Staff Security Engineer, PKI & Secrets
$188k - $275kCoreWeave
Staff Security Engineer, PKI & Secrets
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Francisco, CA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at
What You'll Do:
The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure by design, from data centers and GPU fleets to the platform layers powering our customers' AI workloads. The PKI & Secrets team owns the cryptographic infrastructure underpinning the confidentiality, integrity, and authenticity of CoreWeave's data and systems: PKI, secrets management, HSMs, key management, and code signing.
We partner with teams across the company to deliver cryptographic services that are secure, reliable, and easy to use at scale.
About the Role:
As a Staff Security Engineer on the PKI & Secrets team, you will shape how CoreWeave manages cryptographic infrastructure across its global fleet. You'll design and operate PKI hierarchies, secrets management platforms, HSM infrastructure, and key management systems; working hands-on with engineering teams to integrate these capabilities into their services and workflows.
In This Role, You Will:
- Contribute to the design, implementation, and operation of CoreWeave's PKI infrastructure, including CA hierarchies, issuance policies, certificate lifecycle management, and trust distribution across Kubernetes clusters and bare-metal hosts.
- Manage and evolve secrets management platforms, including access policies, secret lifecycle governance, and integration patterns using External Secrets Operator and cert-manager.
- Operate and scale HSM infrastructure, including PKCS#11 integration, key ceremony procedures, and high-availability designs backing our certificate authorities and signing services.
- Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases, including envelope encryption and KMS API design.
- Deliver PKI-based solutions supporting workload identity, mutual TLS, and hardware attestation.
- Maintain and extend code signing infrastructure for firmware images, UEFI binaries, container images, and application binaries.
- Develop and enforce cryptographic best practices and policies, and contribute to post-quantum cryptography readiness.
Who You Are:
- (8)+ years of experience in security engineering or infrastructure engineering.
- Strong understanding of PKI concepts including CA hierarchies, certificate profiles, issuance policies, revocation, and trust distribution.
- Hands-on experience operating HashiCorp Vault or similar secrets management platforms in production.
- Experience with hardware security modules (HSMs), PKCS#11 interfaces, and key ceremony procedures.
- Solid understanding of applied cryptography: symmetric and asymmetric algorithms, digital signatures, envelope encryption, and TLS.
- Proficiency in Go, Python, or similar languages, with the ability to build production tooling and automation.
- Experience with Kubernetes, including cert-manager, trust-manager, or External Secrets Operator.
- Demonstrated ability to drive cross-functional initiatives across infrastructure, platform, and product teams.
Preferred:
- Experience operating PKI backed by HSMs in a cloud provider or hyperscaler environment.
- Familiarity with code signing workflows (Authenticode, Cosign/Sigstore, transparency logs, timestamping).
- Experience with KMS design, including customer-managed keys and multi-tenant key isolation.
- Understanding of hardware attestation and workload identity (TPM, SPDM, SPIFFE/SPIRE).
- Exposure to post-quantum cryptography standards and migration planning.
Wondering If You're A Good Fit?
We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams, even if you aren't a 100% skill or experience match. If some of this describes you, we'd love to talk.
- You think deeply about how trust is established in complex distributed systems — and you enjoy making that infrastructure invisible to the teams that depend on it.
- You're comfortable operating at multiple levels of abstraction, from HSM key ceremonies to Kubernetes operator design and developer experience.
- You're a pragmatic builder who ships durable solutions in fast-moving environments.
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!
The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings; for roles in other locations, benefits vary and are shared during the hiring process. These include:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
California Applicants
California Consumer Privacy Act
Equal Opportunity & Accommodations
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io.
Export Control Compliance
This position requires access to export controlled information. To conform to U.S.
$140k - $200k
...Tango! About the Role: We’re hiring a Staff Security Engineer , a senior, polyglot, full-stack Application... ...and Platform teams to harden runtimes, secrets management, identity, and... ...threat modeling, secure design patterns, PKI/identity flows, OAuth/OIDC, and authentication...SuggestedWork at officeRemote workVisa sponsorshipWork visaFlexible hours$192k - $278k
...employee productivity without compromising security by ensuring every identity is... ...work. Position We are looking for a Staff Security Engineer to found and lead the DevSecOps function... ...governance, including branch protections, secret scanning, access controls, repository...SuggestedImmediate startRemote work$115.5k - $165k
...be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange... ...shape the future of cybersecurity. Our Engineering team built the world’s largest cloud security... ...U.S. citizenship and active U.S. Top Secret (TS) clearance (must be maintained) 5+ years...SuggestedWork at officeLocal areaWorldwide- ...Staff Security Engineer - Operations As a Staff Security Engineer - Operations within Global Information Security (GIS), you will serve as the... ...& API Protection (WAF / WAAP) Public Key Infrastructure (PKI) Added Certification or Experience a plus in the...SuggestedWork at officeWorldwideAll shiftsMonday to FridayShift work2 days per week
$405k
...Security Risk Engineer Anthropic's mission is to create reliable, interpretable, and steerable... ...a breadth of areas from identity and secrets management to infrastructure security,... ...hybrid policy: Currently, we expect all staff to be in one of our offices at least 2...SuggestedVisa sponsorship- ...Senior Security Engineer - PKI Dallas, TX/Charlotte, NC/ Newark, DE Senior Security Engineer position on the team responsible for all engineering aspects of the company's Public Key (PKI) infrastructure. This technical team also supports both internally and externally...
- ...Staff Security Engineer Our mission is to transform high finance by making capital markets faster, smarter, and more accessible. At Rogo, we're making Wall Street AI-native, empowering finance professionals at the world's top investment banks, private equity funds,...
$184k - $241.5k
...THE POSITION Our roster has an opening with your name on it As a Staff Security Engineer on our Product Security team, you'll define and deliver multi-year security initiatives and set the direction for how FanDuel engineers build securely by default at scale. Working...Temporary workLocal areaWorldwideShift work$200k - $300k
...Radar Red Team Security Engineer Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled solutions for... ...engineers at Radar fit one of two molds, technically: either Staff level expertise in one stack, or "Multi-Stack" at any level....Full time$188k - $275k
...Staff Security Engineer, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators...Permanent employmentTemporary workCasual workWork at officeFlexible hours$190k - $250k
...Fanatics Betting and Gaming is headquartered in New York with offices in Denver, Leeds and Dublin. The Role: As a Staff Security Engineer on the Fanatics Ecosystems Security team, you will lead security reviews, deliver impactful tooling in close partnership with...Full timeTemporary workSeasonal work$196k - $245k
...your impact and unlock incredible career growth opportunities, join us, and build real world value. THE WORK: As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional Finance...Full timeContract workWork at officeLocal area$188k - $275k
...Staff Security Engineer, SOAR CoreWeave's Detection and Response team is responsible for empowering and deploying decisive action across the enterprise to react to security threats. We also design security-related detections and engineer automations which reduce the...Permanent employmentTemporary workCasual workWork at officeFlexible hours$255k - $295k
...who are motivated to make a meaningful impact on healthcare at scale. About the role: We are seeking an exceptional Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and ensuring...Remote workFlexible hours$10 per hour
...s ahead. About the Role: Our engineering organization is growing, and... ...requires dedicated application security ownership. This role exists... ...ground up. As our first dedicated Staff Application Security Engineer... ...and validate fixes Secrets Management Design and implement...Full timeTemporary workFor contractorsWork at officeRemote workVisa sponsorshipFlexible hours$120k - $165k
Morgan Stanley is seeking a Cybersecurity Engineer in New York to join our PKI and Secrets Management team. The role emphasizes designing, implementing, and... ...managing the certificate lifecycle and ensuring the security of cryptographic services. A competitive salary range...$200k - $260k
...top 50 nationwide. The Role The Cloud Security function at Ro is dedicated to protecting... ...achieve this by collaborating closely with engineers and leaders across Ro’s platform, data,... ...stringent network policies, manage secrets securely, and ensure resilience against...Local areaFlexible hours$174.32k - $246.23k
The Staff Cloud Security Engineer is a critical, hands‑on technical role responsible for engineering, implementing, and automating robust security... ...access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and...Work at officeLocal areaRemote workWork from homeHome office$20k
We are seeking an experienced Cloud Security Engineer to shape the security foundation of our modern cloud environments and next-generation... ...and lifecycle expectations with regard to non-human identity. Secrets Management: Govern the secure use of cloud identities,...Local areaFlexible hours$196k - $245k
Staff Security Engineer, Secure Digital Asset Operations New York, NY, United States Please note this is for New York, NY, United States. You only need to apply to one location if there are multiple listed for the job. At Ripple, we’re building a world where value moves...Full timeContract workLocal area$168k - $240k
...offering a wide range of simple, reliable, and secure crypto products and services to... ...cryptospace. From security architecture and engineering to maintenance of cold storage systems... ...safe, secure, and supported. The Role: Staff Security Engineer We are seeking an experienced...Work at officeRemote workFlexible hours- Paxos Trust Company, LLC is seeking a full-time Staff Security Engineer to work remotely. You will design, build, and secure products and infrastructure, focusing on next-gen defenses and driving secure software development practices. Your role includes leading incident...Remote jobFull time
- A leading crypto platform is seeking a Staff Software Engineer specializing in security to enhance its digital asset protection. The ideal candidate will engage in developing and implementing sophisticated security measures to protect customer assets, collaborate closely...Remote job
$180k - $220k
...Own technical direction and execution of security initiatives that protect company data... ...complex initiatives, and develop senior engineers toward the next level. Responsibilities... ...changes Mentor senior engineers toward Staff-level behaviors; your impact compounds through...Work at officeImmediate startFlexible hours- GitLab is seeking a Staff Security Engineer with extensive IAM experience to lead the Corporate Security Identity Team. This role involves designing innovative identity access solutions and mentoring other engineers. Candidates must have 8+ years of IAM experience and be...Flexible hours
- ...be focused on two new major product lines coming to market in the next few months. Join us!! The Role We're hiring a Staff/Senior Security Engineer to lead our signing and treasury security program across wallets and custodian accounts. This is a high-impact, mission...Contract workRemote workFlexible hours
- ...and/or PRs on our Github repos About this role: This isn’t one of those roles where “security” means running scans or writing policies that gather dust. We’re looking for a real engineer—someone who thinks like a builder and a breaker. Someone who gets deep into the...Remote workFlexible hours
- ...engagement solutions enable brands to do more with less and make every guest feel like a regular. Reporting to the Security Engineering Director, the Staff Security Engineer will act as technical lead of the Olo Security Blue Team and work on security defenses that...Remote work
$188k - $275k
...Staff Network Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$204k - $240k
Etsy, Inc. is looking for a seasoned security professional in New York to lead incident response initiatives and strengthen detection... ...and cloud technologies. The position also involves mentoring engineers and working closely on security projects. We offer a competitive...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer, PKI & Secrets. Be the first to apply!
- software engineer staff New York, NY
- assistant engineer New York, NY
- assistant engineering manager New York, NY
- staff design engineer New York, NY
- project engineer assistant project manager New York, NY
- technology administrator New York, NY
- staff data engineer New York, NY
- assistant chief engineer New York, NY
- senior staff systems engineer New York, NY
- staff engineer New York, NY


