Senior Software Engineer - Security - Elasticsearch

Elastic Elastic · Enterprise · Canada · Platform - Data and Compute

Senior Software Engineer for Elasticsearch Security team, focusing on architecture and design of core security features like authentication, authorization, and tenant isolation. The role involves developing foundational security models, optimizing performance in distributed systems, applying cryptographic solutions, ensuring data isolation, and staying updated on security best practices. It also includes driving vulnerability management and leveraging AI-driven tools for security workflows.

What you'd actually do

  1. Contributing to core security initiatives from architecture to production, focusing on the delivery of new critical features. Participating in the technical design, planning, and execution for major security components inside the Elasticsearch core engine.
  2. Developing the foundational security models for features.
  3. Optimizing security performance at scale in distributed systems environments.
  4. Applying cryptographic solutions to address genuine customer use cases.
  5. Ensuring robust data isolation within shared infrastructure supporting disparate customers.

Skills

Required

  • deep knowledge of Java internals and JVM memory management
  • understanding of concurrency models
  • experience building authorization systems that are scalable and performant under high concurrency and large permission sets
  • solid comprehension of distributed systems security
  • deep knowledge of edge identity protocols (OAuth 2.0, SAML)
  • proven track record of using AI to accelerate development, debug complex systems, and optimize code

Nice to have

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

What the JD emphasized

  • high-performance security at all levels
  • high-performance, thread-safe, and lock-free
  • scalable and performant under high concurrency and large permission sets
  • distributed systems security
  • edge identity protocols (OAuth 2.0, SAML)
  • AI to accelerate development, debug complex systems, and optimize code