Principal Software Engineer - Security - Elasticsearch

Elastic
$191,900 - $303,500Remote

About The Position

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI. We are seeking a Principal Software Engineer to join the Elasticsearch Security team. In this role, you will lead the architecture and design of Elasticsearch's main features. These features include authentication, authorization, and tenant isolation. You will work with engineering and product leaders at Elastic. Your goal is to provide high-performance security at all levels. This includes ensuring that our distributed data store has top-quality security at scale.

Requirements

  • Deep knowledge of Java internals and JVM memory management.
  • Understanding of how concurrency models work.
  • Ability to write code that is high-performance, thread-safe, and lock-free.
  • Experience working with large open-source and enterprise codebases.
  • Proven experience in designing and building systems for authorization that can scale.
  • Deep experience designing scalable RBAC/ABAC models and token validation pipelines.
  • Experience with permission compilation and distributed cache invalidation strategies.
  • Solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation.
  • Deep knowledge of edge identity protocols (OAuth 2.0, SAML).
  • Proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still owning the final outcomes.
  • Ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities.
  • Ability to work autonomously, drive decisions, and lead a distributed team by leveraging asynchronous, direct, and transparent communication.

Nice To Haves

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Knowledge of cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

Responsibilities

  • Owning core security initiatives from architecture to production, focusing on the delivery of new critical features.
  • Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine.
  • Developing the foundational security models for intricate features.
  • Optimizing security performance at scale in distributed systems environments.
  • Applying cryptographic solutions to address genuine customer use cases.
  • Ensuring robust data isolation within shared infrastructure supporting disparate customers.
  • Monitoring and applying the latest advancements and best practices in security. This includes authentication, identity management, cryptography, and data access management.
  • Collaborating with peers across the company to embed security into new customer features from the outset.
  • Drive vulnerability management efforts by collaborating closely with the InfoSec team to proactively identify, assess, and remediate security risks.
  • Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation, streamlining security workflows and reducing manual intervention.
  • Mentoring and coaching other engineers, fostering a culture of technical excellence and security-first development.

Benefits

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family in many locations
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings
  • Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with minimum of 16 weeks of parental leave
  • Stock program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service