Senior Software Engineer II - KMS
HybridBengaluru, Karnataka, India
Job Summary
Design and build high-availability, security-critical key management services in Go, owning end-to-end workstreams from design through production operation. Lead the design and implementation of key generation, rotation, escrow, and destruction workflows, ensuring correctness guarantees and audit trail requirements. Scale the DEK/KEK hierarchy for envelope encryption across storage, databases, and inference workloads while driving FIPS 140-2 and SOC 2 compliance into the engineering design process. Proactively identify and remediate complex security vulnerabilities, including side-channel exposures and privilege escalation paths. Drive reliability improvements and lead incident response for security-sensitive production events, while mentoring IC2 engineers through code reviews and design feedback.
Required Qualifications
- 6+ years of software engineering experience
- at least 2-3 years focused on cryptographic systems, key management, or security-critical distributed services
- Strong proficiency in Go
- solid understanding of gRPC microservices architecture
- Working knowledge of applied cryptographic primitives — AES-GCM, RSA, ECDSA, HMAC, key derivation functions (HKDF, PBKDF2)
- ability to reason about correct usage of cryptographic primitives
- Hands-on experience with Hardware Security Modules or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault, Thales/Luna, or equivalent)
- Understanding of FIPS 140-2 requirements and how they constrain cryptographic implementation choices
- familiarity with SOC 2 or other audit frameworks as they apply to key management
- Solid understanding of consensus, replication, and partitioning
- Hands-on experience with Kubernetes
- SQL (MySQL)
- Infrastructure as Code (Terraform)
- Able to collaborate effectively across teams (IAM, Storage, Databases, Inference)
- Able to clearly communicate security trade-offs to both engineers and non-security stakeholders
Desired Qualifications
- Experience with secrets management platforms (HashiCorp Vault, AWS Secrets Manager) and their integration patterns
- Familiarity with PKCS#11 or other HSM interface standards
- Exposure to key management interoperability standards (KMIP)
- Prior work on customer-facing encryption products (BYOK, CMEK, customer-managed secrets)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.