Staff Security Engineer

Data Direct Networks

California (MO)

On-site

USD 190,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
Tuition Reimbursement
Employee Referral Program
Excellent Medical, Dental and Vision
Paid Leave Programs
Anniversary and Recognition Awards

Job summary

Data Direct Networks is seeking a Sr. Staff Security Architect to lead end-to-end security for its distributed storage platforms, including S3-compatible systems and POSIX file systems.

You will partner with Data Path, Control Plane, and Ecosystem teams to embed security by design, drive risk assessments, and guide implementation at scale across multi-tenant environments. This role demands deep cryptography, IAM, and secure API expertise.

Qualifications

  • Bachelor’s or Master’s degree in CS, Eng or related field.
  • 12+ years in security architecture or distributed systems.
  • Experience designing security for large-scale storage platforms.
  • Strong understanding of data path vs control plane security.
  • Expertise in encryption technologies and key management.
  • Experience integrating with external KMS using KMIP.
  • IAM expertise: RBAC, ABAC, SSO, MFA, federation.
  • Experience with LDAP/AD and OIDC.
  • Familiarity with TLS 1.3 and request signing (SigV4).
  • Multi-tenant systems design and policy enforcement.
  • Logging, auditing, SIEM integration.
  • Strong cross-team collaboration.

Responsibilities

  • Lead design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX file systems, and KV cache–based data services.
  • Partner with Data Path engineering teams to secure data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.
  • Lead threat modeling, security reviews, and SSDLC practices across the platform.
  • Define IAM integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.
  • Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.
  • Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas.
  • Collaborate with Control Plane teams to define secure APIs, authentication/authorization workflows, policy enforcement, and tenant lifecycle management.
  • Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.
  • Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies.
  • Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.
  • Provide technical leadership and mentorship across cross-functional engineering teams.

Skills

Security architecture
Distributed systems
Threat modeling
Encryption & key management
IAM & access control
RBAC/ABAC
Secure SDLC
Protocol security
Multi-tenant isolation
Security leadership

Education

Bachelor's or Master’s degree in Computer Science/Engineering

Tools

KMIP/KMS integration
LDAP / Active Directory
OIDC
Keycloak
TLS 1.3 / mutual TLS
SSO / MFA / Federation
SigV4

Job description

Staff Security Engineer
Employment Type

Full time

Location Type

On-site

DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.

Key Responsibilities

Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.

Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.

Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.

Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.

Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.

Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.

Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.

Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.

Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies.

Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.

Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.

Required Qualifications

Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.

12+ years of experience in security architecture, infrastructure security, or distributed systems.

Proven experience designing security for large-scale distributed systems or storage platforms.

Strong understanding of data path vs. control plane architectures and their security implications.

Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.

Experience integrating with external KMS solutions using KMIP or similar protocols.

Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.

Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.

Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).

Experience designing multi-tenant systems with strong isolation and policy enforcement.

Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.

Ability to collaborate effectively with protocol, storage, and platform engineering teams.

Preferred Skills

Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.

Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.

Hands‑on experience with BYOK models and tenant‑scoped key management.

Experience implementing ABAC using metadata, tags, and classification attributes.

Background in zero trust architecture and distributed system security design.

Experience with secure deletion techniques, including cryptographic erasure.

Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.

Experience designing security for high-performance, low-latency distributed systems.

Familiarity with anomaly detection, security analytics, and alerting systems.

What You’ll Work On

Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems.

Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services.

Building scalable encryption, identity, and access control frameworks for multi‑tenant environments.

Strengthening tenant isolation, auditability, and compliance across the platform.

Ensuring secure integration across ecosystem components and external services.

Leading cross‑team security initiatives that influence system design, implementation, and long‑term platform evolution.

Benefits

Highly Competitive Vacation Plans

Paid Holidays

Bonus Programs

Tuition Reimbursement

Employee Referral Program

Excellent Medical, Dental and Vision Benefits

Paid Leave Programs

Anniversary and Recognition Awards

We pride ourselves on our commitment to delivering tangible and consistent results.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

DDN • Sacramento (CA)

On-site
USD 180,000 - 240,000
Lead Engineer – Security Architecture
Lead Engineer – Security Architecture

DDN • Sacramento (CA)

On-site
USD 220,000 - 300,000
Lead Engineer – Security Architecture
Lead Engineer – Security Architecture

Data Direct Networks • California (MO)

On-site
USD 180,000 - 240,000
Vacation plans
Paid holidays
Bonus programs
+5
Senior Security Architect: Distributed Storage & IAM
Senior Security Architect: Distributed Storage & IAM

DDN • Sacramento (CA)

On-site
USD 180,000 - 240,000
Senior Security Architect - Distributed Storage
Senior Security Architect - Distributed Storage

Data Direct Networks • California (MO)

On-site
USD 190,000 - 240,000
Highly Competitive Vacation Plans
Paid Holidays
Bonus Programs
+5
Senior Security Architect for Distributed Storage Platforms
Senior Security Architect for Distributed Storage Platforms

Data Direct Networks • California (MO)

On-site
USD 180,000 - 240,000
Vacation plans
Paid holidays
Bonus programs
+5
Enterprise Data Security Architect
Enterprise Data Security Architect

Keysight Technologies SAles Spain SL. • Colorado Springs (CO)

On-site
USD 115,200 - 192,000
Medical, dental and vision
401(k) Plan
Flexible Time Off
+1
Manager, IT Security
Manager, IT Security

Sun Communities & Sun Outdoors • Southfield (MI)

On-site
USD 100,000 - 130,000
Comprehensive Medical and Prescription coverage
401(k) Plan with matching contribution
Paid Time Off including holidays and parental leave
+2
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Jobgether • United States

On-site
USD 137,000 - 222,000
401(k) match
Medical benefits
Equity opportunities
+2
Software Development Engineer, US Amazon Dedicated Cloud Security
Software Development Engineer, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 143,000 - 195,000
Health insurance
401(k) matching