Skip to main content
Posted 23 July, 2026

Senior Software Engineer I - Key Management Systems

DigitalOcean
Bengaluru Full Time
Reference: 102_698976_7987503

We are seeking a Senior Software Engineer (IC3) to join our Security Products team working on Key Management Systems (KMS). Our KMS platform is foundational to DigitalOcean's security posture - managing the full lifecycle of cryptographic keys that protect customer data across the platform, from envelope encryption for block storage and databases to API credential management and secrets handling.

In this role, you will own significant technical workstreams within our KMS platform - not just implementing features, but shaping how cryptographic systems are designed, hardened, and operated. You will go deep on HSM integration, key lifecycle management, and compliance engineering, and will actively raise the security and technical quality of the team around you. If you are a strong engineer who wants to combine cryptographic depth with growing cross-team influence in one of the most security-critical domains at DigitalOcean, this is the team for you.

What You'll Do

  • Own Technical Workstreams: Design and build high-availability, security-critical key management services in Go, taking end-to-end ownership from design through production operation.
  • Drive Key Lifecycle Engineering: Lead the design and implementation of key generation, rotation, escrow, and destruction workflows - owning the design decisions, correctness guarantees, and audit trail requirements, not just the implementation.
  • Advance Envelope Encryption: Design and scale the DEK/KEK hierarchy that protects customer data at rest across Storage, Databases, and Inference workloads - anticipating cross-service dependencies and designing for clean key isolation boundaries.
  • Build for Compliance: Drive FIPS 140-2 and SOC 2 compliance requirements into the engineering design process, not just as a checklist post-implementation - including audit logging, key material handling policies, and cryptographic algorithm governance.
  • Proactively Harden Systems: Identify and remediate complex security vulnerabilities in key management flows - from side-channel exposure in cryptographic operations to privilege escalation paths in key access APIs.
  • Operational Excellence: Drive reliability and performance improvements for KMS services; lead incident response and postmortems for security-sensitive production events.
  • Mentor & Elevate: Mentor IC2 engineers through code reviews and design feedback, sharing knowledge in applied cryptography and security engineering best practices.

What You'll Add to DigitalOcean

  • Experience: 4-7 years of software engineering experience, with at least 1-2 years focused on cryptographic systems, key management, or security-critical distributed services.
  • Language Proficiency: Strong proficiency in Go and solid understanding of gRPC microservices architecture.
  • Cryptography Depth: Working knowledge of applied cryptographic primitives - AES-GCM, RSA, ECDSA, HMAC, key derivation functions (HKDF, PBKDF2) - and the ability to reason about correct usage, not just API invocation.
  • HSM & KMS Experience: Hands-on experience with Hardware Security Modules or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault, Thales/Luna, or equivalent).
  • Compliance Familiarity: Understanding of FIPS 140-2 requirements and how they constrain cryptographic implementation choices; familiarity with SOC 2 or other audit frameworks as they apply to key management.
  • Distributed Systems: Solid understanding of consensus, replication, and partitioning - able to design systems that maintain cryptographic correctness guarantees under failure conditions.
  • Cloud Native: Hands-on experience with Kubernetes, SQL (MySQL), and Infrastructure as Code (Terraform).
  • Communication: Able to collaborate effectively across teams (IAM, Storage, Databases, Inference) and clearly communicate security trade-offs to both engineers and non-security stakeholders.

Nice to Have

  • Experience with secrets management platforms (HashiCorp Vault, AWS Secrets Manager) and their integration patterns.
  • Familiarity with PKCS#11 or other HSM interface standards.
  • Exposure to key management interoperability standards (KMIP).
  • Prior work on customer-facing encryption products (BYOK, CMEK, customer-managed secrets).

*This job is located in Bengaluru, India

JR: 2026-7967

#LI-Hybrid

Sign up for Job Alerts