← Back to results

Principal Software Engineer (Java) - Security - Elasticsearch

Lead the architecture and design of Elasticsearch's security features, focusing on high-performance security at scale.

Location
United Kingdom
Compensation
Not disclosed
Level
principal
Type
full time

Posted by employer 17 hours ago

First seen on Joblaze 1 hour ago

Last verified on the company career page 1 hour ago

What you'll build

  • Own core security initiatives from architecture to production
  • Lead technical design for major security components
  • Optimize security performance in distributed systems
  • Monitor advancements in security best practices
  • Drive vulnerability management efforts

Must have

  • Deep knowledge of Java internals and JVM memory management
  • Proven experience in designing scalable authorization systems
  • Solid comprehension of distributed systems security
  • Deep knowledge of edge identity protocols

Nice to have

  • Knowledge of cipher suites and TLS handshakes
  • Familiarity with Post-Quantum Cryptography
  • Hands-on experience with FedRAMP and SOC 2 requirements

AI in the day-to-day

Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation.

Not disclosed in this posting: compensation, years of experience, work arrangement, visa sponsorship.

Benefits

Volunteer Time Off Flexible Work Schedule Generous Vacation Days Health Insurance Parental Leave

Joblaze summary

In the role of Principal Software Engineer for Elasticsearch's Security team, the individual will lead the design and implementation of critical security features, including authentication and authorization. Proficiency in Java, distributed systems, and security protocols is essential, along with experience in scalable authorization systems. This position is suited for a senior engineer with a strong background in security architecture and a collaborative mindset, capable of mentoring others and driving initiatives across teams.

Joblaze insights

  • Listed today — first seen on Joblaze October 8, 2026. Last confirmed on Elastic's careers page October 8, 2026.

Quick facts

What's the tech stack?
Joblaze extracted these technologies from the posting: ABAC, Cryptography, Elasticsearch, Java, OAuth 2.0, RBAC.
What seniority level is this role?
Elastic targets principal-level candidates for this position.
Is this full-time or contract?
Full-time for this Principal Software Engineer (Java) - Security - Elasticsearch role at Elastic.

From the original posting

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

What is The Role

We are seeking a Principal Software Developer to join the Elasticsearch Security team. In this role, you will lead the architecture and design of Elasticsearch's main features. These features include authentication, authorization, and tenant isolation.

You will work with engineering and product leaders at Elastic. Your goal is to provide high-performance security at all levels. This includes ensuring that our distributed data store has top-quality security at scale.

What You Will Be Doing

  • Owning core security initiatives from architecture to production, focusing on the delivery of new critical features. Leading the technical design, plan, and execution for major security components inside the Elasticsearch core engine.
  • Developing the foundational security models for intricate features.
  • Optimizing security performance at scale in distributed systems environments.
  • Applying cryptographic solutions to address genuine customer use cases.
  • Ensuring robust data isolation within shared infrastructure supporting disparate customers.
  • Monitoring and applying the latest advancements and best practices in security. This includes authentication, identity management, cryptography, and data access management.
  • Collaborating with peers across the company to embed security into new customer features from the outset.
  • Drive vulnerability management efforts by collaborating closely with the InfoSec team to proactively identify, assess, and remediate security risks.
  • Leverage AI-driven tools to automate vulnerability triage, prioritization, and preliminary investigation, streamlining security workflows and reducing manual intervention.
  • Mentoring and coaching other engineers, fostering a culture of technical excellence and security-first development.

What You Bring

  • You have deep knowledge of Java internals and JVM memory management. You understand how concurrency models work. You can write code that is high-performance, thread-safe, and lock-free. This experience includes working with large open-source and enterprise codebases.
  • You have proven experience in designing and building systems for authorization that can scale. This includes deep experience designing scalable RBAC/ABAC models and token validation pipelines. It includes permission compilation and distributed cache invalidation strategies.
  • You have a solid comprehension of distributed systems security, including node-to-node mutual trust, zero-trust transport, partition tolerance, and cluster state propagation.
  • You have a deep knowledge of edge identity protocols (OAuth 2.0, SAML).
  • You have a proven track record of using AI to accelerate development, debug complex systems, and optimize code, while still owning the final outcomes.
  • You possess the ability to collaborate across functions and teams and seamlessly transition between different projects, codebases, or teams based on business priorities
  • You can work autonomously, drive decisions, and lead a distributed team by leveraging asynchronous, direct, and transparent communication.

Bonus Points

  • Knowledge of cipher suites, TLS handshakes, and PKI/certificate lifecycle management.
  • Cryptographic methods considering memory usage and delays.
  • Familiarity with the implications of Post-Quantum Cryptography (PQC) and readiness to support the migration of services to quantum-resistant cryptographic algorithms.
  • Hands-on experience mapping engine-level technical controls to FedRAMP (Moderate/High), FIPS 140, and SOC 2 requirements.
  • Experience working on the internals of a data store or search engine.

Additional Information - We Take Care of Our People

Please see here for our Privacy Statement.

Standard company text repeated across Elastic's postings is omitted here.

Similar positions