[Job Radar](https://jobradar.live/) / [Jobs](https://jobradar.live/ilanlar) / Staff Security Engineer

Active
Hybrid
Santa Clara Colocation, California, United States
Posted · 31.07.2026
Ashby (US)

# Staff Security Engineer

DDN

DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.

KEY RESPONSIBILITIES
• Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.
• Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.
• Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.
• Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.
• Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.
• Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.
• Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.
• Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.
• Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. .
• Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.
• Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.

REQUIRED QUALIFICATIONS
• Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.
• 12+ years of experience in security architecture, infrastructure security, or distributed systems.
• Proven experience designing security for large-scale distributed systems or storage platforms.
• Strong understanding of data path vs. control plane architectures and their security implications.
• Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.
• Experience integrating with external KMS solutions using KMIP or similar protocols.
• Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.
• Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.
• Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).
• Experience designing multi-tenant systems with strong isolation and policy enforcement.
• Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.
• Ability to collaborate effectively with protocol, storage, and platform engineering teams.

PREFERRED SKILLS
• Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.
• Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.
• Hands-on experience with BYOK models and tenant-scoped key management.
• Experience implementing ABAC using metadata, tags, and classification attributes.
• Background in zero trust architecture and distributed system security design.
• Experience with secure deletion techniques, including cryptographic erasure.
• Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.
• Experience designing security for high-performance, low-latency distributed systems.
• Familiarity with anomaly detection, security analytics, and alerting systems.

WHAT YOU’LL WORK ON
• Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems
• Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services
• Building scalable encryption, identity, and access control frameworks for multi-tenant environments
• Strengthening tenant isolation, auditability, and compliance across the platform
• Ensuring secure integration across ecosystem components and external services
• Leading cross-team security initiatives that influence system design, implementation, and long-term platform evolution

This job was verified from Ashby (US). Applications are completed on the original source.

[Apply on the original listing ↗](https://jobradar.live/ilan/5dc6ce72-67ce-4604-ad5b-4db87f23b52e/git)

## Stop searching one by one for roles like this.

Upload your resume or enter your target roles to see your first 3 matches for free.

[Find jobs for me →](https://jobradar.live/uye/kayit)
Your resume is never shared with employers; it is processed only for matching.

Something wrong with this job?

## Similar jobs

[DDN Jobs](https://jobradar.live/company/ddn) · [Jobs in California](https://jobradar.live/jobs/california)
· [Cybersecurity Jobs in California](https://jobradar.live/jobs/california/cybersecurity) · [Jobs by location](https://jobradar.live/jobs) · [Jobs by company](https://jobradar.live/company)

- [Red Team - Offensive Security Analyst - Manager](https://jobradar.live/ilan/ada12bd9-7e5d-4f5d-93d8-78d35c7fe080) EY · Los Angeles, CA

- [Cybersecurity Internship - Spring 2027](https://jobradar.live/ilan/80122fc3-d56d-4c42-8a74-78d945373104) Varda Space Industries · El Segundo, California, United States

- [Staff Embedded Systems Security Engineer](https://jobradar.live/ilan/f18e8448-e392-4336-9285-1ca400187841) True Anomaly · Denver, CO or Long Beach, CA

- [Senior Embedded Security Engineer](https://jobradar.live/ilan/3c90207f-87f9-4b85-bea0-04399cda9afe) True Anomaly · Denver, CO or Long Beach, CA or SF Bay Area, CA

- [Principal Embedded Systems Security Engineer](https://jobradar.live/ilan/50002c5a-bf49-4194-95c4-47eeb767125e) True Anomaly · Denver, CO or Long Beach, CA

- [Mission Security Engineer III](https://jobradar.live/ilan/9a92cf27-7f62-4ebd-99a6-26d6e7ca9168) True Anomaly · Denver, CO or Long Beach, CA

- [Staff Security Engineer, Detection & Response](https://jobradar.live/ilan/28aeeb36-7def-4cbc-801d-685cad0dc398) Robinhood · Bellevue, WA; Denver, CO; Menlo Park, CA

- [Staff Offensive Security Engineer](https://jobradar.live/ilan/4bb812cb-337f-422b-acc1-e89faa185bf1) Robinhood · Bellevue, WA; Denver, CO; Menlo Park, CA; New York, NY
