Senior Security Engineer, Pki & Secrets

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +4 · Technology

Senior Security Engineer role focused on designing, implementing, and operating cryptographic infrastructure including PKI, secrets management, HSMs, and key management systems for an AI cloud provider. The role involves integrating these capabilities into services and workflows, ensuring security, reliability, and scalability.

What you'd actually do

  1. Contribute to the design, implementation, and operation of CoreWeave's PKI infrastructure, including CA hierarchies, issuance policies, certificate lifecycle management, and trust distribution across Kubernetes clusters and bare-metal hosts.
  2. Manage and evolve secrets management platforms, including access policies, secret lifecycle governance, and integration patterns using External Secrets Operator and cert-manager.
  3. Operate and scale HSM infrastructure, including PKCS#11 integration, key ceremony procedures, and high-availability designs backing our certificate authorities and signing services.
  4. Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases, including envelope encryption and KMS API design.
  5. Deliver PKI-based solutions supporting workload identity, mutual TLS, and hardware attestation.

Skills

Required

  • security engineering
  • infrastructure engineering
  • PKI concepts
  • HashiCorp Vault
  • HSMs
  • PKCS#11
  • applied cryptography
  • Go
  • Python
  • Kubernetes
  • cert-manager
  • External Secrets Operator

Nice to have

  • HSM-backed PKI in cloud provider
  • code signing workflows
  • KMS design
  • hardware attestation
  • workload identity
  • post-quantum cryptography

What the JD emphasized

  • PKI
  • secrets management
  • HSM
  • key management
  • code signing