Remote

Temporal Technologies Inc.
United States
2 days ago
Apply on jobs.ashbyhq.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$176,000.0 - $289,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Applications Architecture Software System Penetration Testing Microsoft Azure Client Server Models Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering
+17 more
Codecs Cyber Security Information Leak Prevention Distributed Systems Python (Programming Language) Key Management Open Source Technology Role-Based Access Control SSL Certificate Management Istio Software Security Multi-Cloud Information Technology Hashicorp CIS Benchmarks Vulnerability Analysis Programming Languages

Job description

Join our dynamic team as a Staff Cloud Security Engineer, where you’ll play a pivotal role in securing the Temporal cloud environment for our customers. In this position, you’ll work closely with our infrastructure teams, software engineering teams, and customers to build security deeply into our platform across multiple clouds. You’ll also help shape how we use AI responsibly in both our infrastructure and our engineering processes. We’re looking for individuals who are passionate about enabling engineering teams to build and ship securely, serving as trusted security partners across the organization. What You’ll Do

  • Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others).
  • Secure Temporal’s core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems.
  • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries.
  • Secure Temporal’s gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.
  • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.
  • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy.
  • Able to participate in on-call rotation.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
  • 5+ years in cloud security or a related role.
  • Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.
  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
  • Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
  • Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc).
  • A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages
  • Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
  • Proficiency in Go; familiarity with Python. Go is Temporal’s primary server and SDK language.
  • Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).
  • Excellent communication and ability to explain complex security concepts to non-technical stakeholders.
  • Excellent collaboration and communication skills.

Nice to Have

  • Prior experience with Temporal, Cadence, or similar workflow orchestration platforms and an understanding of workflow history, replay semantics, and scheduling internals.
  • FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.
  • Open Source automation or automation projects.
  • Expertise in other areas of security (AppSec, CorpSec, GRC)
  • Security conference talks or published research.

About the company

Temporal is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.ashbyhq.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Overview of the Temporal open-source durable execution architecture

Maxim Fateev Maxim Fateev · World Congress 2023

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

1:09 min

Integrating speech models using the Twilio real-time SDK

Marius Obert Marius Obert · Coffee With Developers

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all