DDN Storage Logo

DDN Storage

Staff Security Engineer

Posted Yesterday
Remote or Hybrid
Hiring Remotely in California, USA
Expert/Leader
Remote or Hybrid
Hiring Remotely in California, USA
Expert/Leader
Leads end-to-end security architecture for distributed storage platforms and AI-driven workloads. Responsibilities include threat modeling, SSDLC, IAM integration, RBAC and ABAC authorization, encryption and key management, multi-tenant isolation, secure APIs and protocols, observability, anomaly detection, compliance, and cross-functional technical leadership. The role partners with storage, protocol, control-plane, and platform engineering teams while mentoring engineers and influencing secure system design.
The summary above was generated by AI

DDN is seeking a highly experienced Sr. Staff Security Architect to lead the design and implementation of end-to-end security architecture across distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services. This is an architecture role focused on working closely with engineering teams across the data path, control plane, and ecosystem/protocol domains to ensure security is deeply embedded across all layers of the platform. You will collaborate with protocol teams, storage engineers, and platform architects to define secure-by-design systems that support high-performance, multi-tenant, and AI-driven workloads. The ideal candidate brings deep expertise in distributed systems security, cryptography, identity frameworks, and storage architectures, with a strong ability to influence engineering design and guide implementation at scale.

 
Key Responsibilities
  • Lead the design and implementation of end-to-end security architecture for distributed storage platforms, including S3-compatible systems, POSIX-compliant file systems, and KV cache–based data services.

  • Partner closely with Data Path engineering teams to ensure secure, high-performance data movement across storage tiers, including encryption, integrity validation, and secure I/O handling.

  • Lead threat modeling, security reviews, and Secure Software Development Lifecycle (SSDLC) practices across the platform.

  • Define identity and access management (IAM) integrating enterprise identity providers such as LDAP, Active Directory, OIDC, and Keycloak, supporting SSO, MFA, and federation.

  • Architect fine-grained authorization models using RBAC and ABAC across tenants, datasets, and resources.

  • Design multi-tenant isolation mechanisms across namespaces, policies, encryption boundaries, and resource quotas, enforcing least privilege and segregation of duties.

  • Collaborate with Control Plane teams to define secure APIs, authentication and authorization workflows, policy enforcement, and tenant lifecycle management.

  • Work with Protocol and Ecosystem teams to secure S3 and POSIX/NFS interfaces, including request signing, session management, and endpoint security.

  • Define and enforce encryption strategies for data at rest and in transit, including tenant-specific keys and dataset-level encryption policies. .

  • Drive observability and monitoring strategies to detect anomalous behavior, abnormal access patterns, and potential data exfiltration across the platform.

  • Provide technical leadership and mentorship across cross-functional engineering teams, guiding secure design and implementation practices.

 
Required Qualifications
  • Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.

  • 12+ years of experience in security architecture, infrastructure security, or distributed systems.

  • Proven experience designing security for large-scale distributed systems or storage platforms.

  • Strong understanding of data path vs. control plane architectures and their security implications.

  • Deep expertise in encryption technologies, key management systems, and cryptographic frameworks.

  • Experience integrating with external KMS solutions using KMIP or similar protocols.

  • Strong knowledge of identity and access management (IAM), including RBAC, ABAC, SSO, MFA, and federation.

  • Experience working with enterprise identity providers such as LDAP, Active Directory, and OIDC.

  • Familiarity with secure API design, TLS 1.3, mutual TLS, and request signing mechanisms (e.g., SigV4).

  • Experience designing multi-tenant systems with strong isolation and policy enforcement.

  • Knowledge of logging, auditing, and SIEM integration for security monitoring and compliance.

  • Ability to collaborate effectively with protocol, storage, and platform engineering teams.

 
Preferred Skills
  • Experience working with S3, POSIX/NFS, or similar storage protocols from a security architecture perspective.

  • Familiarity with KV cache systems, memory tiering, or AI/ML data infrastructure security considerations.

  • Hands-on experience with BYOK models and tenant-scoped key management.

  • Experience implementing ABAC using metadata, tags, and classification attributes.

  • Background in zero trust architecture and distributed system security design.

  • Experience with secure deletion techniques, including cryptographic erasure.

  • Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, or FedRAMP.

  • Experience designing security for high-performance, low-latency distributed systems.

  • Familiarity with anomaly detection, security analytics, and alerting systems.

 
What You’ll Work On
  • Defining and driving security architecture across data path, control plane, and protocol layers of distributed storage systems

  • Partnering with engineering teams to embed security into S3, POSIX, and KV cache data services

  • Building scalable encryption, identity, and access control frameworks for multi-tenant environments

  • Strengthening tenant isolation, auditability, and compliance across the platform

  • Ensuring secure integration across ecosystem components and external services

  • Leading cross-team security initiatives that influence system design, implementation, and long-term platform evolution

HQ

DDN Storage California, USA Office

9351 Deering Avenue, CA, United States, 91311

Similar Jobs

Yesterday
Remote
USA
143K-214K Annually
Senior level
143K-214K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Build and lead a scalable application security and secure SDLC program across engineering teams. Establish policies, standards, tooling, vulnerability management, threat modeling, developer enablement, security champions, software supply-chain controls, and executive reporting. Partner with development, platform, DevOps, product, and leadership teams to integrate security into CI/CD, source control, build, release, and deployment workflows while supporting audits, advisories, incident response, and regulatory requirements.
Top Skills: Api SecurityBlack DuckBurp SuiteCheckmarxCi/CdContainer Security ScanningCyclonedxDastGithub Advanced SecurityGitlab Security ToolsInfrastructure-As-Code Security ScanningKubernetesMendNist Sp 800-218Nist SsdfOwasp SammOwasp ZapSastSbomScaSecrets DetectionSemgrepSlsaSnykSonarqubeSpdxVeracodeVex
6 Days Ago
Easy Apply
Remote
USA
Easy Apply
258K-310K Annually
Entry level
258K-310K Annually
Entry level
Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Lead security architecture and design reviews, define standards for protecting sensitive healthcare data, build automated defenses, guide security monitoring and incident response, translate complex objectives into engineering requirements, and mentor engineers through code and design reviews.
Top Skills: AWSCyberhavenKubernetesPythonSnowflakeTerraformWiz
9 Days Ago
Easy Apply
Remote
United States
Easy Apply
204K-290K Annually
Entry level
204K-290K Annually
Entry level
Big Data • Fintech • Mobile • Payments • Financial Services
Lead Affirm’s enterprise AI security review program, threat model LLM and agentic systems, review code and configurations, and develop security guardrails, tooling, policies, and monitoring. Evaluate AI-enabled SaaS vendors, identify emerging vulnerabilities, support incident response, and lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance. The role requires expertise in AI security architecture, threat modeling, IAM, cloud infrastructure, policy-as-code, and regulated enterprise environments.
Top Skills: AnthropicAWSCasbEmbeddingsFine-TuningGitGoogle WorkspaceInfrastructure As CodeJIRAKubernetesMcpMitre AtlasNotionOauth2OktaOpenaiOwasp Llm Top 10Pci DssPythonRagSAMLSlackSoc 2Terraform

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account