> Markdown version of [/jobs/ext/926149-principal-software-engineer-security-engineering](https://www.wearedevelopers.com/jobs/ext/926149-principal-software-engineer-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Software Engineer (Security Engineering) - **Company:** Identity Digital - **Location:** Bellevue, WA, United States (Remote available) - **Salary:** $210,000.0 - $275,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Domain Name System Security Extensions, Domain Name System (DNS), Python (Programming Language), Key Management, OAuth, OpenID, Public Key Infrastructure, Software Engineering, TypeScript, Transport Layer Security, Golang - **Published:** June 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/job/detail/87435515/Principal-Software-Engineer-Security-Engineering ## About the Role * 10+ years of hands-on software engineering, building and shipping production systems * Bachelor's degree in a relevant field or equivalent experience * Fluency in TypeScript and at least one of Go or Python; depth across the stack from SDK to infrastructure * Proven experience building and shipping production SDKs or security-critical libraries * Track record as a principal or lead engineer, setting technical direction while staying hands-on * Deep, non-negotiable security expertise: cryptographic primitives and protocols (Ed25519, JWT/JWKS, OAuth2/OIDC, PKI, TLS, signature schemes), threat modeling (STRIDE or equivalent), and translating threat models into concrete engineering work * Strong understanding of DNS and DNS security (DNSSEC, TXT records, resolution) and how DNS records can anchor cryptographic identity * Working familiarity with the agentic AI ecosystem (agent identity, MCP, A2A patterns) * Minimal travel expected; occasional on-sites as needed * Ability to work across time zones as part of a global organization as needed Preferred Qualifications * Experience contributing to or reviewing IETF/security standards drafts * Background in identity protocols (WebAuthn, DID, Verifiable Credentials) * Knowledge of supply-chain security risks and mitigations Physical Requirements * Prolonged periods of sitting at a desk and working on a computer * Must be able to lift up to 15 pounds at times ## Description * Own the security architecture and threat model for the DNSid platform, SDKs, and supporting infrastructure (STRIDE analysis, attack surface review, trust boundaries) * Design and review the cryptographic core: signing, verification, key management, rotation, and revocation * Build and maintain the DNSid SDKs (TypeScript, Go, and Python) with security-first design and safe defaults * Define and enforce supply-chain security practices for the codebase and dependencies * Conduct security reviews of new features, integrations, and partner-facing implementations * Partner with the standards effort (IETF draft) so the security properties are sound and keep the implementation honest * Establish secure-by-default patterns for how third parties integrate DNSid (auth schemes, scope validation, token handling) * Own the security posture of the entire IDIL engineering org: secure deployment patterns, secrets management, audit readiness (SOC 2), and incident response * Actively models and promotes Identity Digital's core values through day-to-day interactions, behaviors, and decision-making * Other duties as assigned ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)