×
Register Here to Apply for Jobs or Post Jobs. X

Staff Security Engineer

Job in Sacramento, Sacramento County, California, 95828, USA
Listing for: DDN
Full Time position
Listed on 2026-08-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below

DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform.

You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.

Key Responsibilities
  • Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.
  • Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.
  • Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.
  • Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.
  • Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.
  • Design multi-tenant isolation mechanisms across name spaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.
  • Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.
  • Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.
  • Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies.
  • Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.
  • Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.
Required Qualifications
  • Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.
  • 12+ years of experience in security architecture, infrastructure security, or distributed systems.
  • Proven experience designing security for large-scale distributed systems or storage platforms.
  • Strong understanding of data path vs. control plane architectures and their security implications.
  • Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.
  • Experience integrating with external KMS solutions using KMIP or similar protocols.
  • Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.
  • Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.
  • Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).
  • Experience designing multi-tenant systems with strong isolation and policy enforcement.
  • Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.
  • Ability to collaborate effectively with protocol, storage, and platform engineering teams.
Preferred Skills
  • Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.
  • Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.
  • Hands‑on experience with BYOK models and tenant‑scoped key management.
  • Experience implementing ABAC using metadata, tags, and classification attributes.
  • Background in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary