Principal Engineer - Security Architecture
$250k - $315kDataDirect Networks Inc
US-CA-San Francisco - Remote | US-NC-Raleigh Job ID
2026-5833 Name Linked Remote: San Francisco, CA Country United States City San Francisco - Remote Worker Type
Regular Full-Time Employee Posting Location : State/Province CA Overview
This is an incredible opportunity to be part of a company that has been at the forefront of AI and high-performance data storage innovation for over two decades. DataDirect Networks (DDN) is a global market leader renowned for powering many of the world's most demanding AI data centers, in industries ranging from life sciences and healthcare to financial services, autonomous cars, Government, academia, research and manufacturing.
"DDN's A3I solutions are transforming the landscape of AI infrastructure." - IDC
"The real differentiator is DDN. I never hesitate to recommend DDN. DDN is the de facto name for AI Storage in high performance environments" - Marc Hamilton, VP, Solutions Architecture & Engineering | NVIDIA
DDN is the global leader in AI and multi-cloud data management at scale. Our cutting-edge data intelligence platform is designed to accelerate AI workloads, enabling organizations to extract maximum value from their data. With a proven track record of performance, reliability, and scalability, DDN empowers businesses to tackle the most challenging AI and data-intensive workloads with confidence.
Our success is driven by our unwavering commitment to innovation, customer-centricity, and a team of passionate professionals who bring their expertise and dedication to every project. This is a chance to make a significant impact at a company that is shaping the future of AI and data management.
Our commitment to innovation, customer success, and market leadership makes this an exciting and rewarding role for a driven professional looking to make a lasting impact in the world of AI and data storage.
Job DescriptionDDN is seeking a highly accomplished Principal Engineer - Security Architecture to define and drive the security strategy for next-generation distributed storage platforms spanning S3-compatible object storage, POSIX-compliant file systems, and KV cache-based data services. This role is responsible for architecting secure-by-design systems across the data path, control plane, and ecosystem/protocol layers that power high-performance, multi-tenant, AI-driven infrastructure at massive scale.
As a senior technical leader, you will partner closely with storage architects, protocol engineers, platform teams, and security stakeholders to embed advanced security principles into every layer of the platform lifecycle. You will influence long-term architectural direction, establish foundational security standards, and guide implementation across globally distributed engineering organizations.
The ideal candidate combines deep expertise in distributed systems security, cryptography, identity and access management, multi-tenant architectures, and infrastructure security with the ability to drive cross-functional technical strategy and execution.
Key Responsibilities
- Define and lead the long-term security architecture strategy for distributed storage platforms, including S3-compatible object storage, POSIX/NFS file systems, and KV cache-based data services.
- Establish security architecture standards and secure-by-design principles across data path, control plane, orchestration, and protocol layers.
- Partner with Data Path engineering teams to secure high-performance data movement across storage tiers, including encryption, integrity verification, secure I/O handling, and low-latency protection mechanisms.
- Drive security architecture reviews, threat modeling, and Secure Software Development Lifecycle (SSDLC) practices across platform engineering initiatives.
- Architect enterprise-grade Identity and Access Management (IAM) frameworks integrating LDAP, Active Directory, OIDC, Keycloak, SSO, MFA, federation, and delegated authorization models.
- Design and govern fine-grained authorization systems leveraging RBAC, ABAC, metadata-aware policy enforcement, and tenant-scoped access controls.
- Define scalable multi-tenant isolation architectures across namespaces, encryption boundaries, policies, quotas, and workload segregation domains while enforcing least privilege principles.
- Collaborate with Control Plane engineering teams to design secure APIs, authentication workflows, policy orchestration, tenant lifecycle management, and platform governance controls.
- Partner with Protocol and Ecosystem teams to secure S3, POSIX/NFS, and related interfaces, including request signing, session security, endpoint hardening, and protocol-level protections.
- Lead platform-wide encryption and key management strategies for data at rest and in transit, including BYOK, tenant-scoped keys, dataset-level encryption policies, KMIP integration, and external KMS interoperability.
- Define observability, telemetry, logging, auditing, and anomaly detection strategies to identify abnormal behavior, insider threats, and potential data exfiltration risks.
- Drive adoption of Zero Trust security principles across distributed systems and infrastructure components.
- Provide technical leadership, mentorship, and architectural guidance across cross-functional engineering teams, influencing secure implementation practices and platform evolution.
- Represent security architecture initiatives in executive, customer, compliance, and strategic partner discussions as needed.
Required Qualifications
- Bachelor's or Master's degree in Computer Science, Engineering, Cybersecurity, or a related technical field.
- 12+ years of experience in security architecture, distributed systems security, infrastructure security, or large-scale platform engineering.
- Proven track record designing and securing large-scale distributed systems, storage platforms, or cloud-native infrastructure.
- Deep understanding of distributed system architectures, including data path and control plane security models.
- Extensive expertise in cryptography, encryption frameworks, secure key management systems, and PKI architectures.
- Strong experience integrating external KMS platforms using KMIP or equivalent protocols.
- Advanced knowledge of IAM frameworks, including RBAC, ABAC, SSO, MFA, federation, delegated authorization, and policy-driven access control systems.
- Experience integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and SAML-based systems.
- Expertise in secure API design, TLS 1.3, mutual TLS, request signing mechanisms (e.g., SigV4), and service-to-service authentication models.
- Experience designing secure multi-tenant platforms with strong isolation, governance, and policy enforcement mechanisms.
- Strong understanding of security observability, logging, auditability, SIEM integration, and compliance-driven monitoring architectures.
- Demonstrated ability to influence technical direction and drive cross-functional architectural initiatives across engineering organizations.
Preferred Qualifications
- Experience securing S3-compatible object storage, POSIX/NFS file systems, or high-performance distributed storage environments.
- Familiarity with AI/ML infrastructure security, KV cache architectures, memory tiering systems, and GPU-centric distributed environments.
- Experience integrating and managing security solutions across large-scale infrastructure platforms, including cloud, network, and application security domains.
- Hands-on experience with BYOK architectures, tenant-scoped key management, and cryptographic isolation models.
- Experience implementing ABAC using metadata classification, tagging, and contextual policy evaluation.
- Strong background in Zero Trust architecture and distributed systems security engineering.
- Knowledge of secure deletion techniques, including cryptographic erasure and secure lifecycle management.
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST, FedRAMP, and enterprise security governance standards.
- Experience designing security controls for high-throughput, low-latency distributed systems.
- Familiarity with anomaly detection, behavioral analytics, and advanced security telemetry platforms.
- Experience with Linux systems, scripting, automation, DevSecOps workflows, and infrastructure security tooling.
Salary Range for this role: $250,000 - $315,000
DDNJoin our dynamic and driven team, where engineering excellence is at the heart of everything we do. We seek individuals who love to challenge themselves and are fueled by curiosity. Here, you'll have the opportunity to work across various areas of the company, thanks to our flat organizational structure that encourages hands-on involvement and direct contributions to our mission. Leadership is earned by those who take initiative and consistently deliver outstanding results, both in their work ethic and deliverables, making strong prioritization skills essential. Additionally, we value strong communication skills in all our engineers and researchers, as they are crucial for the success of our teams and the company as a whole.
Interview Process: After submitting your application, one of our recruiters will review your resume. If your application passes this stage, you will be invited to a 30-minute interview during which a member of our team will ask some basic questions. If you clear the interview, you will enter the main process, which can consist of up to four interviews in total:
- Coding assessment: Often in a language of your choice.
- Systems design: Translate high-level requirements into a scalable, fault-tolerant service (depending on role).
- Real-time problem-solving: Demonstrate practical skills in a live problem-solving session.
- Meet and greet with the wider team.
- Our goal is to finish the main process in 2-3 weeks at most.
DataDirect Networks (DDN) is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity, gender expression, transgender, sex stereotyping, sexual orientation, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.
#LI-Remote
- A global financial services company is seeking a Lead Identity Engineer in Raleigh, NC, to lead the architecture of next-generation API security and authorization platforms. The role requires expertise in API security, IAM, and familiarity with API gateways. Responsibilities...Suggested
$100k - $172.5k
...Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category: Scientific/Technology... ...We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ...SuggestedFull timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week$99.6k - $223.4k
...delivery infrastructure that integrates seamlessly with OVE’s architecture, enabling scalable, high-quality playback experiences. Why... ...Work with a highly technical, distributed systems-focused engineering team Responsibilities Responsibilities Design and build...SuggestedTemporary workFlexible hours$102.3k - $209.5k
...workloads. We strive to be the go-to experts in RDMA cluster architecture, leveraging our deep understanding of the unique demands of... .... Qualifications: Bachelor's degree in CS or related engineering field with 6+ years of Network Engineering experience or master...SuggestedTemporary workImmediate startFlexible hours- ...Beaverton, OR or Raleigh, NCWe are seeking a Principal Platform Engineer to design, build, and implement scalable, secure infrastructure solutions across commercial and... ...complex problems over producing static architecture artifacts.Responsibilities :Design and implement...SuggestedPermanent employmentLocal area
$120.1k - $251.6k
...Job Description Own the end-to-end power and energy architecture and strategy for hyperscale AI data centers, spanning utility interconnection... ...~ Bachelor's degree in electrical, power, or a related engineering discipline ~15+ years of experience in HV power systems, on...Temporary workFlexible hours- BW Design Group is a fully integrated architecture, engineering, construction, system integration, and consulting firm committed to helping our... ...success and fulfillment.When you join Design Group as a Principal Process Engineer, you are joining a team that will challenge...Work at office
$250k - $275k
...and fulfillment. When you join Design Group as a Sr. Process Engineer, you are joining a team that will challenge you and position you... ...solve their most difficult problems. You will join our Architecture/Engineering Process Practice and partner with seasoned leaders...Full timeWork at officeFlexible hours- ...Analyst Anywhere Type: Contract-to-Hire Category: Security Industry: Government Workplace Type: Remote Reference... ...Analyst to lead proactive defense, guide security architecture, and drive incident response and risk mitigation. The role manages...Hourly payPermanent employmentContract workLocal areaRemote work
$118.3k - $219.8k
...Responsible AI Principles ( The Enterprise Architecture team is composed of domain-focused... ...ensuring adherence to compliance and security standards. Responsibilities: Architecture... ...: Partner with Product Managers, Engineering teams, and business stakeholders to...Local areaWorldwideFlexible hours- ...partner that specializes in enterprise architecture, solution architecture, data architecture... ...with the EA, SOA, and software engineering patterns. Recommends and explains the most... ...that technology solutions are properly secured, according to Identity Management and Access...Full timeRemote work
$146k - $241k
...Position Overview The Principal Data/AI Engineer helps drive the technical strategy and architecture of enterprise-scale data and AI platforms that power mission-critical data products, analytics, and AI-driven solutions. In this role, you will operate as a technical...Remote workWork from home$104.9k - $174.7k
...Principal Incident Response Lead Job Profile Summary The Principal... ...authority for high-severity security events, providing executive-... ...environments • BS Engineering/Computer Science or equivalent... ...including hybrid enterprise architectures and common attack paths. •...Local area- ...environments" - Marc Hamilton, VP, Solutions Architecture & Engineering | NVIDIA DDN is the global leader... ...grow a diverse team of senior and principal engineers focused on distributed... ...and engineering efficiency. Drive secure-by-design engineering practices including...Local areaRemote work
$215k - $265k
...Staff Security Engineer Job Locations US-CA-San Francisco - Remote | US-NC-Raleigh Job ID 2026-5740 Name Linked... ...high performance environments" - Marc Hamilton, VP, Solutions Architecture & Engineering | NVIDIA DDN is the global leader in AI...Full timeLocal areaRemote work- ...remote role that can be hired in NC, AZ, TX, and VA. This position leads daily engineering, operations, analysis, management, and administration of tools, systems, or processes that secure the Bank's information assets and technology infrastructure. Assesses...Remote work
$110k - $150k
...for the world’s built and natural environments. As a team of engineers, architects, designers, scientists, creators and a community... ...understand, innovate, partner and deliver, EXP provides engineering, architecture, design and consulting services to the world’s built and...For contractors$106.61k - $284.28k
...Health seeks a Senior Manager for AI LaunchPad to lead engineering teams and drive the strategy and architecture of the HCD AI platform. The successful candidate... ...stakeholders, and ensure compliance with security regulations. Preferred qualifications include experience...$102.5k - $187.9k
...a focus on Automated Revenue Recognition, Subscription Economy, Cloud and Integration. These service areas span across Solution Architecture, Assessment Services, Project Management, Business and Technology Analysis, and Testing focusing on implementing technology to drive...Summer holidayFlexible hours- ...21117 Remote? No Opportunity As the Principal - Security Architect - Artificial Intelligence (... ...implementation, and governance of security architectures for AI-driven systems and platforms.... ...and deployment. Collaborate with engineering, data science, product, and compliance...Remote workFlexible hours
$109.2k - $223.4k
...running the RDMA network underneath your workload. A Principal Network Engineer on our team supports the design, deployment, and operations... ...infrastructure projects. Translate high-level network architectures into detailed designs and deployment plans while ensuring...Temporary workFlexible hours$104.9k - $174.7k
...Consulting AWS Cloud Network Infrastructure Engineer, you will help define best practices,... ...Cloud Network infrastructure is robust, secure, scalable, resilient, monitored and cost... ...5+ years in AWS cloud engineering and architecture. ~ Strong understanding of AWS network...Temporary workLocal areaImmediate startRemote workFlexible hours$174k - $252k
Senior Security Engineer, Product Security Engineering We are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include: Health, dental, vision, life, disability insurance Retirement Benefits...Full timeTemporary work- ...Summary The Senior Network Engineer provides technical leadership and deep hands-... ...SD-WAN, cloud connectivity, and network security, ensuring scalable, secure, and highly... ...Network Engineer owns key aspects of network architecture, standards, monitoring strategy,...Remote work
- ...your opportunities be, too? The Opportunity The Cloud Security Principal Engineer position at Ally is a member of the Information... ...team to report and lead the remediation efforts. Perform architecture and engineering responsibilities in support of existing technologies...Work experience placementRemote workFlexible hours
$207k - $300k
Staff Security Engineer, Product Security Engineering corporate_fare Google place New York, NY, USA; Kirkland, WA, USA; +2 more Apply benefits for this role include: Health, dental, vision, life, disability insurance Retirement Benefits: 401(k) with company match Paid...Full timeTemporary work- 6AM City, LLC is seeking a Principal - Security Architect specializing in AI-driven systems to lead security architecture design and governance. The chosen candidate will be responsible for ensuring AI solutions are secure, compliant, and resilient. This role involves...
- A leading digital financial services company is seeking a Principal - Security Architect to lead the design and implementation of security architectures for AI-driven systems. This role requires 7+ years in security architecture with a focus on AI, cloud, and identity...Flexible hours
- ...Senior Security Engineer The Senior Security Engineer on the Proxy Team is responsible for evolving and sustaining the enterprise secure... ...changing security landscape driven by AI, cloud-native architectures, and advanced threat techniques. This role focuses on modernizing...Work at office
$53.28k - $218.48k
Noblis is seeking Test / Implementation Engineers in Raleigh, NC to support the FAA Air Traffic Systems. This role involves executing... ...procedures, troubleshooting systems, and optimizing network architecture. The position requires a Bachelor’s degree in engineering and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Engineer - Security Architecture. Be the first to apply!
- principal cloud engineer Raleigh, NC
- data center chief engineer Raleigh, NC
- hotel chief engineer Raleigh, NC
- principal developer Raleigh, NC
- senior civil engineer project manager Raleigh, NC
- general engineer Raleigh, NC
- senior principal engineer Raleigh, NC
- chief engineer Raleigh, NC
- principal infrastructure engineer Raleigh, NC
- director data engineering Raleigh, NC


