> Markdown version of [/jobs/ext/1424205-principal-software-engineer-security-elasticsearch](https://www.wearedevelopers.com/jobs/ext/1424205-principal-software-engineer-security-elasticsearch). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Software Engineer - Security - Elasticsearch - **Company:** Elastic - **Location:** Mountain View, CA, United States - **Salary:** $159,800.0 - $252,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, User Authentication, Cipher, Cyber Security, Data Security, Data Stores, Software Debugging, Distributed Data Store, Distributed Systems, Memory Management, Elasticsearch, Federal Information Processing Standards (FIPS), Identity and Access Management, Java Virtual Machine (JVM), OAuth, Open Source Technology, Public Key Infrastructure, Role-Based Access Control, Distributed Caching, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Vulnerability Management, Search Engines, Codebase - **Published:** July 24, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17694853?backUrl=%2Fcareer%2F17694853%2FPrincipal-Software-Engineer-Security-Elasticsearch-California-Mountain-View ## About the Role * You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases. * You have proven experience in designing and building systems for authorization that can scale. This includes deep experience designing scalable RBAC/ABAC models and token validation pipelines. It includes permission compilation and distributed cache invalidation strategies. * You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation. * You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML). * You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still owning the final outcomes. * You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities * You can work autonomously, drive decisions, and lead a distributed team by leveraging asynchronous, direct, and transparent communication. Bonus Points: * Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management. * Cryptographic methods considering memory usage and delays. * Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms. * Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements. * Experience working on the internals of a data store or search engine. ## Description You will work with engineering and product leaders at Elastic. Your goal is to provide high-performance security at all levels. This includes ensuring that our distributed data store has top-quality security at scale. What You Will Be Doing: * Owning core security initiatives from architecture to production, focusing on the delivery of new critical features. Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine. * Developing the foundational security models for intricate features. * Optimizing security performance at scale in distributed systems environments. * Applying cryptographic solutions to address genuine customer use cases. * Ensuring robust data isolation within shared infrastructure supporting disparate customers. * Monitoring and applying the latest advancements and best practices in security. This includes authentication, identity management, cryptography, and data access management. * Collaborating with peers across the company to embed security into new customer features from the outset. * Drive vulnerability management efforts by collaborating closely with the InfoSec team to proactively identify, assess, and remediate security risks. * Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation, streamlining security workflows and reducing manual intervention. * Mentoring and coaching other engineers, fostering a culture of technical excellence and security-first development. ## Related Videos - [How building an industry DBMS differs from building a research one](https://www.wearedevelopers.com/videos/768-how-building-an-industry-dbms-differs-from-building-a-research-one) - [Getting to Know Your Legacy (System) with AI-Driven Software Archeology](https://www.wearedevelopers.com/videos/1437-getting-to-know-your-legacy-system-with-ai-driven-software-archeology) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why your codebase lies to AI?](https://www.wearedevelopers.com/videos/100281-why-your-codebase-lies-to-ai) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)