30 Jul
|
DigitalOcean
|
Karnataka
30 Jul
DigitalOcean
Karnataka
Dive in and do the best work of your career at DigitalOcean. Journey alongside a robust community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you ll find your place here. We value winning together while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a Software Engineer II to join our Security Products team working on Key Management Systems (KMS). Our KMS platform is foundational to DigitalOceans security posture, managing the full lifecycle of cryptographic keys that protect customer data across the platform, from envelope encryption for block storage and databases to API credential management and secrets handling.
In this role, you will contribute meaningfully to building and maintaining the systems that power DigitalOceans key management platform. You will work within established technical frameworks, implement features against well-scoped designs, and grow your expertise in applied cryptography and security engineering. If you are passionate about writing clean, reliable code and want to develop deep expertise in cryptographic systems, this is the team for you.
What Youll Do
- Build & Extend: Implement features and bug fixes across DigitalOceans key management services in Go , working within established architectural patterns and contributing to a high-reliability, security-critical platform.
- Contribute to Key Lifecycle Systems: Work on key generation, rotation, and revocation workflows,
learning the cryptographic principles deeply and contributing to reliable, well-tested implementations.
- Write Quality Code: Participate in code reviews, write comprehensive unit and integration tests, and maintain high engineering standards with particular attention to the correctness requirements of security-sensitive code.
- Operate What You Build: Participate in on-call rotations, investigate production issues, write runbooks, and develop operational ownership of the services you contribute to.
- Support Envelope Encryption Work: Implement data encryption key (DEK) wrapping and unwrapping logic using established key encryption key (KEK) hierarchies, translating well-defined requirements into working, tested code.
- Learn & Grow: Partner with senior engineers to develop your understanding of HSM integration, cryptographic protocol design, and compliance requirements (FIPS 140-2, SOC 2) building the skills to take on increasing ownership over time.
- Collaborate Cross-Functionally: Work with teammates across IAM, Storage, and Database teams to understand how your work fits into the broader platform security model.
What Youll Add to DigitalOcean
- Experience: 2 4 years of software engineering experience, with a strong foundation in building and shipping production services.
- Language Proficiency:
Proficiency in Go or a strong background in another typed systems language with demonstrated ability to ramp quickly.
- Security Fundamentals: Understanding of core cryptographic concepts symmetric vs. asymmetric encryption, key derivation, hashing and genuine curiosity to go deeper into applied cryptography.
- Systems Thinking: Understanding of how distributed systems work replication, latency trade-offs, failure modes with an appreciation for the higher stakes of failures in security-critical systems.
- Cloud Native: Exposure to containerized environments (Kubernetes) and SQL databases (Postgres, mySQL); experience with Terraform is a plus.
- Problem Solver: Comfort working through ambiguous bugs and production issues, and a disciplined approach to correctness over cleverness in security-sensitive code.
- Communication: Ability to clearly document your work, ask good questions, and collaborate effectively with teammates and stakeholders.
Nice to Have
- Familiarity with Hardware Security Modules (HSMs) or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault).
- Exposure to FIPS 140-2 compliance requirements or cryptographic standards (AES-GCM, RSA, ECDSA).
- Prior experience working on security-sensitive or compliance-adjacent systems.
- Familiarity with gRPC microservices architecture.
This job is located in Bengaluru, India
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Software Engineer II - Key Management Systems (Karnataka)
🏢 DigitalOcean
📍 Karnataka