Staff Security Engineer, PKI & Secrets
$188k - $275kCoreWeave
CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at
What You'll Do: The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure by design, from data centers and GPU fleets to the platform layers powering our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure underpinning the confidentiality, integrity, and authenticity of CoreWeave's data and systems: PKI, secrets management, HSMs, key management, and code signing. We partner with teams across the company to deliver cryptographic services that are secure, reliable, and easy to use at scale.About the Role: As a Staff Security Engineer on the PKI & Secrets team, you will shape how CoreWeave manages cryptographic infrastructure across its global fleet. You'll design and operate PKI hierarchies, secrets management platforms, HSM infrastructure, and key management systems; working hands-on with engineering teams to integrate these capabilities into their services and workflows.
In this role, you will:
- Contribute to the design, implementation, and operation of CoreWeave's PKI infrastructure, including CA hierarchies, issuance policies, certificate lifecycle management, and trust distribution across Kubernetes clusters and bare-metal hosts.
- Manage and evolve secrets management platforms, including access policies, secret lifecycle governance, and integration patterns using External Secrets Operator and cert-manager.
- Operate and scale HSM infrastructure, including PKCS#11 integration, key ceremony procedures, and high-availability designs backing our certificate authorities and signing services.
- Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases, including envelope encryption and KMS API design.
- Deliver PKI-based solutions supporting workload identity, mutual TLS, and hardware attestation.
- Maintain and extend code signing infrastructure for firmware images, UEFI binaries, container images, and application binaries.
- Develop and enforce cryptographic best practices and policies, and contribute to post-quantum cryptography readiness.
- (8)+ years of experience in security engineering or infrastructure engineering.
- Strong understanding of PKI concepts including CA hierarchies, certificate profiles, issuance policies, revocation, and trust distribution.
- Hands-on experience operating HashiCorp Vault or similar secrets management platforms in production.
- Experience with hardware security modules (HSMs), PKCS#11 interfaces, and key ceremony procedures.
- Solid understanding of applied cryptography: symmetric and asymmetric algorithms, digital signatures, envelope encryption, and TLS.
- Proficiency in Go, Python, or similar languages, with the ability to build production tooling and automation.
- Experience with Kubernetes, including cert-manager, trust-manager, or External Secrets Operator.
- Demonstrated ability to drive cross-functional initiatives across infrastructure, platform, and product teams.
- Experience operating PKI backed by HSMs in a cloud provider or hyperscaler environment.
- Familiarity with code signing workflows (Authenticode, Cosign/Sigstore, transparency logs, timestamping).
- Experience with KMS design, including customer-managed keys and multi-tenant key isolation.
- Understanding of hardware attestation and workload identity (TPM, SPDM, SPIFFE/SPIRE).
- Exposure to post-quantum cryptography standards and migration planning.
- You think deeply about how trust is established in complex distributed systems - and you enjoy making that infrastructure invisible to the teams that depend on it.
- You're comfortable operating at multiple levels of abstraction, from HSM key ceremonies to Kubernetes operator design and developer experience.
- You're a pragmatic builder who ships durable solutions in fast-moving environments.
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings; for roles in other locations, benefits vary and are shared during the hiring process. These include:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
California Applicants California Consumer Privacy Act
Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io. Export Control Compliance This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.
$188k - $275k
...team is responsible for empowering and deploying decisive action across the enterprise to react to security threats. We also design security-related detections and engineer automations which reduce the need for human intervention. About the role: You...SuggestedPermanent employmentTemporary workCasual workWork at officeFlexible hours$188k - $275k
...CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at What You'll Do: We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave's Vulnerability Management program. You will design and implement...SuggestedPermanent employmentTemporary workCasual workWork at officeFlexible hours$188k - $275k
...became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at What You'll Do: We are seeking a Staff Network Security Engineer to architect the defense of our global backbone, edge, and massive-scale GPU clusters. We are looking for a builder,...SuggestedPermanent employmentTemporary workCasual workWork at officeFlexible hours$188k - $275k
...Staff AI Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale...SuggestedPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours- ...one of New Jersey’s largest law firms, is seeking a Network and Security Engineer. This role provides advanced technical and engineering... ...managing firewalls, Core network infrastructure, IDS/IPS, DLP, PKI, network monitoring, alerting, and intrusion detection. Control...Suggested
$172.83k
...Security Engineer Purpose of the role To develop, implement and maintain solutions that support the safeguarding of the banks systems... ...sensitive data and systems. Management and protection of secrets, ensuring that they are securely generated, stored, and used....Hourly payRemote work$133.6k - $220.4k
...Architect, develop, and manage scalable PKI solutions. Lead certificate lifecycle management... ...and product owners to ensure robust security and seamless operations. Identify and... ...streamline PKI processes. Mentor junior engineers and partners within the enterprise. Deliver...$133.6k - $220.4k
Prudential Annuities Distributors (PAD) is seeking a PKI Architect to design and manage scalable PKI solutions. You will lead the implementation... ...and collaborate with technical teams to ensure robust security and streamlined operations. The ideal candidate will have...$139k - $204k
...Counter threat actors at a scale most practitioners never encounter - and build the capabilities to stay left of boom Work alongside security partners who hold a high bar and expect you to raise it Shape how CoreWeave finds and responds to the threats that matter most,...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...Senior Network Security Engineer About the Role We are seeking a Senior Network Security Engineer to help lead the transformation and modernization of large-scale enterprise network security infrastructure within a highly complex global environment. This role is responsible...Remote workWorldwide
$165k - $242k
...Offensive Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$188k - $275k
...in March 2025. Learn more at What You'll Do: The Storage Engine Team at CoreWeave is responsible for the product capabilities... ...efficiency. Lead efforts to improve the reliability, durability, security, and observability of our storage stack. Collaborate with...Permanent employmentTemporary workCasual workWork at officeFlexible hours$188k - $275k
...in March 2025. Learn more at What You'll Do: The Storage Engine Team at CoreWeave is responsible for the product capabilities... ...efficiency. Lead efforts to improve the reliability, durability, security, and observability of our storage stack. Collaborate with...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...is seeking a skilled Software Engineer to support and advance... ...This position requires a DOD security clearance; US citizenship is... ...including department technical staff, management, and US government... ...to obtain and maintain a DOD secret level security clearance (This...
- ...Security Technology Developer Basic Qualifications: ~10+ years of experience in developing and deploying security technologies... ...’s degree in computer science, Software Development, Software Engineering, or a related field, or equivalent alternative education,...Immediate startRemote work
$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help...Remote work$165k - $242k
...AI workloads in the world. In this role, you will lead network security for the platform, shaping how security is designed into the... ...and operated. You will lead and grow a team of network security engineers while defining how network security scales alongside the platform...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...Senior Application Security Architect We are seeking a highly skilled and experienced... ...you will partner closely with product, engineering, and cloud architecture teams to design... ...management, OAuth2/OIDC, JWT security, secrets management, key management (KMS), and zero...
$177k - $237k
...team is at the forefront of the shift to the Intelligence Age, re-engineering the physical layer to support the unprecedented power and... ...the next era of computing. About the role: ~ As our Staff, Data Center Augmentation Engineer, you will be the bridge between...Permanent employmentTemporary workFor contractorsCasual workWork at officeFlexible hoursShift work$122k - $163k
...CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at What You'll Do CoreWeave is seeking a Security Engineer to spearhead the design, development, and maintenance of our rapidly expanding global physical security network. This role is...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...Senior Full Stack Security Engineer Looking for a Senior Full Stack Security Engineer who is passionate about designing and building secure platforms and applications. The ideal candidate will feel comfortable working with both front-end and back-end application developers...
$69.45k - $90.2k
...personally thrive, make a difference and be part of a culture where individuality is noticed and valued every day. Information Security Engineer I About the Role The Information Security Engineer I is a professional member of the CISO Identity & Access Management...Remote work$190k - $282k
...Senior Security Production Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA / San Francisco, CA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$146.56k - $175k
...First Shift (Day) Job Description Develop and implement security policies, protocols, and procedures. Configure, manage, and optimize... ...Bachelor’s Degree in Computer Information Systems or Computer Engineering. Must have three years of experience with SIEM platforms, SOC/...Full timeMonday to FridayShift workNight shiftDay shift$109k - $160k
...Security Operations Engineer Livingston, NJ CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hoursNight shiftWeekend work$91.44k - $118.75k
Information Security Engineer III About the Role The Information Security Engineer III serves as a member of the NIST CISO Audit & Assurance... ...to work independently and effectively with all levels of staff and management both internally and externally Preferred Skills...Remote workWork from homeFlexible hours$188k - $275k
...performance internal platform that gives network engineers, fleet engineers, and operations teams... ...ownership of production systems. For Staff level: demonstrated ability to make... ...authentication, authorization, and frontend security best practices for internal tooling....Permanent employmentTemporary workCasual workWork at officeImmediate startFlexible hours- CoreWeave is seeking a Staff Business Systems Engineer to lead the design and optimization of Order-to-Cash workflows across NetSuite. The role requires extensive collaboration with Finance and Engineering teams to enhance process excellence and compliance with key standards...Flexible hours
$188k - $275k
About the Role We are seeking a highly experienced Staff Business Systems Engineer specializing in Order to Cash (OTC) processes to lead the design, optimization, and scalability of enterprise business systems supporting quote-to-cash operations. This role partners closely...Contract workTemporary workCasual workWork at officeRemote workFlexible hours$165k - $242k
...required to support the most demanding AI workloads in the world. In this role, you will lead and scale CoreWeave's Platform Security engineering function, owning how security is designed into the Kubernetes-based platform and public cloud environments. This is a hands-...Permanent employmentTemporary workCasual workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, PKI & Secrets. Be the first to apply!
- engineering aide Livingston, NJ
- technology administrator Livingston, NJ
- staff engineer Livingston, NJ
- assistant engineer Livingston, NJ
- senior staff systems engineer Livingston, NJ
- sr information security engineer Livingston, NJ
- senior cloud security engineer Livingston, NJ
- IT security engineer Livingston, NJ
- information technology security engineer Livingston, NJ
- network security engineer Livingston, NJ



