Principal Software Engineer - Security - Elasticsearch

Elastic Elastic · Enterprise · Canada · Platform - Data and Compute

Principal Software Engineer for Elasticsearch Security, focusing on architecture and design of authentication, authorization, and tenant isolation. The role involves leading core security initiatives, developing foundational security models, optimizing performance, applying cryptographic solutions, ensuring data isolation, and staying updated on security advancements. It also includes driving vulnerability management, leveraging AI-driven tools for security workflows, and mentoring engineers. Requires deep Java/JVM knowledge, experience with scalable authorization systems, distributed systems security, and edge identity protocols. Experience with AI for development acceleration is a plus.

What you'd actually do

  1. Owning core security initiatives from architecture to production, focusing on the delivery of new critical features. Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine.
  2. Developing the foundational security models for intricate features.
  3. Optimizing security performance at scale in distributed systems environments.
  4. Applying cryptographic solutions to address genuine customer use cases.
  5. Ensuring robust data isolation within shared infrastructure supporting disparate customers.

Skills

Required

  • Java internals and JVM memory management
  • concurrency models
  • high-performance, thread-safe, and lock-free code
  • large open-source and enterprise codebases
  • designing and building systems for authorization at scale
  • scalable RBAC/ABAC models
  • token validation pipelines
  • permission compilation
  • distributed cache invalidation strategies
  • distributed systems security
  • node-to-node mutual trust
  • zero-trust transport
  • partition tolerance
  • cluster state propagation
  • edge identity protocols (OAuth 2.0, SAML)
  • using AI to accelerate development, debug complex systems, and optimize code
  • collaborate across functions and teams
  • work autonomously
  • drive decisions
  • lead a distributed team

Nice to have

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

What the JD emphasized

  • high-performance
  • scale
  • distributed systems
  • AI-driven tools