Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Staff Security Engineer

Ddn
CompanyDdn
CategoryEngineering
LocationSacramento
RemoteRemote (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted15 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.   KEY RESPONSIBILITIES - Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. - Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling. - Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform. - Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation. - Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources. - Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties. - Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management. - Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security. - Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. . - Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform. - Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.   REQUIRED QUALIFICATIONS - Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field. - 12+ years of experience in security architecture, infrastructure security, or distributed systems. - Proven experience designing security for large-scale distributed systems or storage platforms. - Strong understanding of data path vs. control plane architectures and their security implications. - Deep expertise in encryption technologies, key management systems, and cryptographic frameworks. - Experience integrating with external KMS solutions using KMIP or similar protocols. - Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation. - Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC. - Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4). - Experience designing multi-tenant systems with strong isolation and policy enforcement. - Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance. - Ability to collaborate effectively with protocol, storage, and platform engineering teams.   PREFERRED SKILLS - Experience working with S3, POSIX/NFS, or similar storage protocol
HOUSE ADYour CV gets thirty seconds.CV writing and honest review. English & Greek.kaeros.app →
Staff Security Engineer — Ddn · Job Opportunities API