Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, PKI & Secrets

$188k - $275k

CoreWeave

Staff Security Engineer, PKI & Secrets

Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Francisco, CA

CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at

What You'll Do:

The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure by design, from data centers and GPU fleets to the platform layers powering our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure underpinning the confidentiality, integrity, and authenticity of CoreWeave's data and systems: PKI, secrets management, HSMs, key management, and code signing.

We partner with teams across the company to deliver cryptographic services that are secure, reliable, and easy to use at scale.

About the Role:

As a Staff Security Engineer on the PKI & Secrets team, you will shape how CoreWeave manages cryptographic infrastructure across its global fleet. You'll design and operate PKI hierarchies, secrets management platforms, HSM infrastructure, and key management systems; working hands-on with engineering teams to integrate these capabilities into their services and workflows.

In This Role, You Will:
  • Contribute to the design, implementation, and operation of CoreWeave's PKI infrastructure, including CA hierarchies, issuance policies, certificate lifecycle management, and trust distribution across Kubernetes clusters and bare-metal hosts.
  • Manage and evolve secrets management platforms, including access policies, secret lifecycle governance, and integration patterns using External Secrets Operator and cert-manager.
  • Operate and scale HSM infrastructure, including PKCS#11 integration, key ceremony procedures, and high-availability designs backing our certificate authorities and signing services.
  • Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases, including envelope encryption and KMS API design.
  • Deliver PKI-based solutions supporting workload identity, mutual TLS, and hardware attestation.
  • Maintain and extend code signing infrastructure for firmware images, UEFI binaries, container images, and application binaries.
  • Develop and enforce cryptographic best practices and policies, and contribute to post-quantum cryptography readiness.
Who You Are:
  • (8)+ years of experience in security engineering or infrastructure engineering.
  • Strong understanding of PKI concepts including CA hierarchies, certificate profiles, issuance policies, revocation, and trust distribution.
  • Hands-on experience operating HashiCorp Vault or similar secrets management platforms in production.
  • Experience with hardware security modules (HSMs), PKCS#11 interfaces, and key ceremony procedures.
  • Solid understanding of applied cryptography: symmetric and asymmetric algorithms, digital signatures, envelope encryption, and TLS.
  • Proficiency in Go, Python, or similar languages, with the ability to build production tooling and automation.
  • Experience with Kubernetes, including cert-manager, trust-manager, or External Secrets Operator.
  • Demonstrated ability to drive cross-functional initiatives across infrastructure, platform, and product teams.
Preferred:
  • Experience operating PKI backed by HSMs in a cloud provider or hyperscaler environment.
  • Familiarity with code signing workflows (Authenticode, Cosign/Sigstore, transparency logs, timestamping).
  • Experience with KMS design, including customer-managed keys and multi-tenant key isolation.
  • Understanding of hardware attestation and workload identity (TPM, SPDM, SPIFFE/SPIRE).
  • Exposure to post-quantum cryptography standards and migration planning.
Wondering If You're A Good Fit?

We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams, even if you aren't a 100% skill or experience match. If some of this describes you, we'd love to talk.

  • You think deeply about how trust is established in complex distributed systems — and you enjoy making that infrastructure invisible to the teams that depend on it.
  • You're comfortable operating at multiple levels of abstraction, from HSM key ceremonies to Kubernetes operator design and developer experience.
  • You're a pragmatic builder who ships durable solutions in fast-moving environments.

Why CoreWeave?

At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:

  • Be Curious at Your Core
  • Act Like an Owner
  • Empower Employees
  • Deliver Best-in-Class Client Experiences
  • Achieve More Together

We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!

The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).

What We Offer

The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.

In addition to a competitive salary, we offer a variety of benefits to support your needs, including:

  • Medical, dental, and vision insurance - 100% paid for by CoreWeave
  • Company-paid Life Insurance
  • Voluntary supplemental life insurance
  • Short and long-term disability insurance
  • Flexible Spending Account
  • Health Savings Account
  • Tuition Reimbursement
  • Ability to Participate in Employee Stock Purchase Program (ESPP)
  • Mental Wellness Benefits through Spring Health
  • Family-Forming support provided by Carrot
  • Paid Parental Leave
  • Flexible, full-service childcare support with Kinside
  • 401(k) with a generous employer match
  • Flexible PTO
  • Catered lunch each day in our office and data center locations
  • A casual work environment
  • A work culture focused on innovative disruption

Our Workplace

While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.

California Consumer Privacy Act - California applicants only

CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.

As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, PKI & Secrets in New York, NY vacancy
  • $165k - $242k

     ...Learn more at What You'll Do: The Security Foundations organization at CoreWeave keeps...  ...our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure...  ...About the Role: As a Senior Security Engineer on the PKI & Secrets team, you will shape... 
    Suggested
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    7 days ago
  • $140k - $200k

     ...Tango! About the Role: We’re hiring a Staff Security Engineer , a senior, polyglot, full-stack Application...  ...and Platform teams to harden runtimes, secrets management, identity, and...  ...threat modeling, secure design patterns, PKI/identity flows, OAuth/OIDC, and authentication... 
    Suggested
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours

    Fyrfly

    New York, NY
    4 hours ago
  • $192k - $278k

     ...employee productivity without compromising security by ensuring every identity is...  ...best work. Position We are looking for a Staff Security Engineer to found and lead the DevSecOps function...  ..., including branch protections, secret scanning, access controls, repository... 
    Suggested
    Immediate start
    Remote work

    1Password

    New York, NY
    4 hours ago
  • $190k - $240k

     ...Senior/Staff Security Engineer New York, New York, United States Sage is on a mission to improve care and quality of life for older adults...  ...dependency scanning, credential leak monitoring, and secret rotation automation. Embed security into CI/CD pipelines... 
    Suggested
    Apprenticeship
    Work at office
    Local area
    Remote work
    2 days per week

    SAGE

    New York, NY
    4 days ago
  • $115.5k - $165k

     ...be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange...  ...shape the future of cybersecurity. Our Engineering team built the world’s largest cloud security...  ...U.S. citizenship and active U.S. Top Secret (TS) clearance (must be maintained) 5+ years... 
    Suggested
    Work at office
    Local area
    Worldwide

    Framework Ventures

    New York, NY
    4 hours ago
  •  ...Senior Security Engineer - PKI Dallas, TX/Charlotte, NC/ Newark, DE Senior Security Engineer position on the team responsible for all engineering aspects of the company's Public Key (PKI) infrastructure. This technical team also supports both internally and externally... 

    E-Pro

    Jersey City, NJ
    4 days ago
  • $200k - $250k

     ...with a single, convenient solution. By integrating cutting‑edge security features and launching innovative tools for an enhanced...  ...trust Phantom to securely store their crypto assets. As a Security Engineer, you will be responsible for identifying, exploiting and mitigating... 
    Live in
    Remote work
    Flexible hours

    Framework Ventures

    New York, NY
    4 hours ago
  • $220k - $260k

     ...Responsibilities Own critical security infrastructure/services for the company (Key Management for wallet infrastructure) Perform regular...  ...skills. Nice to have experience working as a security software engineer at crypto companies experience developing key management... 
    Remote work
    Flexible hours

    Framework Ventures

    New York, NY
    4 hours ago
  • $231.62k - $266.37k

    Peloton Interactive, Inc. seeks Staff Cloud Security Engineer in New York City, NY Job Duties: Drive organization-wide cloud security strategy by...  ..., network segmentation, encryption, logging, and secrets management. Lead secure cloud migration and modernization... 
    Part time
    Work at office
    Local area
    Remote work

    Peloton

    New York, NY
    4 days ago
  • $20k

     ...We are seeking an experienced Cloud Security Engineer to shape the security foundation of our modern cloud environments and next-generation...  ...and lifecycle expectations with regard to non-human identity. Secrets Management: Govern the secure use of cloud identities, Application... 
    Local area
    Flexible hours

    ServiceTitan

    New York, NY
    4 hours ago
  • $174.32k - $246.23k

     ...The Staff Cloud Security Engineer is a critical, hands‑on technical role responsible for engineering, implementing, and automating robust security...  ...access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and... 
    Work at office
    Local area
    Remote work
    Work from home
    Home office

    Included Health

    New York, NY
    4 hours ago
  •  ...virtual support to patients across an expansive array of specialties, in all 50 states. About The Role OpenLoop is looking for a Staff Security Engineer (DevOps Integrations) to join our team remotely. In this role, you will be responsible for being our DevSecOps subject... 
    Remote work
    Shift work

    OpenLoop Health

    New York, NY
    5 days ago
  •  ...Ethena Labs is seeking a Staff/Senior Security Engineer to lead their signing and treasury security program. This high-impact role involves owning the design of the signing regime and ensuring secure operational workflows within the security department. Ideal candidates... 
    Remote work
    Flexible hours

    Ethena Labs

    New York, NY
    2 days ago
  •  ...OpenLoop Health is seeking a Staff Security Engineer (DevOps Integrations) to join our team remotely. This role involves leading DevSecOps practices across IT, software engineering, and product teams while ensuring implementation of secure practices in development lifecycles... 
    Remote work

    OpenLoop Health

    New York, NY
    4 hours ago
  • $239k - $275k

     ...individuals who are motivated to make a meaningful impact on healthcare at scale.About the roleWe are seeking an exceptional Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and... 
    Remote work
    Flexible hours

    Garner Health

    New York, NY
    2 days ago
  • $168k - $240k

     ...offering a wide range of simple, reliable, and secure crypto products and services to...  ...crypto space. From security architecture and engineering to maintenance of cold storage systems...  ..., secure, and supported. The Role: Staff Security Engineer We are seeking an... 
    Work at office
    Remote work
    Flexible hours

    Gemini

    New York, NY
    1 day ago
  • $190k - $250k

     ...Fanatics Betting and Gaming is headquartered in New York with offices in Denver, Leeds and Dublin. The Role: As a Staff Security Engineer on the Fanatics Ecosystems Security team, you will lead security reviews, deliver impactful tooling in close partnership with... 
    Full time
    Temporary work
    Seasonal work

    Fanatics Betting & Gaming

    New York, NY
    4 days ago
  • $147k - $253k

     ...fusion, and networking technology to the military in months, not years. About the Team Anduril’s Application and Security Engineering team is looking for a Staff Security Engineer to focus on Identity and Access Management and build and maintain world class defensive... 
    Full time
    Work experience placement

    anduril

    New York, NY
    4 hours ago
  • $180k - $247.5k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building...  ...you are too, let's talk. Join Okta's Defensive Cyber Engineering team as a Staff Engineer responsible for safeguarding Okta's environments.... 
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    New York, NY
    4 hours ago
  •  ...will be focused on two new major product lines coming to market in the next few months. Join us!! The Role We're hiring a Staff/Senior Security Engineer to lead our signing and treasury security program across wallets and custodian accounts. This is a high-impact, mission... 
    Contract work
    Remote work
    Flexible hours

    Ethena Labs

    New York, NY
    2 days ago
  • A leading crypto platform is seeking a Staff Software Engineer specializing in security to enhance its digital asset protection. The ideal candidate will engage in developing and implementing sophisticated security measures to protect customer assets, collaborate closely... 
    Remote work

    Blockchain Works

    New York, NY
    2 days ago
  • $200k - $350k

     ...trajectory of superintelligence. Come and be one of them. About the Role Fluidstack is looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security strategy and defend our fast-growing cloud platform. You will design and deploy advanced... 
    Local area

    Fluidstack

    New York, NY
    3 days ago
  •  ...that make care smarter and more human, enabling other practitioners to access high‑quality supplements and clinical insights. Staff Security Engineer Fullscript is seeking a seasoned Staff Security Engineer to join our security team as a senior technical leader. In this... 
    Flexible hours

    Fullscript

    New York, NY
    4 hours ago
  •  ...Staff Security Engineer (Blue Team) at Olo Reporting to the Security Engineering Director, the Staff Security Engineer will act as the technical lead of the Olo Security Blue Team, designing and maintaining security defenses that protect our clients and their customers... 
    Remote work

    Olo

    New York, NY
    4 hours ago
  •  ...Staff Security Engineer At Rogo, we are building Wall Street's first true AI analyst. Our mission is to empower finance professionals at the world's top investment banks, private equity funds, and investment firms with AI that delivers unparalleled speed, accuracy,... 

    Rogo AI

    New York, NY
    4 days ago
  • $188k - $275k

     ...Staff Security Engineer, SOAR CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups,... 
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $196k - $245k

     ...your impact and unlock incredible career growth opportunities, join us, and build real world value. THE WORK: As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional Finance... 
    Full time
    Contract work
    Work at office
    Local area

    Ripple

    New York, NY
    1 day ago
  •  ...Staff Security Engineer (Blockchain) Remote (US) – Software Engineering – Full-Time – Remote About the Company Hi, we're Ondo Finance. Our mission is to provide institutional-grade, blockchain-enabled investment products and services. We have both a technology arm that... 
    Full time
    Contract work
    Remote work
    Flexible hours

    Framework Ventures

    New York, NY
    4 hours ago
  • $200k - $300k

     ...Radar Red Team Security Engineer Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled solutions for...  ...engineers at Radar fit one of two molds, technically: either Staff level expertise in one stack, or "Multi-Stack" at any level.... 
    Full time

    RADAR

    New York, NY
    4 days ago
  •  ...and/or PRs on our Github repos About this role: This isn’t one of those roles where “security” means running scans or writing policies that gather dust. We’re looking for a real engineer—someone who thinks like a builder and a breaker. Someone who gets deep into the... 
    Remote work
    Flexible hours

    LiveKit

    New York, NY
    4 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, PKI & Secrets. Be the first to apply!