Principal Software Developer - Security - Elasticsearch

Elastic Elastic · Enterprise · Canada · Platform - Data and Compute

Principal Software Developer for Elasticsearch Security team, focusing on architecture and design of core security features like authentication, authorization, and tenant isolation. The role involves leading technical design, developing foundational security models, optimizing performance, applying cryptographic solutions, ensuring data isolation, and collaborating across teams. It also emphasizes leveraging AI-driven tools for security workflows and mentoring engineers.

What you'd actually do

  1. Owning core security initiatives from architecture to production, focusing on the delivery of new critical features. Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine.
  2. Developing the foundational security models for intricate features.
  3. Optimizing security performance at scale in distributed systems environments.
  4. Applying cryptographic solutions to address genuine customer use cases.
  5. Ensuring robust data isolation within shared infrastructure supporting disparate customers.

Skills

Required

  • deep knowledge of Java internals and JVM memory management
  • understanding of concurrency models
  • writing high-performance, thread-safe, and lock-free code
  • experience with large open-source and enterprise codebases
  • designing and building systems for authorization that can scale
  • deep experience designing scalable RBAC/ABAC models and token validation pipelines
  • permission compilation and distributed cache invalidation strategies
  • solid comprehension of distributed systems security
  • node-to-node mutual trust
  • zero-trust transport
  • partition tolerance
  • cluster state propagation
  • deep knowledge of edge identity protocols (OAuth 2.0, SAML)
  • proven track record of using AI to accelerate development, debug complex systems, and optimize code
  • ability to collaborate across functions and teams
  • seamlessly transition between different projects, codebases, or teams
  • work autonomously
  • drive decisions
  • lead a distributed team by leveraging asynchronous, direct, and transparent communication

Nice to have

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

What the JD emphasized

  • high-performance
  • scale
  • distributed systems
  • security