Senior Security Engineer, PKI & Secrets
San Francisco, CA - USA
Job Summary
What Youll Do:
The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure by design from data centers and GPU fleets to the platform layers powering our customers AI workloads. The PKI & Secrets team owns the cryptographic infrastructure underpinning the confidentiality integrity and authenticity of CoreWeaves data and systems: PKI secrets management HSMs key management and code signing.
We partner with teams across the company to deliver cryptographic services that are secure reliable and easy to use at scale.
About the Role:
As a Senior Security Engineer on the PKI & Secrets team you will shape how CoreWeave manages cryptographic infrastructure across its global fleet. Youll design and operate PKI hierarchies secrets management platforms HSM infrastructure and key management systems; working hands-on with engineering teams to integrate these capabilities into their services and workflows.
In this role you will:
- Contribute to the design implementation and operation of CoreWeaves PKI infrastructure including CA hierarchies issuance policies certificate lifecycle management and trust distribution across Kubernetes clusters and bare-metal hosts.
- Manage and evolve secrets management platforms including access policies secret lifecycle governance and integration patterns using External Secrets Operator and cert-manager.
- Operate and scale HSM infrastructure including PKCS#11 integration key ceremony procedures and high-availability designs backing our certificate authorities and signing services.
- Contribute to the design of key management and data encryption solutions for internal and customer-facing use cases including envelope encryption and KMS API design.
- Deliver PKI-based solutions supporting workload identity mutual TLS and hardware attestation.
- Maintain and extend code signing infrastructure for firmware images UEFI binaries container images and application binaries.
- Develop and enforce cryptographic best practices and policies and contribute to post-quantum cryptography readiness.
Who You Are:
- (5) years of experience in security engineering or infrastructure engineering.
- Strong understanding of PKI concepts including CA hierarchies certificate profiles issuance policies revocation and trust distribution.
- Hands-on experience operating HashiCorp Vault or similar secrets management platforms in production.
- Experience with hardware security modules (HSMs) PKCS#11 interfaces and key ceremony procedures.
- Solid understanding of applied cryptography: symmetric and asymmetric algorithms digital signatures envelope encryption and TLS.
- Proficiency in Go Python or similar languages with the ability to build production tooling and automation.
- Experience with Kubernetes including cert-manager trust-manager or External Secrets Operator.
- Demonstrated ability to drive cross-functional initiatives across infrastructure platform and product teams.
Preferred
- Experience operating PKI backed by HSMs in a cloud provider or hyperscaler environment.
- Familiarity with code signing workflows (Authenticode Cosign/Sigstore transparency logs timestamping).
- Experience with KMS design including customer-managed keys and multi-tenant key isolation.
- Understanding of hardware attestation and workload identity (TPM SPDM SPIFFE/SPIRE).
- Exposure to post-quantum cryptography standards and migration planning.
Wondering if youre a good fit
We believe in investing in our people and value candidates who can bring their own diversified experiences to our teams even if you arent a 100% skill or experience match. If some of this describes you wed love to talk.
- You think deeply about how trust is established in complex distributed systems and you enjoy making that infrastructure invisible to the teams that depend on it.
- Youre comfortable operating at multiple levels of abstraction from HSM key ceremonies to Kubernetes operator design and developer experience.
- Youre a pragmatic builder who ships durable solutions in fast-moving environments.
Why CoreWeave
At CoreWeave we work hard have fun and move fast! Were in an exciting stage of hyper-growth that you will not want to miss out on. Were not afraid of a little chaos and were constantly learning. Our team cares deeply about how we build our product and how we work together which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff the organizations growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry who will want to learn from you too. Come join us!
The base salary range for this role is $165000 to $242000. The starting salary will be determined based on job-related knowledge skills experience and market location. We strive for both market alignment and internal equity when determining addition to base salary our total rewards package includes a discretionary bonus equity awards and a comprehensive benefits program (all based on eligibility).
What We Offer
The range weve posted represents the typical compensation range for this role. To determine actual compensation we review the market rate for each candidate which can include a variety of factors. These include qualifications experience interview performance and location.
In addition to a competitive salary we offer a variety of benefits to support your needs including:
- Medical dental and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
Our Workplace
While we prioritize a hybrid work environment remote work may be considered for candidates located more than 30 miles from an office based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.
California Consumer Privacy Act - California applicants only
CoreWeave is an equal opportunity employer committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race color religion sex disability age sexual orientation gender identity national origin veteran status or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA) CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process unless such accommodation would cause an undue hardship. If reasonable accommodation is needed please contact: .
Export Control Compliance
This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information applicant must either be (A) a U.S. person defined as a (i) U.S. citizen or national (ii) U.S. lawful permanent resident (green card holder) (iii) refugee under 8 U.S.C. 1157 or (iv) asylee under 8 U.S.C. 1158 (B) eligible to access the export controlled information without a required export authorization or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may for legitimate business reasons decline to pursue any export licensing process.
Required Experience:
Senior IC
About Company
What We Offer The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and loc ... View more