DigitalOcean logo
DigitalOceanPosted 1 week ago

Senior Software Engineer II - KMS

HybridBengaluru, Karnataka, India

Full TimeSenior LevelLargeCloud Computing

Job Summary

Design and build high-availability, security-critical key management services in Go, owning end-to-end workstreams from design through production operation. Lead the design and implementation of key generation, rotation, escrow, and destruction workflows, ensuring correctness guarantees and audit trail requirements. Scale the DEK/KEK hierarchy for envelope encryption across storage, databases, and inference workloads while driving FIPS 140-2 and SOC 2 compliance into the engineering design process. Proactively identify and remediate complex security vulnerabilities, including side-channel exposures and privilege escalation paths. Drive reliability improvements and lead incident response for security-sensitive production events, while mentoring IC2 engineers through code reviews and design feedback.

Required Qualifications

  • 6+ years of software engineering experience
  • at least 2-3 years focused on cryptographic systems, key management, or security-critical distributed services
  • Strong proficiency in Go
  • solid understanding of gRPC microservices architecture
  • Working knowledge of applied cryptographic primitives — AES-GCM, RSA, ECDSA, HMAC, key derivation functions (HKDF, PBKDF2)
  • ability to reason about correct usage of cryptographic primitives
  • Hands-on experience with Hardware Security Modules or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault, Thales/Luna, or equivalent)
  • Understanding of FIPS 140-2 requirements and how they constrain cryptographic implementation choices
  • familiarity with SOC 2 or other audit frameworks as they apply to key management
  • Solid understanding of consensus, replication, and partitioning
  • Hands-on experience with Kubernetes
  • SQL (MySQL)
  • Infrastructure as Code (Terraform)
  • Able to collaborate effectively across teams (IAM, Storage, Databases, Inference)
  • Able to clearly communicate security trade-offs to both engineers and non-security stakeholders

Desired Qualifications

  • Experience with secrets management platforms (HashiCorp Vault, AWS Secrets Manager) and their integration patterns
  • Familiarity with PKCS#11 or other HSM interface standards
  • Exposure to key management interoperability standards (KMIP)
  • Prior work on customer-facing encryption products (BYOK, CMEK, customer-managed secrets)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce