Principal Software Engineer (Security Engineering)

Identity Digital
Bellevue, WA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$210,000.0 - $275,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Domain Name System Security Extensions Domain Name System (DNS) Python (Programming Language) Key Management OAuth OpenID Public Key Infrastructure Software Engineering TypeScript Transport Layer Security Golang

Job description

  • Own the security architecture and threat model for the DNSid platform, SDKs, and supporting infrastructure (STRIDE analysis, attack surface review, trust boundaries)
  • Design and review the cryptographic core: signing, verification, key management, rotation, and revocation
  • Build and maintain the DNSid SDKs (TypeScript, Go, and Python) with security-first design and safe defaults
  • Define and enforce supply-chain security practices for the codebase and dependencies
  • Conduct security reviews of new features, integrations, and partner-facing implementations
  • Partner with the standards effort (IETF draft) so the security properties are sound and keep the implementation honest
  • Establish secure-by-default patterns for how third parties integrate DNSid (auth schemes, scope validation, token handling)
  • Own the security posture of the entire IDIL engineering org: secure deployment patterns, secrets management, audit readiness (SOC 2), and incident response
  • Actively models and promotes Identity Digital’s core values through day-to-day interactions, behaviors, and decision-making
  • Other duties as assigned

Requirements

  • 10+ years of hands-on software engineering, building and shipping production systems
  • Bachelor’s degree in a relevant field or equivalent experience
  • Fluency in TypeScript and at least one of Go or Python; depth across the stack from SDK to infrastructure
  • Proven experience building and shipping production SDKs or security-critical libraries
  • Track record as a principal or lead engineer, setting technical direction while staying hands-on
  • Deep, non-negotiable security expertise: cryptographic primitives and protocols (Ed25519, JWT/JWKS, OAuth2/OIDC, PKI, TLS, signature schemes), threat modeling (STRIDE or equivalent), and translating threat models into concrete engineering work
  • Strong understanding of DNS and DNS security (DNSSEC, TXT records, resolution) and how DNS records can anchor cryptographic identity
  • Working familiarity with the agentic AI ecosystem (agent identity, MCP, A2A patterns)
  • Minimal travel expected; occasional on-sites as needed
  • Ability to work across time zones as part of a global organization as needed

Preferred Qualifications

  • Experience contributing to or reviewing IETF/security standards drafts
  • Background in identity protocols (WebAuthn, DID, Verifiable Credentials)
  • Knowledge of supply-chain security risks and mitigations

Physical Requirements

  • Prolonged periods of sitting at a desk and working on a computer
  • Must be able to lift up to 15 pounds at times

Benefits & conditions

The U.S. base salary range for this full-time position is $210,000 - $275,000 (flexibility based on experience) plus benefits as described below. In addition, the successful candidate will be eligible to receive other compensation from time to time in the form of discretionary and/or nondiscretionary bonuses and long-term incentive plan. Actual compensation will be influenced by a candidate’s qualifications, internal employee equity considerations, and location. We will not ask for information about a candidate’s current or past compensation for purposes of developing an offer of employment.

US team members (and their spouses, domestic partners, and/or dependent children) are covered by generously subsidized medical, dental, and vision insurance which includes company contributions to a Health Savings Accounts. Team members are also covered by company-paid life and disability insurance and have the option of participating in employee-paid supplemental life, accidental death and dismemberment, critical illness, and accident insurance. In addition, team members can enroll in the company’s 401(k) plan with up to a 5% match. You receive 15 days of paid vacation yearly, increasing to 20 days after one year. Additionally, you get 5 days of paid sick leave, 13 paid holidays, and 20 weeks of paid parental leave for birthing parents, 12 weeks for others. Also, there’s an opportunity for tuition reimbursement for qualifying expenses.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all