Our Mission: Create a world where everyone has an authentic digital identity. Identity Digital is an internet infrastructure company that makes sure web addresses work seamlessly. If we do our job right, we are invisible to the user. We have the world’s largest portfolio of nearly 300 TLDs like .info, .pro, .world, which lets people and businesses build, market, and own their digital identities using meaningful words on both sides of the dot. In addition to TLDs, Identity Digital is a best-in-class registry service provider (RSP) that supports more than 28 million domains. This means that we help organizations maintain business continuity, reduce risk and avoid reputational challenges with state-of-the-art AI and ML capabilities. Moreover, Identity Digital is a leader in the domain industry, helping expand the number and variety of digital identities to its customers and users around the world in a secure, stable, and reliable manner. Our technology and business practices are built on sustainable practices, inclusive governance initiatives and environmentally friendly practices. Our mission is to evolve the future of authentic digital identities for forward-thinking businesses and people everywhere. Beyond our registry services, we help customers discover, register, support, and use high-quality domain names with name.com, an Identity Digital-owned registrar.
Principal Software Engineer (Security Engineering)
Location
United States
Posted
19 hours ago
Salary
$210K - $275K / year
Seniority
Lead
Job Description
Principal Software Engineer (Security Engineering)
Identity Digital
Summary / Objective Identity Digital Innovation Labs (IDIL) is building DNSid, the foundational identity layer for the agentic internet, enabling AI agents to establish verifiable, DNS-anchored identities. This principal-level software engineering role will build the platform, SDKs, and tooling that make DNSid real, while bringing deep, hands-on security expertise to every layer of the product and engineering organization. Security is not a feature of DNSid; it is the product, and this engineer will write and review production code, shape the cryptographic core, define the standards the team builds against, and own the security posture of the IDIL engineering org. This role reports to the VP, Engineering & Technical Architect. What You'll Do - Own the security architecture and threat model for the DNSid platform, SDKs, and supporting infrastructure (STRIDE analysis, attack surface review, trust boundaries) - Design and review the cryptographic core: signing, verification, key management, rotation, and revocation - Build and maintain the DNSid SDKs (TypeScript, Go, and Python) with security-first design and safe defaults - Define and enforce supply-chain security practices for the codebase and dependencies - Conduct security reviews of new features, integrations, and partner-facing implementations - Partner with the standards effort (IETF draft) so the security properties are sound and keep the implementation honest - Establish secure-by-default patterns for how third parties integrate DNSid (auth schemes, scope validation, token handling) - Own the security posture of the entire IDIL engineering org: secure deployment patterns, secrets management, audit readiness (SOC 2), and incident response - Actively models and promotes Identity Digital's core values through day-to-day interactions, behaviors, and decision-making - Other duties as assigned Who You Are / What You Bring Required Qualifications - 10+ years of hands-on software engineering, building and shipping production systems - Bachelor's degree in a relevant field or equivalent experience - Fluency in TypeScript and at least one of Go or Python; depth across the stack from SDK to infrastructure - Proven experience building and shipping production SDKs or security-critical libraries - Track record as a principal or lead engineer, setting technical direction while staying hands-on - Deep, non-negotiable security expertise: cryptographic primitives and protocols (Ed25519, JWT/JWKS, OAuth2/OIDC, PKI, TLS, signature schemes), threat modeling (STRIDE or equivalent), and translating threat models into concrete engineering work - Strong understanding of DNS and DNS security (DNSSEC, TXT records, resolution) and how DNS records can anchor cryptographic identity - Working familiarity with the agentic AI ecosystem (agent identity, MCP, A2A patterns) - Minimal travel expected; occasional on-sites as needed - Ability to work across time zones as part of a global organization as needed Preferred Qualifications - Experience contributing to or reviewing IETF/security standards drafts - Background in identity protocols (WebAuthn, DID, Verifiable Credentials) - Knowledge of supply-chain security risks and mitigations Physical Requirements - Prolonged periods of sitting at a desk and working on a computer - Must be able to lift up to 15 pounds at times Location: Remote This position is open to candidates residing in the following states only: AZ, CA, CO, DE, MD, MA, MO, NJ, NV, NY, NC, OR, OK, PA, SC, TX, UT, VA, and WA. Salary Range The U.S. base salary range for this full-time position is $210,000 - $275,000 (flexibility based on experience) plus benefits as described below. In addition, the successful candidate will be eligible to receive other compensation from time to time in the form of discretionary and/or nondiscretionary bonuses and long-term incentive plan. Actual compensation will be influenced by a candidate's qualifications, internal employee equity considerations, and location. We will not ask for information about a candidate's current or past compensation for purposes of developing an offer of employment. US team members (and their spouses, domestic partners, and/or dependent children) are covered by generously subsidized medical, dental, and vision insurance which includes company contributions to a Health Savings Accounts. Team members are also covered by company-paid life and disability insurance and have the option of participating in employee-paid supplemental life, accidental death and dismemberment, critical illness, and accident insurance. In addition, team members can enroll in the company's 401(k) plan with up to a 5% match. You receive 15 days of paid vacation yearly, increasing to 20 days after one year. Additionally, you get 5 days of paid sick leave, 13 paid holidays, and 20 weeks of paid parental leave for birthing parents, 12 weeks for others. Also, there's an opportunity for tuition reimbursement for qualifying expenses. Note: Benefits programs are subject to eligibility requirements and may vary in certain locations. A few things to know about us Identity Digital is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, age, national origin, veteran status, marital status, sexual orientation, gender identity, disability or any other category prohibited by local, state or federal law. This policy applies to all aspects of employment, including recruitment, placement, promotion, transfer, demotion, compensation, benefits, social and recreational activities, and termination. Background Check Statement At the time of an offer, you will be required to complete a background check. Any offer is contingent upon a satisfactory background check. Sponsorship Statement Please note that work sponsorship for this position may not be available now or in the future. While we strive to support our candidates, not all roles will qualify. Eligibility will be reviewed on a case-by-case basis. Accommodation Statement We are committed to the full inclusion of all qualified individuals. As part of this commitment, Identity Digital will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, please contact our Recruiting Team at careers@identity.digital.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Act as the primary technical point of contact for the client, driving discussions, defining strategies, and recommending M365 and Security solutions. • Design, implement, and manage complex hybrid Exchange environments (On-Premises + Exchange Online), handling coexistence techniques and appliance requirements during migrations. • Lead SharePoint 2019/SE and SharePoint Online initiatives, with a deep focus on information architecture, taxonomy, content types, and modern search configurations. • Manage hybrid identity environments using Entra ID and Active Directory, alongside endpoint management via Microsoft Intune and Microsoft Teams deployment. • Design and enforce security policies using the Microsoft Defender Suite (Defender for Endpoint, Identity, and Office 365), Microsoft Purview, and advanced Conditional Access policies.
Senior Information Security Analyst I – IAM Cloud
Riachuelo🌎 Viva a carreira que se conecta com @vc em nosso Ecossistema. Clique na aba "vagas" e confira nossas oportunidades! ↓
• Support the company in structuring and evolving identity and access management in the cloud, establishing standards and best practices • Design, implement and maintain cloud access profiles applying the principle of least privilege for infrastructure, development, data, security teams and others • Define and manage IAM Roles and Policies specific to each function, ensuring segregation of duties • Define, deploy and support IAM Roles and STS services for both human and non-human access • Support audits and compliance requirements
IT Security Administrator
BitwardenOpen source password management solutions for individuals, teams, and business organizations.
• Assist with Security and IT related Technical Service Desk tickets • First touch point for user support (investigation/resolution, referral to TSD/Senior team member, etc) • Assist with access control changes, onboarding automation SCIM, and user provisioning / deprovisioning. • Strong hands-on expertise with configuring and administering/ maintaining Atlassian cloud products (JIRA, Service Management, Confluence, etc). • Security and IT administrative tasks related to auditing, access management, and licensing users across various departments. • Responds to, and where appropriate, resolves or escalates security incidents and investigations. • Assist Security and IT and other divisions with ensuring the secure and ethical implementation and operation of AI systems and data within the organization. • Investigates, monitors and reviews SOC and SIEM alerts and network traffic for unusual or suspicious activity or security events, and investigates these as a first level responder. • Provides escalations to tier 2 and tier3 SOC team as needed to assist with investigation of security events. • Assist with developing and maintaining documentation for security systems, services and procedures to support Bitwarden’s security, compliance needs and certification requirements such as ISO 27001, SOC2, HIPAA, and GDPR. • Administer and maintain endpoint protection and overall security and data protection utilizing various technologies such as Endpoint Detection and Response (EDR), Mobile Device Management (MDM), Secure Access Service Edge (SASE), Data Loss Prevention (DLP), DarkOps and Brand protection service, and other security solutions. • Establish and document standardized processes for managing security and IT services and establish secure/hardened system configuration baselines. • Assist with patching and updating and overall vulnerability management to keep all systems and endpoint devices secure and operational with minimal downtime.
Information Security Engineer Consultant
OptumOptum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Requisition Number: 2353672 Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. We are seeking a Mid-Level Security Operations Engineer (PAM & Certificate Management) to support and operate Privileged Access Management (PAM), Vendor PAM (VPAM), and Certificate Lifecycle / PKI services across enterprise environments. This is a hands-on, operational role focused on securing privileged identities, managing digital certificates, and enforcing strong access controls, cryptographic hygiene, and regulatory compliance. Primary Responsibilities: - Privileged Access Management (PAM / VPAM) - Onboard, manage, and govern privileged accounts within PAM vaults - Administer and enforce password management and access control policies - Monitor, audit, and record privileged sessions - Deploy, configure, and harden PAM platform components - Manage PAM connectors, plugins, and integrations - Implement authentication integrations (LDAP, SAML, RADIUS) - Administer Active Directory security groups for access segregation - Certificate Lifecycle Management & PKI Operations - Manage certificate issuance, renewal, replacement, revocation, and expiration - Proactively monitor certificate health to prevent outages - Troubleshoot certificate trust and validation issues - Support enterprise PKI and Certificate Authority services - Deploy certificates across servers, applications, and network devices - Automation & Operations - Support automation for privileged access and certificate management - Perform basic scripting (PowerShell / Python) - Support incident response for access, certificate, or encryption issues - Compliance & Governance - Enforce least-privilege and Zero Trust principles - Support audits with logs, reports, and evidence - Ensure compliance with enterprise security standards - Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so Required Qualifications: - Bachelor's degree or equivalent experience - 5+ years of infrastructure or security operations experience - 3+ years hands-on PAM and/or PKI experience - Active Directory administration experience - Solid understanding of privileged access, PKI, TLS/SSL, and X.509 Preferred Qualifications: - Cloud certificate services experience - Relevant security or infrastructure certifications - Experience with Delinea, CyberArk, BeyondTrust, or One Identity - Proven exposure to Vendor PAM (VPAM) At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.



