Senior Software Developer - Security - Elasticsearch

Elastic Elastic · Enterprise · Canada · Platform - Data and Compute

Senior Software Developer for Elasticsearch Security team, focusing on architecture, design, and implementation of security features like authentication, authorization, and tenant isolation. The role involves optimizing security performance in distributed systems, applying cryptographic solutions, and ensuring data isolation. A key aspect is leveraging AI-driven tools to enhance security workflows, vulnerability management, and development processes.

What you'd actually do

  1. Contributing to core security initiatives from architecture to production, focusing on the delivery of new critical features. Participating in the technical design, planning, and execution for major security components inside the Elasticsearch core engine.
  2. Developing the foundational security models for features.
  3. Optimizing security performance at scale in distributed systems environments.
  4. Applying cryptographic solutions to address genuine customer use cases.
  5. Ensuring robust data isolation within shared infrastructure supporting disparate customers.

Skills

Required

  • deep knowledge of Java internals and JVM memory management
  • understanding of concurrency models
  • experience building authorization systems that are scalable and performant
  • designing access models
  • validating credentials/tokens at scale
  • keeping authorization decisions consistent across a distributed system
  • solid comprehension of distributed systems security
  • node-to-node mutual trust
  • zero-trust transport
  • partition tolerance and cluster state propagation
  • deep knowledge of edge identity protocols (OAuth 2.0, SAML)
  • proven track record of using AI to accelerate development, debug complex systems, and optimize code
  • ability to collaborate across functions and teams
  • seamlessly transition between different projects, codebases, or teams
  • work autonomously
  • supporting decisions and results in a distributed team
  • leveraging asynchronous, direct, and transparent communication

Nice to have

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

What the JD emphasized

  • high-performance security at all levels
  • scalable and performant under high concurrency and large permission sets
  • solid comprehension of distributed systems security
  • deep knowledge of edge identity protocols
  • proven track record of using AI to accelerate development, debug complex systems, and optimize code