Staff Security Engineer, PKI & Secrets
$188k - $275kCoreWeave
Staff Security Engineer, PKI & Secrets
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Francisco, CA
CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at
What You'll Do:
The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure by design, from data centers and GPU fleets to the platform layers powering our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure underpinning the confidentiality, integrity, and authenticity of CoreWeave's data and systems: PKI, secrets management, HSMs, key management, and code signing.
We partner with teams across the company to deliver cryptographic services that are secure, reliable, and easy to use at scale.
About the Role:
As a Staff Security Engineer on the PKI & Secrets team, you will shape how CoreWeave manages cryptographic infrastructure across its global fleet. You'll design and operate PKI hierarchies, secrets management platforms, HSM infrastructure, and key management systems; working hands-on with engineering teams to integrate these capabilities into their services and workflows.
In This Role, You Will:
- Contribute to the design, implementation, and operation of CoreWeave's PKI infrastructure, including CA hierarchies, issuance policies, certificate lifecycle management, and trust distribution across Kubernetes clusters and bare-metal hosts.
- Manage and evolve secrets management platforms, including access policies, secret lifecycle governance, and integration patterns using External Secrets Operator and cert-manager.
- Operate and scale HSM infrastructure, including PKCS#11 integration, key ceremony procedures, and high-availability designs backing our certificate authorities and signing services.
- Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases, including envelope encryption and KMS API design.
- Deliver PKI-based solutions supporting workload identity, mutual TLS, and hardware attestation.
- Maintain and extend code signing infrastructure for firmware images, UEFI binaries, container images, and application binaries.
- Develop and enforce cryptographic best practices and policies, and contribute to post-quantum cryptography readiness.
Who You Are:
- (8)+ years of experience in security engineering or infrastructure engineering.
- Strong understanding of PKI concepts including CA hierarchies, certificate profiles, issuance policies, revocation, and trust distribution.
- Hands-on experience operating HashiCorp Vault or similar secrets management platforms in production.
- Experience with hardware security modules (HSMs), PKCS#11 interfaces, and key ceremony procedures.
- Solid understanding of applied cryptography: symmetric and asymmetric algorithms, digital signatures, envelope encryption, and TLS.
- Proficiency in Go, Python, or similar languages, with the ability to build production tooling and automation.
- Experience with Kubernetes, including cert-manager, trust-manager, or External Secrets Operator.
- Demonstrated ability to drive cross-functional initiatives across infrastructure, platform, and product teams.
Preferred:
- Experience operating PKI backed by HSMs in a cloud provider or hyperscaler environment.
- Familiarity with code signing workflows (Authenticode, Cosign/Sigstore, transparency logs, timestamping).
- Experience with KMS design, including customer-managed keys and multi-tenant key isolation.
- Understanding of hardware attestation and workload identity (TPM, SPDM, SPIFFE/SPIRE).
- Exposure to post-quantum cryptography standards and migration planning.
Wondering If You're A Good Fit?
We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams, even if you aren't a 100% skill or experience match. If some of this describes you, we'd love to talk.
- You think deeply about how trust is established in complex distributed systems — and you enjoy making that infrastructure invisible to the teams that depend on it.
- You're comfortable operating at multiple levels of abstraction, from HSM key ceremonies to Kubernetes operator design and developer experience.
- You're a pragmatic builder who ships durable solutions in fast-moving environments.
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!
The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs, including:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
Our Workplace
While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.
California Consumer Privacy Act - California applicants only
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io.
$165k - $242k
...Learn more at What You'll Do: The Security Foundations organization at CoreWeave keeps... ...our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure... ...About the Role: As a Senior Security Engineer on the PKI & Secrets team, you will shape...SuggestedPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$140k - $200k
...Tango! About the Role: We’re hiring a Staff Security Engineer , a senior, polyglot, full-stack Application... ...and Platform teams to harden runtimes, secrets management, identity, and... ...threat modeling, secure design patterns, PKI/identity flows, OAuth/OIDC, and authentication...SuggestedWork at officeRemote workVisa sponsorshipWork visaFlexible hours$192k - $278k
...employee productivity without compromising security by ensuring every identity is... ...best work. Position We are looking for a Staff Security Engineer to found and lead the DevSecOps function... ..., including branch protections, secret scanning, access controls, repository...SuggestedImmediate startRemote work$190k - $240k
...Senior/Staff Security Engineer New York, New York, United States Sage is on a mission to improve care and quality of life for older adults... ...dependency scanning, credential leak monitoring, and secret rotation automation. Embed security into CI/CD pipelines...SuggestedApprenticeshipWork at officeLocal areaRemote work2 days per week$115.5k - $165k
...be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange... ...shape the future of cybersecurity. Our Engineering team built the world’s largest cloud security... ...U.S. citizenship and active U.S. Top Secret (TS) clearance (must be maintained) 5+ years...SuggestedWork at officeLocal areaWorldwide- ...Senior Security Engineer - PKI Dallas, TX/Charlotte, NC/ Newark, DE Senior Security Engineer position on the team responsible for all engineering aspects of the company's Public Key (PKI) infrastructure. This technical team also supports both internally and externally...
$200k - $250k
...with a single, convenient solution. By integrating cutting‑edge security features and launching innovative tools for an enhanced... ...trust Phantom to securely store their crypto assets. As a Security Engineer, you will be responsible for identifying, exploiting and mitigating...Live inRemote workFlexible hours$220k - $260k
...Responsibilities Own critical security infrastructure/services for the company (Key Management for wallet infrastructure) Perform regular... ...skills. Nice to have experience working as a security software engineer at crypto companies experience developing key management...Remote workFlexible hours$231.62k - $266.37k
Peloton Interactive, Inc. seeks Staff Cloud Security Engineer in New York City, NY Job Duties: Drive organization-wide cloud security strategy by... ..., network segmentation, encryption, logging, and secrets management. Lead secure cloud migration and modernization...Part timeWork at officeLocal areaRemote work$20k
...We are seeking an experienced Cloud Security Engineer to shape the security foundation of our modern cloud environments and next-generation... ...and lifecycle expectations with regard to non-human identity. Secrets Management: Govern the secure use of cloud identities, Application...Local areaFlexible hours$174.32k - $246.23k
...The Staff Cloud Security Engineer is a critical, hands‑on technical role responsible for engineering, implementing, and automating robust security... ...access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and...Work at officeLocal areaRemote workWork from homeHome office- ...virtual support to patients across an expansive array of specialties, in all 50 states. About The Role OpenLoop is looking for a Staff Security Engineer (DevOps Integrations) to join our team remotely. In this role, you will be responsible for being our DevSecOps subject...Remote workShift work
- ...Ethena Labs is seeking a Staff/Senior Security Engineer to lead their signing and treasury security program. This high-impact role involves owning the design of the signing regime and ensuring secure operational workflows within the security department. Ideal candidates...Remote workFlexible hours
- ...OpenLoop Health is seeking a Staff Security Engineer (DevOps Integrations) to join our team remotely. This role involves leading DevSecOps practices across IT, software engineering, and product teams while ensuring implementation of secure practices in development lifecycles...Remote work
$239k - $275k
...individuals who are motivated to make a meaningful impact on healthcare at scale.About the roleWe are seeking an exceptional Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and...Remote workFlexible hours$168k - $240k
...offering a wide range of simple, reliable, and secure crypto products and services to... ...crypto space. From security architecture and engineering to maintenance of cold storage systems... ..., secure, and supported. The Role: Staff Security Engineer We are seeking an...Work at officeRemote workFlexible hours$190k - $250k
...Fanatics Betting and Gaming is headquartered in New York with offices in Denver, Leeds and Dublin. The Role: As a Staff Security Engineer on the Fanatics Ecosystems Security team, you will lead security reviews, deliver impactful tooling in close partnership with...Full timeTemporary workSeasonal work$147k - $253k
...fusion, and networking technology to the military in months, not years. About the Team Anduril’s Application and Security Engineering team is looking for a Staff Security Engineer to focus on Identity and Access Management and build and maintain world class defensive...Full timeWork experience placement$180k - $247.5k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...you are too, let's talk. Join Okta's Defensive Cyber Engineering team as a Staff Engineer responsible for safeguarding Okta's environments....Local areaWorldwideFlexible hours- ...will be focused on two new major product lines coming to market in the next few months. Join us!! The Role We're hiring a Staff/Senior Security Engineer to lead our signing and treasury security program across wallets and custodian accounts. This is a high-impact, mission...Contract workRemote workFlexible hours
- A leading crypto platform is seeking a Staff Software Engineer specializing in security to enhance its digital asset protection. The ideal candidate will engage in developing and implementing sophisticated security measures to protect customer assets, collaborate closely...Remote work
$200k - $350k
...trajectory of superintelligence. Come and be one of them. About the Role Fluidstack is looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security strategy and defend our fast-growing cloud platform. You will design and deploy advanced...Local area- ...that make care smarter and more human, enabling other practitioners to access high‑quality supplements and clinical insights. Staff Security Engineer Fullscript is seeking a seasoned Staff Security Engineer to join our security team as a senior technical leader. In this...Flexible hours
- ...Staff Security Engineer (Blue Team) at Olo Reporting to the Security Engineering Director, the Staff Security Engineer will act as the technical lead of the Olo Security Blue Team, designing and maintaining security defenses that protect our clients and their customers...Remote work
- ...Staff Security Engineer At Rogo, we are building Wall Street's first true AI analyst. Our mission is to empower finance professionals at the world's top investment banks, private equity funds, and investment firms with AI that delivers unparalleled speed, accuracy,...
$188k - $275k
...Staff Security Engineer, SOAR CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups,...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$196k - $245k
...your impact and unlock incredible career growth opportunities, join us, and build real world value. THE WORK: As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional Finance...Full timeContract workWork at officeLocal area- ...Staff Security Engineer (Blockchain) Remote (US) – Software Engineering – Full-Time – Remote About the Company Hi, we're Ondo Finance. Our mission is to provide institutional-grade, blockchain-enabled investment products and services. We have both a technology arm that...Full timeContract workRemote workFlexible hours
$200k - $300k
...Radar Red Team Security Engineer Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled solutions for... ...engineers at Radar fit one of two molds, technically: either Staff level expertise in one stack, or "Multi-Stack" at any level....Full time- ...and/or PRs on our Github repos About this role: This isn’t one of those roles where “security” means running scans or writing policies that gather dust. We’re looking for a real engineer—someone who thinks like a builder and a breaker. Someone who gets deep into the...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, PKI & Secrets. Be the first to apply!
- staff security engineer New York, NY
- staff devops engineer New York, NY
- assistant engineer New York, NY
- engineering aide New York, NY
- assistant chief engineer New York, NY
- staff engineer New York, NY
- technology administrator New York, NY
- assistant electrical engineer New York, NY
- senior staff systems engineer New York, NY
- assistant mechanical engineer New York, NY


