{"data":{"job_id":"f51a5673-ac8d-4ec1-8042-073a47ca177b","membership":"included","merged_into_job_id":null,"currentness":"current","stale":true,"company_id":"e66467fb-a46d-837d-8d8d-b3c799a5160b","employer_name":{"state":"known","value":"DDN","evidence":["company_record:e66467fb-a46d-837d-8d8d-b3c799a5160b"],"postingIds":[]},"title":{"state":"known","value":"Staff Security Engineer","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"description":{"state":"known","value":"DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.\n\nKEY RESPONSIBILITIES\n\n- Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.\n\n- Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.\n\n- Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.\n\n- Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.\n\n- Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.\n\n- Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.\n\n- Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.\n\n- Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.\n\n- Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. .\n\n- Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.\n\n- Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.\n\nREQUIRED QUALIFICATIONS\n\n- Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.\n\n- 12+ years of experience in security architecture, infrastructure security, or distributed systems.\n\n- Proven experience designing security for large-scale distributed systems or storage platforms.\n\n- Strong understanding of data path vs. control plane architectures and their security implications.\n\n- Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.\n\n- Experience integrating with external KMS solutions using KMIP or similar protocols.\n\n- Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.\n\n- Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.\n\n- Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).\n\n- Experience designing multi-tenant systems with strong isolation and policy enforcement.\n\n- Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.\n\n- Ability to collaborate effectively with protocol, storage, and platform engineering teams.\n\nPREFERRED SKILLS\n\n- Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.\n\n- Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.\n\n- Hands-on experience with BYOK models and tenant-scoped key management.\n\n- Experience implementing ABAC using metadata, tags, and classification attributes.\n\n- Background in zero trust architecture and distributed system security design.\n\n- Experience with secure deletion techniques, including cryptographic erasure.\n\n- Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.\n\n- Experience designing security for high-performance, low-latency distributed systems.\n\n- Familiarity with anomaly detection, security analytics, and alerting systems.\n\nWHAT YOU’LL WORK ON\n\n- Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems\n\n- Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services\n\n- Building scalable encryption, identity, and access control frameworks for multi-tenant environments\n\n- Strengthening tenant isolation, auditability, and compliance across the platform\n\n- Ensuring secure integration across ecosystem components and external services\n\n- Leading cross-team security initiatives that influence system design, implementation, and long-term platform evolution","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"work_arrangement":{"state":"known","value":"hybrid","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"locations":[{"state":"known","value":{"city":"Santa Clara Colocation"},"postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]}],"job_first_seen_at":"2026-09-15T18:20:51.464Z","curated_at":"2026-10-03T11:13:06.757Z","job_updated_at":"2026-10-08T06:07:44.106Z","postings":[{"posting_id":"b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062","board_id":"ashby","source_posting_id":"aaf072d8-900e-4613-b6d2-9b93319c434e","posting_status":"listed","posting_url":{"state":"known","value":"https://jobs.ashbyhq.com/ddn/aaf072d8-900e-4613-b6d2-9b93319c434e","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"application_url":{"state":"known","value":"https://jobs.ashbyhq.com/ddn/aaf072d8-900e-4613-b6d2-9b93319c434e/application","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"location":{"state":"known","value":{"city":"Santa Clara Colocation","remote":false},"postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"pay":{"state":"extraction_failed","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"title":{"state":"known","value":"Staff Security Engineer","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"employer_name":{"state":"extraction_failed","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"description":{"state":"known","value":"DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.\n\nKEY RESPONSIBILITIES\n\n- Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.\n\n- Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.\n\n- Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.\n\n- Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.\n\n- Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.\n\n- Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.\n\n- Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.\n\n- Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.\n\n- Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. .\n\n- Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.\n\n- Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.\n\nREQUIRED QUALIFICATIONS\n\n- Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.\n\n- 12+ years of experience in security architecture, infrastructure security, or distributed systems.\n\n- Proven experience designing security for large-scale distributed systems or storage platforms.\n\n- Strong understanding of data path vs. control plane architectures and their security implications.\n\n- Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.\n\n- Experience integrating with external KMS solutions using KMIP or similar protocols.\n\n- Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.\n\n- Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.\n\n- Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).\n\n- Experience designing multi-tenant systems with strong isolation and policy enforcement.\n\n- Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.\n\n- Ability to collaborate effectively with protocol, storage, and platform engineering teams.\n\nPREFERRED SKILLS\n\n- Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.\n\n- Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.\n\n- Hands-on experience with BYOK models and tenant-scoped key management.\n\n- Experience implementing ABAC using metadata, tags, and classification attributes.\n\n- Background in zero trust architecture and distributed system security design.\n\n- Experience with secure deletion techniques, including cryptographic erasure.\n\n- Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.\n\n- Experience designing security for high-performance, low-latency distributed systems.\n\n- Familiarity with anomaly detection, security analytics, and alerting systems.\n\nWHAT YOU’LL WORK ON\n\n- Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems\n\n- Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services\n\n- Building scalable encryption, identity, and access control frameworks for multi-tenant environments\n\n- Strengthening tenant isolation, auditability, and compliance across the platform\n\n- Ensuring secure integration across ecosystem components and external services\n\n- Leading cross-team security initiatives that influence system design, implementation, and long-term platform evolution","evidence":["source description HTML is a partial formatting fragment; the complete source description was preserved"],"postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"work_arrangement":{"state":"known","value":"hybrid","postingIds":["b48398ee93e669c3933a18edd6df0cabfd65905358c0af6cd24017a7f6b98062"]},"source_posted_at":"2026-07-31T20:11:35.694Z","first_seen_at":"2026-09-15T18:20:51.464Z","last_completed_fetch_at":"2026-10-06T16:31:42.465Z","latest_application_check":null,"source_data":{"sourceType":"ashby","availability":"listed","employmentType":"FullTime","sourcePostedAt":"2026-07-31T20:11:35.694Z","sourceUpdatedAt":null,"jobLocationType":"hybrid"},"source_rights":{"rights_record_id":"ats:ashby:jobs-api-list:global","terms_verdict":"unclear","conditions":null,"attribution_required":null,"attribution_text":null,"attribution_link":null},"source_type":"ashby","source_class":"ats","employment_type":"FullTime"}]},"snapshot_watermark":"2026-10-08T08:01:59.931Z"}