Principal Software Engineer (Java) - Security - Elasticsearch
elastic
As Principal Software Developer on the Elasticsearch Security team, you will own architecture and delivery of core security features at scale. You’ll drive design across authentication, authorization, and tenant isolation, partnering with engineering and product leaders. You’ll optimize performance in a distributed data store and apply cryptography to real customer use cases. You’ll mentor engineers and collaborate company-wide to embed security into new features from the outset. This role offers a chance to shape secure, high-performance capabilities that enable Elastic to scale securely for Fortune 500 customers.
Pay / Benefits- Competitive pay
- Health coverage for you and family
- Flexible locations and schedules
- Generous vacation days
- Donations match up to $2000
- Volunteer hours (up to 40 per year)
- Own core security initiatives from architecture to production for critical features
- Lead technical design, plan, and execution of security components in Elasticsearch core engine
- Develop foundational security models for complex features
- Optimize security performance at scale in distributed environments
- Apply cryptographic solutions to customer use cases
- Ensure robust data isolation within shared infrastructure
- Monitor and apply latest security best practices (auth, identity, crypto, data access)
- Collaborate with cross-functional teams to embed security in new features from the start
- Drive vulnerability management with InfoSec to identify, assess, and remediate risks
- Leverage AI-driven tools to automate vulnerability triage and streamline security workflows
- Mentor and coach engineers to foster security-first development
- Deep knowledge of Java internals and JVM memory management
- Understanding of concurrency models and ability to write high-performance, thread-safe, lock-free code
- Experience designing scalable authorization systems (RBAC/ABAC) and token validation pipelines
- Solid understanding of distributed systems security (node-to-node trust, zero-trust transport, partition tolerance, cluster state)
- Knowledge of edge identity protocols (OAuth 2.0, SAML)
- Proven track record of using AI to accelerate development and debugging while owning outcomes
- Ability to collaborate across functions and transition between projects and codebases autonomously
- Strong sense of independent decision-making and distributed team leadership
- Collaborative
- Autonomous decision-making
- Strong communication across teams
- Java and JVM internals
- Concurrency and parallelism
- RBAC/ABAC design and token pipelines
Reference: WJ-747_30999961