Temporal Technologies Logo

Temporal Technologies

Staff Cloud Security Engineer

Posted 11 Days Ago
Remote
Hiring Remotely in United States
176K-289K Annually
Senior level
Remote
Hiring Remotely in United States
176K-289K Annually
Senior level
Secure Temporal’s multi-cloud platform across AWS, GCP, and Azure by embedding security into infrastructure and application architecture. Responsibilities include threat modeling, risk assessment, Kubernetes hardening, multi-tenant isolation, gRPC and mTLS security, service mesh configuration, cloud security posture management with Wiz, secrets management, encryption, compliance policy development, engineering partnership, and on-call participation. The role also contributes to responsible AI practices and security for distributed workflow systems.
The summary above was generated by AI
Role Summary

Join our dynamic team as a Staff Cloud Security Engineer, where you'll play a pivotal role in securing the Temporal cloud environment for our customers. In this position, you'll work closely with our infrastructure teams, software engineering teams, and customers to build security deeply into our platform across multiple clouds. You'll also help shape how we use AI responsibly in both our infrastructure and our engineering processes. We're looking for individuals who are passionate about enabling engineering teams to build and ship securely, serving as trusted security partners across the organization.

What You’ll Do
  • Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others).

  • Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems.

  • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries.

  • Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication.

  • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers.

  • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy.

  • Able to participate in on-call rotation.

What You’ll Bring
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).

  • 5+ years in cloud security or a related role.

  • Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.

  • Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.

  • Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.

  • Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc).

  • A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages

  • Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.

  • Proficiency in Go; familiarity with Python. Go is Temporal's primary server and SDK language.

  • Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).

  • Excellent communication and ability to explain complex security concepts to non-technical stakeholders.

  • Excellent collaboration and communication skills.

Nice to Have
  • Prior experience with Temporal, Cadence, or similar workflow orchestration platforms and an understanding of workflow history, replay semantics, and scheduling internals.

  • FedRAMP, SOC 2 Type II, or ISO 27001 experience, particularly in the context of cloud-native SaaS.

  • Open Source automation or automation projects.

  • Expertise in other areas of security (AppSec, CorpSec, GRC)

  • Security conference talks or published research.

Temporal Technologies is an Equal Opportunity Employer. Temporal Technologies does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need. We embrace and celebrate differences and diversity.

Temporal is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist.

Similar Jobs

27 Days Ago
Remote
USA
190K-220K Annually
Senior level
190K-220K Annually
Senior level
Artificial Intelligence • Insurance • Software • Automation
Design and scale secure AWS environments, build and maintain Terraform IaC and pipelines, lead security assessments and incident response, integrate security into CI/CD, define IAM/encryption/network controls, monitor and investigate cloud threats, and coach teams on cloud security best practices.
Top Skills: AntivirusAWSBashCi/CdEdrEncryptionIamLogging/MonitoringMdmNetwork SecurityPowershellPythonTerraformTypescript
One Month Ago
Remote or Hybrid
152K-250K Annually
Senior level
152K-250K Annually
Senior level
Healthtech • Social Impact • Software
Own and build Grow Therapy's data security infrastructure: automated data classification, field-level masking/tokenization, encryption and key management, secure data connectors to AI tooling, and access controls. Define a multi-year vision, implement pipelines and services, and partner across Data, Engineering, and Detection & Response to make secure-by-default the company standard.
37 Minutes Ago
In-Office or Remote
153K-239K Annually
Senior level
153K-239K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads Boeing’s Systems Engineering, Integration and Test organization for the Sapphire program. Owns SEIT standards, governance, CONOPS, archetype roadmaps, engineering toolchains, requirements traceability, integration testing, KPIs, and continuous improvement. Provides technical leadership across engineering teams and IPTs, removes execution blockers, presents readiness evidence to executives, and drives repeatable delivery across PLM, ERP, MES, and related enterprise systems. Up to 20% travel may be required.
Top Skills: AdoAgileAlmBorisDigital ThreadDoorsErpIcdsJIRAMbseMesMicrosoft PlannerMicrosoft ProjectMiddlewareMomPdmPlmPolarionPower BIRequirements ManagementTeamcenterTest Automation

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account