
Role Summary
Join Temporal as a Staff Cloud Security Engineer to play a pivotal role in securing our cloud environment for customers. You will work closely with infrastructure teams, software engineering teams, and customers to build security deeply into our platform across multiple clouds. You'll also help shape how we use AI responsibly in both our infrastructure and engineering processes.
What You’ll Do
- Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across AWS, GCP, Azure, and others.
- Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model—identifying attack surfaces unique to durable, stateful distributed systems.
- Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment.
- Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.
- Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.
- Stay current on emerging cloud security standards and guidance (e.g., CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy.
- Participate in on-call rotation.
What You’ll Bring
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years in cloud security or a related role.
- Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.
- Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
- Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
- Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc.).
- Deep understanding of application architecture and design principles, with the ability to effectively identify vulnerabilities across multiple programming languages.
- Experience with secrets management at scale (e.g., HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
- Proficiency in Go; familiarity with Python. Go is Temporal's primary server and SDK language.
- Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).
- Excellent communication and ability to explain complex security concepts to non-technical stakeholders.
Nice to Have
- Prior experience with Temporal, Cadence, or similar workflow orchestration platforms.
- FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.
- Open source automation or automation projects.
- Expertise in other areas of security (AppSec, CorpSec, GRC).
- Security conference talks or published research.
Timezone overlap
UTC-8–-4
Open to
US
Sign in to track applications and earn points.