Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a Senior Software Engineer (IC3) to join our Security Products team working on Key Management Systems (KMS). Our KMS platform is foundational to DigitalOcean's security posture — managing the full lifecycle of cryptographic keys that protect customer data across the platform, from envelope encryption for block storage and databases to API credential management and secrets handling.
In this role, you will own significant technical workstreams within our KMS platform — not just implementing features, but shaping how cryptographic systems are designed, hardened, and operated. You will go deep on HSM integration, key lifecycle management, and compliance engineering, and will actively raise the security and technical quality of the team around you. If you are a strong engineer who wants to combine cryptographic depth with growing cross-team influence in one of the most security-critical domains at DigitalOcean, this is the team for you.
What You'll Do- Own Technical Workstreams: Design and build high-availability, security-critical key management services in Go, taking end-to-end ownership from design through production operation.
- Drive Key Lifecycle Engineering: Lead the design and implementation of key generation, rotation, escrow, and destruction workflows — owning the design decisions, correctness guarantees, and audit trail requirements, not just the implementation.
- Advance Envelope Encryption: Design and scale the DEK/KEK hierarchy that protects customer data at rest across Storage, Databases, and Inference workloads — anticipating cross-service dependencies and designing for clean key isolation boundaries.
- Build for Compliance: Drive FIPS 140-2 and SOC 2 compliance requirements into the engineering design process, not just as a checklist post-implementation — including audit logging, key material handling policies, and cryptographic algorithm governance.
- Proactively Harden Systems: Identify and remediate complex security vulnerabilities in key management flows — from side-channel exposure in cryptographic operations to privilege escalation paths in key access APIs.
- Operational Excellence: Drive reliability and performance improvements for KMS services; lead incident response and postmortems for security-sensitive production events.
- Mentor & Elevate: Mentor IC2 engineers through code reviews and design feedback, sharing knowledge in applied cryptography and security engineering best practices.
- Experience: 4–7 years of software engineering experience, with at least 1–2 years focused on cryptographic systems, key management, or security-critical distributed services.
- Language Proficiency: Strong proficiency in Go and solid understanding of gRPC microservices architecture.
- Cryptography Depth: Working knowledge of applied cryptographic primitives — AES-GCM, RSA, ECDSA, HMAC, key derivation functions (HKDF, PBKDF2) — and the ability to reason about correct usage, not just API invocation.
- HSM & KMS Experience: Hands-on experience with Hardware Security Modules or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault, Thales/Luna, or equivalent).
- Compliance Familiarity: Understanding of FIPS 140-2 requirements and how they constrain cryptographic implementation choices; familiarity with SOC 2 or other audit frameworks as they apply to key management.
- Distributed Systems: Solid understanding of consensus, replication, and partitioning — able to design systems that maintain cryptographic correctness guarantees under failure conditions.
- Cloud Native: Hands-on experience with Kubernetes, SQL (MySQL), and Infrastructure as Code (Terraform).
- Communication: Able to collaborate effectively across teams (IAM, Storage, Databases, Inference) and clearly communicate security trade-offs to both engineers and non-security stakeholders.
- Experience with secrets management platforms (HashiCorp Vault, AWS Secrets Manager) and their integration patterns.
- Familiarity with PKCS#11 or other HSM interface standards.
- Exposure to key management interoperability standards (KMIP).
- Prior work on customer-facing encryption products (BYOK, CMEK, customer-managed secrets).
*This job is located in Bengaluru, India
JR: 2026-7967
#LI-Hybrid
- We innovate with purpose. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
- We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
- We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
- We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
- DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.
Skills Required
- 4-7 years of software engineering experience with 1-2 years focused on cryptographic or key management systems
- Strong proficiency in Go
- Solid understanding of gRPC microservices architecture
- Working knowledge of applied cryptographic primitives (AES-GCM, RSA, ECDSA, HMAC, HKDF, PBKDF2)
- Hands-on experience with HSMs or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault, Thales/Luna, or equivalent)
- Familiarity with FIPS 140-2 requirements and SOC 2 audit frameworks as applied to key management
- Solid understanding of distributed systems concepts (consensus, replication, partitioning)
- Hands-on experience with Kubernetes
- Experience with SQL databases (MySQL)
- Experience with Infrastructure as Code (Terraform)
- Ability to collaborate across teams and communicate security trade-offs to technical and non-technical stakeholders
- Experience with secrets management platforms (HashiCorp Vault, AWS Secrets Manager) and integrations
- Familiarity with PKCS#11 or other HSM interface standards
- Exposure to KMIP or key management interoperability standards
- Prior work on customer-facing encryption products (BYOK, CMEK, customer-managed secrets)
DigitalOcean Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage is described as market‑leading across medical, dental, vision, and mental‑health, with company‑paid life and income‑protection. This positions core healthcare and protection benefits as a standout element of the package.
-
Parental & Family Support — Parental leave is characterized as above‑average, frequently highlighted alongside a phased return‑to‑work program. This indicates strong support for new parents beyond baseline policies.
-
Equity Value & Accessibility — The package includes recurring equity grants and access to an Employee Stock Purchase Plan. This provides meaningful ownership opportunities alongside cash compensation.
DigitalOcean Insights
What We Do
DigitalOcean is the Inference Cloud — a full-stack, production-ready cloud platform built to run AI applications with predictable performance, sustainable economics, and radically simpler operations at scale. We are built for teams turning AI into real products — not just training models. Our advantage is not fewer features, but fewer failure modes when operating AI at scale — combining minimal operational overhead, predictable cost efficiency, and a full-stack cloud that works as a system. Hyperscalers are broad by design. Neoclouds are infrastructure-first. DigitalOcean is inference-first — with a real cloud underneath. It combines inference-optimized compute, managed inference software, and integrated cloud capabilities that reduce operational burden for teams running real workloads. Inference is the foundation—not the boundary. Everything else builds on top of it.
Why Work With Us
At DO, we do career-defining work. We innovate with AI and build cutting-edge tech. Our rewards to match that intensity - to motivate you, recognize your impact, and give you what you need to thrive. If you have a growth mindset, like to think big and bold, and are energized by the fast-paced environment, you'll find your place here.
Gallery
DigitalOcean Offices
Remote Workspace
Employees work remotely.
We commit to both remote work and in-person collaboration. These ways of working are dependent on specific roles and are mutually agreed upon by employees. In the US, we are mainly remote. In our APAC locations, we have a hybrid in-office approach.
