Senior Software Developer - Security - Elasticsearch
Elastic
- Location
- Canada
- Work model
- Remote
- Level
- Senior
- Salary
- $128.3k/yr
- Posted
- 1h ago
Skills
About this role
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
What is The Role
We are seeking a Senior Software Developer to join the Elasticsearch Security team. In this role, you will contribute to the architecture and design of Elasticsearch's main features. These features include authentication, authorization, and tenant isolation. You will work with engineering and product leaders at Elastic. Your goal is to participate in providing high-performance security at all levels. This includes ensuring that our distributed data store has top-quality security at scale.
What You Will Be Doing
• Contributing to core security initiatives from architecture to production, focusing on the delivery of new critical features. Participating in the technical design, planning, and execution for major security components inside the Elasticsearch core engine.
• Developing the foundational security models for features.
• Optimizing security performance at scale in distributed systems environments.
• Applying cryptographic solutions to address genuine customer use cases.
• Ensuring robust data isolation within shared infrastructure supporting disparate customers.
• Monitoring and applying the latest advancements and best practices in security. This includes authentication, identity management, cryptography, and data access management.
• Collaborating with peers across the company to embed security into new customer features from the outset.
• Drive vulnerability management efforts by collaborating closely with the InfoSec team to proactively identify, assess, and remediate security risks.
• Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation, streamlining security workflows and reducing manual intervention.
What You Bring
• You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases.
• You have experience building authorization systems that are scalable and performant under high concurrency and large permission sets, including designing access models, validating credentials/tokens at scale, and keeping authorization decisions consistent across a distributed system.
• You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance and cluster state propagation.
• You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML).
• You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still collaborating on the final outcomes.
• You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities
• You can work autonomously, supporting decisions and results in a distributed team by leveraging asynchronous, direct, and transparent communication.
Bonus Points
• Knowledge of cipher suites, TLS handshakes, and PKI/certificate