography, PKI and key management.
  • Experience integrating enterprise identity providers (LDAP, AD, OIDC, SAML).
  • Strong knowledge of secure API design, TLS, SigV4, and service authentication.

Responsibilities

  • Define and lead long-term security architecture for distributed storage platforms.
  • Establish secure-by-design principles across data path, control plane, and protocols.
  • Lead threat modeling, SSDLC practices, and security reviews across teams.
  • Design enterprise IAM frameworks with RBAC/ABAC and tenant isolation.
  • Collaborate to secure APIs, authentication workflows, and governance controls.

Skills

Distributed systems security
Security architecture
Advanced cryptography
IAM (Identity and Access Management)
Zero Trust

Education

Bachelor’s or Master’s degree in Computer Science or related field

Tools

KMIP/KMS integrations

Job description

We are on our way to being the first company to power 1 MILLION GPUs and want world-class talent to join our amazing team!

The world is moving faster than ever, and yet, it will never move this slowly again. We are at the forefront of an incredible technological revolution but, at its core, it is fueled by incredible people. People like you.

1,000 Global Employees

11k Happy Customers

16 International Offices

We’re Looking for the Best and Brightest

We are the world’s leading data intelligence platform that reliably accelerates massive datasets for actionable real‑time insights. Join our team to help the best and brightest minds tackle the world’s biggest challenges in business, science, medicine, academia and government.

Do What Can’t be Done

For the past 20 years, our team has kept us at the forefront of storage technology and has provided the foundation for enabling researchers to push the limits of “what can be done.”
These innovations take research and discovery to the next level, enabling them to discover cures to disease, observe global warming patterns, model innovative automotive and aerospace designs, discover new sources of energy, make communities safer, and accelerate business results across a wide variety of industries.

DDN Helps Build Your Future, Too

At DDN, we understand our customers’ diverse needs. Whether you’re a data scientist, IT professional, executive, or researcher, our solutions empower you with cutting‑edge technology and unparalleled support.

Highly Competitive Vacation Plans

Paid Holidays

Bonus Programs

Tuition Reimbursement

Employee Referral Program

Excellent Medical, Dental and Vision Benefits

Paid Leave Programs

Anniversary and Recognition Awards

Lead Engineer – Security Architecture
Location
Employment Type

Full time

Location Type

On-site

DDN is seeking a highly accomplished Principal Engineer – Security Architecture to define and drive the security strategy for next‑generation distributed storage platforms spanning S3‑compatible object storage, POSIX‑compliant file systems, and KV cache–based data services. This role is responsible for architecting secure‑by‑design systems across the data path, control plane, and ecosystem/protocol layers that power high‑performance, multi‑tenant, AI‑driven infrastructure at massive scale.

As a senior technical leader, you will partner closely with storage architects, protocol engineers, platform teams, and security stakeholders to embed advanced security principles into every layer of the platform lifecycle. You will influence long‑term architectural direction, establish foundational security standards, and guide implementation across globally distributed engineering organizations.

The ideal candidate combines deep expertise in distributed systems security, cryptography, identity and access management, multi‑tenant architectures, and infrastructure security with the ability to drive cross‑functional technical strategy and execution.

Key Responsibilities

Define and lead the long‑term security architecture strategy for distributed storage platforms, including S3‑compatible object storage, POSIX/NFS file systems, and KV cache–based data services.

Establish security architecture standards and secure‑by‑design principles across data path, control plane, orchestration, and protocol layers.

Partner with Data Path engineering teams to secure high‑performance data movement across storage tiers, including encryption, integrity verification, secure I/O handling, and low‑latency protection mechanisms.

Drive security architecture reviews, threat modeling, and Secure Software Development Lifecycle (SSDLC) practices across platform engineering initiatives.

Architect enterprise‑grade Identity and Access Management (IAM) frameworks integrating LDAP, Active Directory, OIDC, Keycloak, SSO, MFA, federation, and delegated authorization models.

Design and govern fine‑grained authorization systems leveraging RBAC, ABAC, metadata‑aware policy enforcement, and tenant‑scoped access controls.

Define scalable multi‑tenant isolation architectures across namespaces, encryption boundaries, policies, quotas, and workload segregation domains while enforcing least privilege principles.

Collaborate with Control Plane engineering teams to design secure APIs, authentication workflows, policy orchestration, tenant lifecycle management, and platform governance controls.

Partner with Protocol and Ecosystem teams to secure S3, POSIX/NFS, and related interfaces, including request signing, session security, endpoint hardening, and protocol‑level protections.

Lead platform‑wide encryption and key management strategies for data at rest and in transit, including BYOK, tenant‑scoped keys, dataset‑level encryption policies, KMIP integration, and external KMS interoperability.

Define observability, telemetry, logging, auditing, and anomaly detection strategies to identify abnormal behavior, insider threats, and potential data exfiltration risks.

Drive adoption of Zero Trust security principles across distributed systems and infrastructure components.

Provide technical leadership, mentorship, and architectural guidance across cross‑functional engineering teams, influencing secure implementation practices and platform evolution.

Represent security architecture initiatives in executive, customer, compliance, and strategic partner discussions as needed.

Required Qualifications

Bachelor’s or Master’s degree in Computer Science, Engineering, Cybersecurity, or a related technical field.

12+ years of experience in security architecture, distributed systems security, infrastructure security, or large‑scale platform engineering.

Proven track record designing and securing large‑scale distributed systems, storage platforms, or cloud‑native infrastructure.

Deep understanding of distributed system architectures, including data path and control plane security models.

Extensive expertise in cryptography, encryption frameworks, secure key management systems, and PKI architectures.

Strong experience integrating external KMS platforms using KMIP or equivalent protocols.

Advanced knowledge of IAM frameworks, including RBAC, ABAC, SSO, MFA, federation, delegated authorization, and policy‑driven access control systems.

Experience integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and SAML‑based systems.

Expertise in secure API design, TLS 1.3, mutual TLS, request signing mechanisms (e.g., SigV4), and service‑to‑service authentication models.

Experience designing secure multi‑tenant platforms with strong isolation, governance, and policy enforcement mechanisms.

Strong understanding of security observability, logging, auditability, SIEM integration, and compliance‑driven monitoring architectures.

Demonstrated ability to influence technical direction and drive cross‑functional architectural initiatives across engineering organizations.

Preferred Qualifications

Experience securing S3‑compatible object storage, POSIX/NFS file systems, or high‑performance distributed storage environments.

Familiarity with AI/ML infrastructure security, KV cache architectures, memory tiering systems, and GPU‑centric distributed environments.

Experience integrating and managing security solutions across large‑scale infrastructure platforms, including cloud, network, and application security domains.

Hands‑on experience with BYOK architectures, tenant‑scoped key management, and cryptographic isolation models.

Experience implementing ABAC using metadata classification, tagging, and contextual policy evaluation.

Strong background in Zero Trust architecture and distributed systems security engineering.

Knowledge of secure deletion techniques, including cryptographic erasure and secure lifecycle management.

Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST, FedRAMP, and enterprise security governance standards.

Experience designing security controls for high‑throughput, low‑latency distributed systems.

Familiarity with anomaly detection, behavioral analytics, and advanced security telemetry platforms.

Experience with Linux systems, scripting, automation, DevSecOps workflows, and infrastructure security tooling.

We pride ourselves on our commitment to delivering tangible and consistent results.

Let’s Forge a Better Future, Together

Explore our current job openings and find the perfect opportunity to advance your career with a company that values expertise, creativity and growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Engineer – Security Architecture
Lead Engineer – Security Architecture

DDN • Sacramento (CA)

On-site
USD 220,000 - 300,000
Staff Security Engineer
Staff Security Engineer

DDN • Sacramento (CA)

On-site
USD 180,000 - 240,000
Staff Security Engineer
Staff Security Engineer

Data Direct Networks • California (MO)

On-site
USD 190,000 - 240,000
Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
+5
Senior Staff Storage Engineer
Senior Staff Storage Engineer

Data Direct Networks • California (MO), Northern (KY)

Hybrid
USD 170,000 - 240,000
Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
+5
Sr Staff Engineer
Sr Staff Engineer

Data Direct Networks • California (MO)

On-site
USD 180,000 - 260,000
Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
+5
Senior Staff Engineer
Senior Staff Engineer

Data Direct Networks • North Carolina

Hybrid
USD 225,000 - 275,000
Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
+5
Senior Security Architect for Distributed Storage Platforms
Senior Security Architect for Distributed Storage Platforms

Data Direct Networks • California (MO)

On-site
USD 180,000 - 240,000
Vacation plans
Paid holidays
Bonus programs
+5
Senior Security Architect: Distributed Storage & IAM
Senior Security Architect: Distributed Storage & IAM

DDN • Sacramento (CA)

On-site
USD 180,000 - 240,000
Advisory Sales Engineer - Strategic AI
Advisory Sales Engineer - Strategic AI

Data Direct Networks • Germany (OH)

On-site
USD 120,000 - 190,000
Highly competitive vacation plans
Paid holidays
Bonus programs
+5
Director, Engineering – Release Engineering, DevOps & SRE
Director, Engineering – Release Engineering, DevOps & SRE

Data Direct Networks • North Carolina

Hybrid
USD 250,000 - 300,000
Vacation plans
Paid holidays
Bonus programs
+5