DDN logo
DDN

World’s leading Data Intelligence Platform supercharging over 500,000 GPUs across all data workloads

Staff Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000Since 1998H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

8 days ago

Salary

0

Seniority

Lead

Job Description

Staff Security Engineer

DDN

Role Description DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale. Key Responsibilities - Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. - Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling. - Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform. - Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation. - Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources. - Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties. - Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management. - Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security. - Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. - Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform. - Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices. Qualifications - Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field. - 12+ years of experience in security architecture, infrastructure security, or distributed systems. - Proven experience designing security for large-scale distributed systems or storage platforms. - Strong understanding of data path vs. control plane architectures and their security implications. - Deep expertise in encryption technologies, key management systems, and cryptographic frameworks. - Experience integrating with external KMS solutions using KMIP or similar protocols. - Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation. - Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC. - Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4). - Experience designing multi-tenant systems with strong isolation and policy enforcement. - Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance. - Ability to collaborate effectively with protocol, storage, and platform engineering teams. Preferred Skills - Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective. - Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations. - Hands-on experience with BYOK models and tenant-scoped key management. - Experience implementing ABAC using metadata, tags, and classification attributes. - Background in zero trust architecture and distributed system security design. - Experience with secure deletion techniques, including cryptographic erasure. - Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP. - Experience designing security for high-performance, low-latency distributed systems. - Familiarity with anomaly detection, security analytics, and alerting systems. What You’ll Work On - Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems. - Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services. - Building scalable encryption, identity, and access control frameworks for multi-tenant environments. - Strengthening tenant isolation, auditability, and compliance across the platform. - Ensuring secure integration across ecosystem components and external services. - Leading cross-team security initiatives that influence system design, implementation, and long-term platform evolution.

Related Categories

Related Job Pages

More Security Engineer Jobs

Desjardins logo

Senior Security Advisor – Offensive and Defensive

Desjardins

At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should reflect the diversity of the members, clients and communities we serve. If there's something we can do to help make the recruitment process or the job you're applying for more accessible, let us know. We can provide accommodations at any stage in the recruitment process. Just ask!

Full TimeRemoteTeam 10,001+Since 1900H1B No Sponsor

• Lead large-scale development projects, initiatives and activities in your specialty area • Advise clients and partners to help position, plan, develop, select solutions for, execute and monitor projects and initiatives • Develop and update policies, standards, models, methodologies, tools and programs • Conduct strategic monitoring in your area of expertise to identify emerging security issues • Analyze, map and explain threats to guide test activities • Represent your unit before decision-making bodies • Represent Desjardins when making agreements with external partners and organizations

Canada
Full TimeRemoteTeam 1,001-5,000

Role Description The Information Security Engineer will be responsible for the security of the organization’s Azure and Office 365 services, network, and endpoints. The Information Security Engineer will also support and execute on project tasks and deliverables in support of the organization’s information security roadmap/strategy. - Ensure the organization’s cloud infrastructure and data is secure and protected by implementing appropriate security controls in Azure and Office 365 based upon industry best practices. - Monitor the M365 and Azure Security Score, follow and implement Microsoft’s recommendations and deviate where necessary to continue to strengthen the organization's security posture in Azure and Office 365. - Lead efforts in remediating vulnerabilities and identifying gaps or security deficiencies on all network and endpoint devices using vulnerability management tools and risk assessments. - Manage and maintain Privileged Access Management (PAM) system. - Perform risk assessments and reviews for onboarding practices, third-party vendors, and self-assessments for the organization. - Assist in updating and executing the security awareness program. - Keep abreast of security trends and threats and ensure that the organization’s security practices are updated and aligned. - Serve as the lead and point of contact for all security related events and breaches, coordinating efforts across all technology teams. - Proactively search, detect, and respond to security events and incidents utilizing EDR and SIEM security monitoring tools. - Act as the SME for the organization’s security tools and applications including the evaluation, implementation, and maintenance of such tools. - Support a variety of security initiatives and projects that align with the organization’s information security roadmap. - Other duties as assigned. Qualifications - Expert knowledge and proven experience with cloud and cyber security principles, technologies, and best practices. - Experience with leading and responding to security incidents and events. - Demonstrates professionalism, confidentiality, and diplomacy and can serve a wide range of employees with equity and tact. - Thorough knowledge and understanding of security functions within Azure and Office 365 services. - Thorough knowledge and understanding of network and endpoint security. - Ability to work independently with minimal supervision. - Excellent customer service skills. - Effective verbal and written communication skills. - Ability to establish and maintain effective working relationships with a diverse group of people at all levels of the organization. - Commitment to excellence and high standards. - Detail oriented with strong follow-up initiative. - Versatility, flexibility, and a willingness to work within constantly changing priorities with enthusiasm. Requirements - Bachelor’s degree in cyber security, information technology, and/or equivalent experience. - 3-5 years of experience working as a cyber security analyst or engineer. - ITIL Foundations Certification or willingness to obtain it within one year of hire date. - Knowledge and experience working in a cloud-based infrastructure. Preferred Education and Experience - Healthcare industry experience. - Azure and Office 365 support experience. - CISSP, CCSP or CompTIA Security+ certification. - Knowledge of Cybersecurity Frameworks (NIST CSF, ISO27001, HITRUST, HIPAA). - Strong knowledge and experience with the following: Azure and Office 365 security technologies (Microsoft Defender, Azure Security Center, Azure Sentinel, Microsoft Cloud App Security, Microsoft ATP), EPP and EDR solutions, Email Security and Encryption Services, Data Loss Prevention tools. Benefits - Multiple medical and prescription coverage options. - Dental and vision care plans. - Health Savings Accounts (HSAs), where applicable. - Flexible Spending Accounts (FSAs). - Voluntary critical illness, cancer, and accident insurance. - Voluntary hospital indemnity coverage. - Voluntary short-term and long-term disability insurance. - Voluntary term life insurance and AD&D (Accidental Death & Dismemberment). - 401(k) retirement savings plan. - Paid time off (PTO). - Commuter benefits. - Group auto and homeowners' insurance. Part-time Benefits - Vision. - Flexible Spending Accounts. - MetLife Auto/Vehicle & Home Insurance Discounts.

United States
$100K - $140K / year
Job Closed
DraftKings Inc. logo

Staff Security Engineer, AI

DraftKings Inc.

Defining what it means to build and deliver the most extraordinary sports & entertainment experiences.The Crown is Yours

Full TimeRemoteTeam 1,001-5,000Since 2012

• Set the security standards and guardrails for the AI platform. • Define the principles, reference architectures, and policy-as-code that all AI tooling at DraftKings adheres to. • Focus on specifying the environment, infrastructure, and authentication methods agents rely on. • Review and build the architecture of AI gateways and tooling. • Provide security review, sign-off, and possibly pair on implementation of these systems. • Streamline how AI services move through InfoSec review. • Reduce AI-driven security noise. • Drive remediation efforts of complex, cross-functional security issues. • Coach and raise the bar by mentoring security and platform engineers.

United States
$160.7K - $200.9K / year
Anomali logo

Technical Account Manager, SIEM / Security Analytics

Anomali

Intelligence-Driven Extended Detection and Response (XDR)

Full TimeRemoteTeam 201-500Since 2013H1B Sponsor

• Serve as an Anomali Platform power user; help our customers achieve success with the technology • Build strong customer relationships, especially with key customer stakeholders • Address customer’s technical requests; proactively identify and resolve issues • Provide advice, guidance, and technical know-how to ensure successful usage and adoption • Manage customer expectations while holding them accountable • Be your customer’s advocate and internal champion • Promote advocacy • Track key account metrics; communicate progress to internal and external stakeholders • Engage with the Onboarding Engineers to ensure a smooth transition • Engage with Technical Support to ensure speedy resolution of customer issues • Engage with Engineering to resolve customer reported issues • Partner with Sales to ensure an exceptional customer experience • Engage with Product Management to promote customer feature requests

Saudi Arabia