DigitalOcean logo
DigitalOcean

The cloud ☁️ of choice for developers, startups, and growing digital businesses around the world.

Principal Engineer – Security Products, Security Visibility

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000Since 2011H1B SponsorCompany SiteLinkedIn

Location

Massachusetts

Posted

8 days ago

Salary

$235.2K - $294K / year

Seniority

Lead

Job Description

Principal Engineer – Security Products, Security Visibility

DigitalOcean

• Define and drive the multi-year technical roadmap for Audit Logging, SIEM Integration, and Unified Security Visibility • Design fault-tolerant, high-throughput audit and telemetry pipelines in Go • Architect the Unified Security Dashboard • Design and deliver integrations with leading SIEM platforms • Lead the redesign of DigitalOcean's audit log infrastructure • Partner with IAM, Threat Detection, DOKS, Billing, and Platform Engineering • Establish logging schema standards, event taxonomy, and observability engineering practices • Mentor and develop senior and mid-level engineers

Job Requirements

  • Over 10 years of software engineering expertise
  • 4+ years dedicated to audit logging, security telemetry, SIEM integration, or managing high-throughput data pipelines
  • Expertise in Go and extensive experience designing gRPC-based microservices
  • Deep knowledge of Apache Flink, Apache Kafka, or similar high-volume stream processing frameworks
  • Proven history of developing security visibility platforms
  • Understanding of audit requirements for frameworks like SOC 2, ISO 27001, FedRAMP, and PCI-DSS
  • Proficient with Kubernetes, Terraform (IaC), SQL (MySQL), and analytical or columnar data stores
  • Track record of leading ambiguous, cross-functional platform initiatives

Benefits

  • Health insurance
  • Retirement plans
  • Paid time off
  • Flexible work arrangements
  • Professional development
  • Bonuses
  • Stock options

Related Categories

Related Job Pages

More Security Engineer Jobs

Msccn logo

Information Systems Security Officer (ISSO)

Msccn

We're a global leader in providing energy solutions that help businesses grow and communities thrive. We work as a team and we’re proud of the difference we make to customers, to local communities, and towards a sustainable future for the world.

Role Description Step into a role where you can make a significant impact on the security posture of Department of Defense (DoD) information systems. As a Security Authorization Expert, you will: - Own the day-to-day security authorization posture of assigned DoD information systems. - Work within a well-resourced team with dedicated engineering, operations, and architecture support. - Develop expertise in modern RMF tooling including eMASS and eMASSer automation. - Directly support mission continuity by managing ATO packages and continuous monitoring programs. - Grow into a senior GRC role with clear advancement pathways. Responsibilities: - Develop, maintain, and update System Security Plans (SSPs) for assigned systems. - Manage Plans of Action & Milestones (POA&Ms) from identification through remediation and closure. - Compile and submit Authorization to Operate (ATO) packages. - Conduct continuous monitoring activities per established strategy. - Utilize eMASS for GRC management and RMF workflow tracking. - Coordinate with Information System Security Engineers (ISSEs) and Security Operations (SecOps) to validate control implementations. - Develop Security Assessment Plans (SAPs) and support Security Assessment Report (SAR) coordination. - Draft supply chain risk management plans. - Support the Cybersecurity Architect with RMF strategic planning. Qualifications - Active Secret or Top Secret clearance. - 3–5 years of RMF/ATO experience within DoD or federal environments. - Hands-on experience with eMASS. - Working knowledge of NIST SP 800-53r5 and DoD RMF processes. - Demonstrated ability to independently author SSPs and manage POA&Ms. Requirements - Required Certification: DoD 8140.03M DCWF Basic tier certification — CEH. - Education: DoD 8140 Interim Education Options. - Desired Certification: DoD 8140.03M DCWF Intermediate tier certification — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+. - Desired Education: Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering. - Desired: Experience with eMASSer or similar RMF automation tooling. - Exposure to cloud-hosted or hybrid system authorization boundaries. - Familiarity with the DoD RMF Knowledge Service. Benefits - Competitive compensation. - Healthcare benefits. - Wellness programs. - Financial benefits. - Retirement plans. - Family support. - Continuing education opportunities. - Time off benefits.

United States
$75.2K - $158.1K / year
Job Closed
Slingshot Aerospace logo

Facility Security Officer

Slingshot Aerospace

We build space simulation and analytics solutions to bring clarity to complex environments and create a safer world.

Full TimeRemoteTeam 51-200Since 2020H1B No Sponsor

• Lead all facility-related responsibilities and security operations across the organization • Oversee facility management, leasing, and compliance • Manage personnel clearances, secure facilities, and physical security programs • Ensure compliance with all government security requirements and regulations • Conduct regular security assessments and implement improvements

Alabama + 30 moreAll locations: Alabama | Arizona | California | Colorado | District Of Columbia | Florida | Hawaii | Illinois | Kansas | Montana | Nevada | New Jersey | New Mexico | New York | North Carolina | Ohio | Oklahoma | Oregon | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Rhode Island | Tennessee | Texas | Utah | Virginia | Washington | West Virginia | Wisconsin
Job Closed
Make-A-Wish America logo

Lead IT Security Engineer

Make-A-Wish America

Together, we create life-changing wishes for children with critical illnesses.

Full TimeRemoteTeam 1,001-5,000Since 1980H1B No Sponsor

• Expertise in designing secure networks, systems, and application architectures • Manage/implement design, installation, configuration, setup, testing, troubleshooting, documentation of security solutions including IAM, endpoint security, firewalls, email security, content filtering and security awareness. • Proficient with networks, systems, applications, and cloud security • Proficiency with risk assessment and vulnerability scanning tools, technologies, and methods • Escalation point for security-related incidents • Proactively report possible threats and or vulnerabilities • Proactively research weaknesses and find ways to counter them • Find cost-effective solutions to cybersecurity problems • Information Technology Security representative on IT projects to provide security advice, expertise, and recommendations • Conduct security awareness training • Planning, researching, and developing security policies, standards and procedures • Ensure the tuning and effectiveness of security tools deployed across the environment • Work closely with our Managed Security Services Provider (MSSP) and IT teams to review alerts and investigate security incidents • 24/7 Availability for Identity & Access Management, Security Incident Response and Escalation • Performs other related job duties, as assigned

United States
$68.1K - $84K / year
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Partner with Security Compliance Regulatory Affairs to execute a unified security regulatory strategy that balances long-term global trends with Twilio’s immediate operational needs. • Monitor, identify, and prioritize new and evolving cybersecurity regulations (including telecom-specific mandates); translate complex requirements into actionable business impacts. • Manage weekly compliance-focused operating rhythm, triaging regulatory developments and escalating critical security risks to senior leadership. • In partnership with cyber legal counsel, define the "scope of applicability" for new regulations to ensure Twilio’s responses and decisions are precise, efficient, and aligned with how we actually build products. • Collaborate with Go-To-Market teams to leverage Twilio’s security compliance posture as a differentiator, identifying opportunities to drive revenue through trust. • Project manage non-security stakeholders to ensure the timely collection of evidence, support, and information required for successful regulatory filings and audits, working closely with the Security Compliance Regulatory Affairs team to facilitate and align on response.

California + 5 moreAll locations: California | Connecticut | New Jersey | New York | Pennsylvania | Washington
$155.5K - $194.4K / year