Senior Software Engineer
Job description
About the role
The Senior Software Engineer, Elasticsearch Security will take ownership of designing and implementing the core security architecture that underpins the Elastic Stack. You will be responsible for defining and delivering authentication, authorization, and tenant isolation features that scale reliably in global, multi-tenant deployments. This role requires close collaboration with product managers, security specialists, and distributed engineering teams to embed security controls directly into the platform from initial design through production rollout. You will safeguard sensitive data stores and ensure consistent, robust protection for demanding enterprise customers operating at scale. The position demands deep expertise in building secure systems that perform under high concurrency without compromising reliability or user experience. You will analyze complex threat models and translate them into resilient technical implementations that address real-world deployment scenarios. Your work will directly influence the trust model of the Elastic platform and shape how organizations adopt search-driven security.
Key facts
What you'll do
- Architect and evolve foundational security models that define how users and services access data across the Elastic Stack.
- Design and implement scalable cryptographic mechanisms that protect data in motion and at rest across distributed nodes and data centers.
- Monitor the global threat landscape and integrate current best practices for identity management, access control, and secure communication channels.
- Coordinate closely with the InfoSec team to drive vulnerability management, assess emerging risks, and automate triage using AI-assisted tooling.
- Embed security controls into new features from initial concept and design phases through implementation, testing, and production deployment.
- Optimize authorization logic to handle extremely high concurrency and extensive permission sets while maintaining decision consistency across the cluster.
- Validate tenant isolation implementations and zero trust architectures to ensure resilience, compliance, and predictable performance in shared environments.
- Partner with cross-functional teams to align security strategy with product roadmaps, customer workflows, and operational requirements.
- Build and maintain deep navigation skills within large, complex open source and enterprise codebases to locate, understand, and modify security-critical components.
- Use AI tools strategically to debug intricate security issues, accelerate development cycles, and maintain high quality outcomes in security-sensitive changes.
- Communicate autonomously within a distributed team, using direct and transparent dialogue to resolve technical ambiguity and drive decisions.
- Define and implement security protocols for node-to-node communication, ensuring mutual trust and integrity during cluster state propagation.
- Manage and integrate edge identity protocols such as OAuth 2.0 and SAML to secure enterprise access and streamline identity federation.
- Contribute to documentation and design artifacts that clarify security boundaries, threat mitigations, and operational runbooks for operations and support teams.
Requirements
- Possess deep knowledge of Java internals and JVM memory management to write high performance, thread safe, and reliable security code.
- Have proven experience building authorization systems that perform under high concurrency and large permission sets, including access models and credential validation at scale.
- Demonstrate a strong understanding of distributed systems security, including node-to-node mutual trust, secure configuration, and cluster state propagation.
- Be familiar with edge identity protocols such as OAuth 2.0 and SAML for securing enterprise access and enabling secure integrations.
- Have a history of using AI tools to debug complex systems, analyze security incidents, and accelerate development while maintaining rigorous quality standards.
- Work autonomously in a distributed team environment, communicating clearly and effectively without constant supervision.
- Bring experience navigating large, complex open source and enterprise codebases, including security-focused repositories and multi-module projects.
- Show consistent ability to translate ambiguous requirements into concrete technical designs, balancing security needs with performance and operational constraints.
Nice to have
- Knowledge of cipher suites, TLS handshakes, and PKI certificate lifecycle management and renewal processes.
- Understanding of cryptographic methods that account for memory usage, processing delays, and performance tradeoffs in high-load scenarios.
- Familiarity with the implications of Post Quantum Cryptography and preparation for migration to quantum resistant algorithms.
- Hands on experience mapping engine level controls to compliance frameworks such as FedRAMP Moderate, FIPS 140, and SOC 2.
- Background in the internals of data stores or search engine implementation, including indexing, query execution, and storage formats.
Practical notes
- This position is based in the United States and requires full-time onsite engagement.
- The role requires U.S. employment eligibility and the ability to meet standard employment requirements.
- Compensation details are provided as a fixed annual salary in USD, aligned with level and location.
- No additional travel, visa sponsorship, or specific deadlines are specified in this description.