- Design and evolve encryption and key-management systems for hosted, VPC, and on-premises deployments
- Build controls to detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage
- Protect customer credentials and tokens from storage and access control through runtime use
- Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication
- Build Python services, libraries, and APIs that standardize security-critical behavior
- Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback
- Define technical approaches, write production code, plan migrations, and remain accountable for production behavior
- Take projects from investigation and design through implementation, migration, rollout, and operation
- Collaborate with established security and infrastructure teams when problems cross application and platform boundaries
Requirements
- 4+ years of experience building and operating production backend systems
- Strong professional experience with Python in a substantial production codebase
- Hands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees
- Depth in at least one of: encryption and key management; signing, authentication, sessions, or token infrastructure; multi-tenant isolation; sensitive-data processing; secure storage and runtime use of customer credentials
- Practical knowledge of applied cryptography
- Experience changing critical systems without disrupting existing customers or making previously stored data inaccessible
- Strong judgment around trust boundaries, failure modes, and the consequences of compromise
- Ability to take an ambiguous technical problem from investigation through production rollout
- Prior healthcare experience is helpful but not required
- Bonus: experience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation
- Bonus: PHI or PII detection, redaction, pseudonymization, or tokenization
- Bonus: PKI, certificate systems, or cryptographic signing
- Bonus: multi-tenant SaaS products handling sensitive customer data
- Bonus: experience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain
- Bonus: self-hosted, VPC, on-premises, or air-gapped deployments
- Bonus: AI-agent, LLM, or connector-based application architecture
- Bonus: startup or growth-stage product experience
Core Competencies
Demonstrates expertise in designing and implementing encryption and key-management systems, with a strong focus on security-critical product systems and sensitive data processing. Proficient in Python development for production environments, ensuring robust handling of customer credentials and compliance with security standards.
Highest-signal resume keywords
- Python Development
- Encryption And Key Management
- Sensitive Data Processing
- Applied Cryptography
- Security-Critical Systems
Hard Skills
- Encryption
- Key Management
- Token Infrastructure
- Multi-Tenant Isolation
- Sensitive Data Handling
- Production Code Development
- Security Controls Implementation
- Data Migration Planning
- Runtime Security Practices
- Observability
Soft Skills
- Strong Judgment
- Problem-Solving
- Collaboration
Industry Keywords
- PHI
- PII
- Healthcare
- Payments
- Financial Infrastructure
- Security-Sensitive Domains
- SaaS Products
Tools & Technologies
- HashiCorp Vault
- Cloud KMS
- HSMs
- PKI
- Certificate Systems
Senior Software Engineer – Encryption, PHI in san francisco at Unknown Company
This position is listed as full time and onsite.