Principal Security Engineer Cloud and Infrastructure Security
One Identity · Remote, UNAVAILABLE, IN · India · Remote
Posted Oct 6, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Overview
Principal Security Engineer Cloud and Infrastructure Security
One Identity · Information Security, Attack Surface
Principal individual contributor · India · Reports to the Director of Information Security
Why this role exists
The architecture set in this role decides which certifications One Identity can hold and which markets we can sell into. That is unusual commercial weight for an engineering seat, and it comes with a mandate from leadership to build the program behind it.
We sell on-premises and hosted solutions. Some products run as hosted services we operate in Azure and AWS. Others ship as software customers deploy in their own datacenters. Infrastructure security here has two audiences: the environments we run, and the base images, container definitions, and deployment defaults we publish, which become part of every customer's environment. A hardening decision made once is inherited by everyone who deploys it.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is its senior technical voice. Scope comes from what you design and automate, and from what engineering chooses to adopt.
What you'll do
Shape the architecture
Own security architecture across Azure and AWS: tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, workload isolation. Where a regulated market or a certification constrains a design, you're expected to know before it's committed.
Run our own products against real security requirements and tell us what you find. IT operates our privileged access controls on One Identity software, so you'll see how our products hold up under production pressure and take that back to the teams building them.
Bring engineering into architectural decisions early. Designs teams help shape are the ones that hold up in production.
Raise the engineering bar
Teams already build with infrastructure as code across both clouds. Raise the security ceiling inside that practice: hardened modules, secure-by-default landing zones and account baselines, and patterns teams reach for because they're better.
Extend policy as code across the pipeline and the platform so teams get a signal at commit time.
Own the hardened image pipeline for virtual machines and containers, covering the fleet we run and the images we publish: build, patch cadence, provenance, signing, and the automation that keeps both current.
Secure the container orchestration layer, including the reference architecture and secure defaults customers inherit when they deploy our products on their own clusters.
Set the security architecture for AI workloads: model and inference endpoint exposure, data boundaries and residency, identity for agents and service principals, secrets handling, and guardrails around AI tooling in the development lifecycle.
Reduce exposure and prove it
Own…