Staff Cloud Security Engineer

Temporal Temporal · Enterprise · United States · Security

Staff Cloud Security Engineer responsible for securing the Temporal cloud environment, integrating security into platform design, and shaping the responsible use of AI in infrastructure and engineering processes.

What you'd actually do

  1. Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others).
  2. Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems.
  3. Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries.
  4. Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.
  5. Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.

Skills

Required

  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
  • Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
  • A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages
  • Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
  • Proficiency in Go; familiarity with Python.
  • Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).

Nice to have

  • Prior experience with Temporal, Cadence, or similar workflow orchestration platforms and an understanding of workflow history, replay semantics, and scheduling internals.
  • FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.
  • Open Source automation or automation projects.
  • Expertise in other areas of security (AppSec, CorpSec, GRC)
  • Security conference talks or published research.

What the JD emphasized

  • Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc)