Staff Cloud Security Engineer

Posted Yesterday
Hiring Remotely in Opportunity, WA, USA
In-Office or Remote
225K-275K Annually
Senior level
Software
The Role
Lead cloud security for Temporal's multi-cloud platform by integrating security into architecture, threat modeling distributed workflow systems, securing gRPC/mTLS/service mesh, managing cloud security posture with tools like Wiz, enforcing secrets and encryption patterns, and partnering with engineering teams while participating in on-call rotation.
Summary Generated by Built In
About Us
Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster. We are on a mission to be the reliable foundation of every developer’s toolbox, and are building the team that will make that happen.
 
Our values guide us —they are present in how we show up, make decisions, and work together to make an impact. We’re curious, driven, collaborative, genuine and humble.
 
Temporal is growing and we are looking for those who share our values, challenge 'standard' thinking, and want to influence our future. If you have a passion for improving the developer experience, building world-class open-source software and communities, and want to be a part of our amazing team, we'd love to hear from you!
Summary

Join our dynamic team as a Staff Cloud Security Engineer, where you'll play a pivotal role in securing the Temporal cloud environment for our customers. In this position, you'll work closely with our infrastructure teams, software engineering teams, and customers to build security deeply into our platform across multiple clouds. You'll also help shape how we use AI responsibly in both our infrastructure and our engineering processes. We're looking for individuals who are passionate about enabling engineering teams to build and ship securely, serving as trusted security partners across the organization.

What You’ll Do
  • Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others).
  • Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems.
  • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries.
  • Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.
  • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.
  • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy.
  • Able to participate in on-call rotation.
What You’ll Bring
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
  • 5+ years in cloud security or a related role.
  • Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.
  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
  • Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
  • Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc).
  • A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages
  • Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
  • Proficiency in Go; familiarity with Python. Go is Temporal's primary server and SDK language.
  • Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).
  • Excellent communication and ability to explain complex security concepts to non-technical stakeholders.
  • Excellent collaboration and communication skills.
Nice to Have
  • Prior experience with Temporal, Cadence, or similar workflow orchestration platforms and an understanding of workflow history, replay semantics, and scheduling internals.
  • FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.
  • Open Source automation or automation projects.
  • Expertise in other areas of security (AppSec, CorpSec, GRC)
  • Security conference talks or published research.
Compensation
  • The estimated pay range for this role is $225,000 - $275,000, depending on qualifications and location.
  • This role is eligible to participate in Temporal's equity plan.
Compensation ranges reflect salary and commission compensation (when applicable) across several geographic markets. Employment offers carefully consider multiple factors, including prior experience, knowledge, expertise, skillset, market location, and job level assessed during the interview process.
 
Employee benefits and perks below are for full-time employees, part-time or temporary positions are excluded. 
 
U.S. Benefits 
  • Unlimited PTO, 12 Holidays + 2 Floating Holidays
  • 100% Premiums Coverage for Medical, Dental, and Vision
  • AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
  • Empower 401K Plan
  • Additional Perks for Learning & Development, Lifestyle Spending, Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!
International Benefits

Paid Time Off (PTO) and Benefits outside the United States vary by country, and are issued in partnership with Remote.com.  Additionally, Temporal offers perks to all international employees for learning & career development, a lifestyle spending account, home office setup, professional memberships, work-from-home meals, and access to the Calm app for mental wellness.

Travel

Temporal is a globally distributed, collaborative team that values opportunities for in-person connection. Occasional travel may be required for company events, team offsites, and other meaningful moments that bring us together.


Temporal Technologies is an Equal Opportunity Employer. Temporal Technologies does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need. We embrace and celebrate differences and diversity.
 
Temporal is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist.
 
We are not working with external recruitment agencies, thanks.

Skills Required

  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
  • 5+ years in cloud security or related role
  • Experience securing multi-cloud environments (AWS, GCP, Azure)
  • Proficiency in Go
  • Familiarity with Python
  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control
  • Experience with multi-tenant security architecture, data plane isolation, control plane hardening, and cross-tenant data leakage prevention
  • Experience with secrets management at scale (e.g., HashiCorp Vault, AWS Secrets Manager)
  • Experience with payload encryption patterns such as codec servers for protecting sensitive workflow data
  • Strong command of gRPC security, mTLS certificate management, and service mesh architectures (Istio, Envoy)
  • Experience managing cloud security posture using tools such as Wiz (misconfiguration detection, compliance monitoring, remediation)
  • Experience conducting threat modeling and risk assessments for distributed systems
  • Proven partnership with engineering and infrastructure teams to integrate security into access and posture
  • Able to participate in on-call rotation
  • Excellent communication skills and ability to explain complex security concepts to non-technical stakeholders
  • Deep understanding of application architecture and ability to identify vulnerabilities across multiple programming languages
  • Strong opinions and experience evaluating the use of AI in security workflows (assessments, threat models, testing)
  • Prior experience with Temporal, Cadence, or similar workflow orchestration platforms
  • FedRAMP, SOC 2 Type II, or ISO 27001 experience in cloud-native SaaS
  • Security conference talks or published research / Open source automation contributions

Temporal Technologies Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Temporal Technologies and has not been reviewed or approved by Temporal Technologies.

  • Healthcare Strength Healthcare coverage is described as 100% employer-paid for medical, dental, and vision, with AD&D, short- and long-term disability, and life insurance included. Feedback suggests this breadth and cost coverage is a strong differentiator for a remote-first employer.
  • Leave & Time Off Breadth Time off includes unlimited PTO alongside 12 standard holidays and 2 floating holidays. Feedback suggests this structure supports rest and recharge across teams.
  • Wellbeing & Lifestyle Benefits Wellbeing and remote-work support include a home office stipend, internet reimbursement, WFH meals, Calm app access, a lifestyle spending account, and learning/professional membership budgets. Feedback suggests these perks enhance overall total rewards beyond base pay.

Temporal Technologies Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bellevue, Washington
501 Employees
Year Founded: 2019

What We Do

Temporal develops and distributes the world's leading open source durable execution system. We make code fault tolerant, durable and simple. Innovative companies like Datadog, Glovo, Indeed, Netflix, Qualtrics, Remitly, Snap and Yum! Brands build their services and applications with Temporal to make them reliable to run, productive to enhance and easy to troubleshoot and repair. More than a decade in the making, Temporal is powered by veterans behind some of the industry's most loved systems technologies, programming frameworks and open source communities as well as investors like Amplify Partners, Sequoia Capital and Index Ventures.

Similar Jobs

Lob Logo Lob

Security Engineer

Logistics • Marketing Tech • Software
Easy Apply
Remote
United States
125 Employees
198K-220K Annually

Assured Logo Assured

Cloud Security Engineer

Artificial Intelligence • Insurance • Software • Automation
Remote
USA
98 Employees
190K-220K Annually
Remote
USA
2000 Employees
174K-320K Annually
Remote
USA
2000 Employees
174K-320K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account