Security & Infrastructure Engineer - Sovereign Zero-Trust

Bison Bison Cooperative Association
San Francisco, CA, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$140,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Audit Trail Computer Networks Continuous Integration Domain Name System (DNS) Key Management Network Architecture Public Key Infrastructure Role-Based Access Control Zero Trust Network Access SAP (Applications) Kubernetes
+3 more
Hashicorp Static Application Security Testing Dynamic Application Security Testing

Job description

  • Architect end-to-end sovereign security posture across all deployment environments - including zero-trust air-gapped network isolation with no external egress, HIPAA/FedRAMP/ITAR compliance readiness, and certified deployment across 20+ international jurisdictions and DoD environments
  • Enforce cryptographically signed agentic access controls via the Signed Action Protocol (SAP), with RBAC/ABAC governing both human and agent principals across every sovereign stack deployment
  • Maintain immutable JSONL audit trails with OpenTelemetry instrumentation across all agent actions, ensuring every deployment can be fully demonstrated, audited, and certified within a 30-minute live review
  • Design and implement zero-trust network architecture: SPIFFE/SPIRE workload identity and mTLS on all inter-service paths
  • Build per-country sovereign PKI: Ed25519 root CAs, TLS cert lifecycle management, and sovereign certificate issuance
  • Implement the Signed Action Protocol: ECDSA P-256 signing on all agent actions and signature verification
  • Deploy and maintain secrets management via OpenBao (sovereign Vault fork): rotation policies and audit logging
  • Own the air-gap certification process: tcpdump verification, DNS egress blocking, and namespace isolation
  • Enforce data residency via Kubernetes network policies, namespace boundaries, and per-country egress rules
  • Integrate security scanning (SAST/DAST) into the CI/CD pipeline with automated credential exposure detection

Requirements

  • 5+ years security engineering with 2+ years at senior level
  • Expert in zero-trust air-gapped architecture, sovereign security deployment (HIPAA/FedRAMP/ITAR), cryptographically signed agentic access controls (SAP/RBAC/ABAC), and immutable audit trail design (JSONL/OpenTelemetry) across DoD and international jurisdictions
  • Zero-trust architecture: SPIFFE/SPIRE, mTLS, and PKI design at depth
  • Cryptography implementation: Ed25519, ECDSA P-256, AES-256-GCM, TLS 1.3
  • Kubernetes security: RBAC, pod security standards, network policies, and secrets management
  • Secrets management: HashiCorp Vault or OpenBao - rotation, audit logging, and access policies
  • Air-gapped or classified system security experience required

Benefits & conditions

Parental leave, 401(k), Health insurance, Paid time off, Vision insurance, Dental insurance Full-time Hybrid work in San Francisco, CA 94177, * 401(k)

  • Dental insurance
  • Health insurance
  • Paid time off
  • Parental leave
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:25 min

Implementing zero trust architectures for secure developer ecosystems

Vandana Verma · LIVE

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

7:50 min

Prioritizing cybersecurity and zero trust in development

Ash Ryan Arnwine Ash Ryan Arnwine +3 · World Congress 2024

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all