Principal Security Engineer Cloud and Infrastructure Security
- Hiring from
- India
- Work type
- Remote
- Posted
Show job descriptionHide job description
Overview
Principal Security Engineer Cloud and Infrastructure Security
One Identity · Information Security, Attack Surface
Principal individual contributor · India · Reports to the Director of Information Security
Why this role exists
The architecture set in this role decides which certifications One Identity can hold and which markets we can sell into. That is unusual commercial weight for an engineering seat, and it comes with a mandate from leadership to build the program behind it.
We sell on-premises and hosted solutions. Some products run as hosted services we operate in Azure and AWS. Others ship as software customers deploy in their own datacenters. Infrastructure security here has two audiences: the environments we run, and the base images, container definitions, and deployment defaults we publish, which become part of every customer's environment. A hardening decision made once is inherited by everyone who deploys it.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is its senior technical voice. Scope comes from what you design and automate, and from what engineering chooses to adopt.
What you'll do
Shape the architecture
- Own security architecture across Azure and AWS: tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, workload isolation. Where a regulated market or a certification constrains a design, you're expected to know before it's committed.
- Run our own products against real security requirements and tell us what you find. IT operates our privileged access controls on One Identity software, so you'll see how our products hold up under production pressure and take that back to the teams building them.
- Bring engineering into architectural decisions early. Designs teams help shape are the ones that hold up in production.
Raise the engineering bar
- Teams already build with infrastructure as code across both clouds. Raise the security ceiling inside that practice: hardened modules, secure-by-default landing zones and account baselines, and patterns teams reach for because they're better.
- Extend policy as code across the pipeline and the platform so teams get a signal at commit time.
- Own the hardened image pipeline for virtual machines and containers, covering the fleet we run and the images we publish: build, patch cadence, provenance, signing, and the automation that keeps both current.
- Secure the container orchestration layer, including the reference architecture and secure defaults customers inherit when they deploy our products on their own clusters.
- Set the security architecture for AI workloads: model and inference endpoint exposure, data boundaries and residency, identity for agents and service principals, secrets handling, and guardrails around AI tooling in the development lifecycle.
Reduce exposure and prove it
- Own infrastructure vulnerability and exposure management end to end: discovery, prioritization weighing exploitability and reachability alongside severity, ownership routing, remediation tracking, verification. Hosted services and customer-deployed software have different release paths and the practice accounts for both.
- Elevate cloud posture and workload protection into a single practice spanning Azure and AWS. You set the platform direction, the coverage standard both clouds are held to, and the path findings take to the teams that own them.
- Drive the decisions on where agentic workflows belong in security engineering: where automation acts and where it recommends, how its output gets verified, and what has to hold true before teams trust it. Where a person still has to act, the finding arrives with owner, fix path, and rationale. Where we can act ourselves, it arrives as a pull request against the module, image definition, or policy that produced it. PRs, not tickets.
- Build so control evidence can be produced by query. Cloud, configuration, and network controls are assessed under ISO 27001 and SOC 2 today, with IRAP, ACN and PCI self-assessment ahead. A portfolio that keeps growing makes hand-assembled evidence unsustainable.
What we're looking for
Required
Ten or more years in security engineering or infrastructure engineering, with substantial time in cloud architecture. Equivalent depth counts.
- Deep cloud security architecture experience across Azure and AWS. Real depth in one, working command of the other.
- Hands-on work securing AI workloads or AI-enabled tooling within the last six months. This area moves fast enough that older experience doesn't carry, and we'll ask specifically what you built and when.
- Something you built that engineering teams adopted and kept using.
The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.
Also matters: enough seniority in infrastructure as code to improve on what strong teams already do; network security fundamentals applied to cloud, covering segmentation, private connectivity, egress control, and east-west traffic; container and Kubernetes security, image hardening, supply chain integrity, and secrets management; policy-as-code frameworks and a view on where enforcement belongs in the lifecycle; controls you designed that held up under an audit you were personally accountable for; judgment about which risks to carry and which to escalate.
Helpful: shipping software customers deploy themselves, FedRAMP or IRAP, a carve-out or large-scale cloud migration.
What you should know going in
This is a builder's seat with leadership behind it. You'll set the infrastructure security architecture for a newly independent company, with the backing to build a program rather than the job of holding one together. The work enables engineering directly and opens new markets. If you've wanted to define the direction, this is that seat.
Company Description
One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.
With team members around the globe, we intend to continue to grow revenues and add value to customers.
When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.
Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.
Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.
Why work with us?
Life at One Identity means collaborating with dedicated professionals with a passion for technology.
When we see something that could be improved, we get to work inventing the solution.
Our people demonstrate our winning culture through positive and meaningful relationships.
We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential.
Our team members’ health and wellness is our priority as well as rewarding them for their hard work.
One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.
All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.
One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages.
Come join us.
Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com.