Principal Engineer Cryptography @GoDaddy
Engineering
Salary usd 165,500 - 3..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Principal Engineer Cryptography @GoDaddy

1mth ago - GoDaddy is hiring a remote Principal Engineer Cryptography. πŸ’Έ Salary: usd 165,500 - 323,000 per year πŸ“Location: USA

Role Description

At GoDaddy, we are seeking an exceptional Principal Compliance Engineer - PKI with deep technical expertise to define requirements and guide the evolution of our Certificate Authority (CA) platform. Reporting to GoDaddy's Vice President Engineering Partners, you will translate industry standards into technical requirements, define specifications for compliance automation, and provide technical guidance for next-generation cryptographic systems. This role combines technical leadership with strategic requirements development, focusing on post-quantum cryptography readiness, certificate lifecycle automation, and CA infrastructure resilience.

What you'll get to do...

  • Technical Standards & Requirements Leadership
    • Actively participate in standards bodies such as the IETF, representing GoDaddy in working groups for TLS and related SSL standards.
  • CA Infrastructure & Systems Requirements
    • Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks.
    • Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems.
    • Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms.
    • Develop automation scripts for compliance testing and validation processes.
    • Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics.
    • Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures.
  • Cryptographic Systems & Innovation
    • Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains.
    • Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms.
    • Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials).
    • Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs.
  • Platform Requirements & Automation
    • Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks.
    • Specify requirements for scalable APIs and automation tools for certificate issuance, renewal, and revocation workflows.
    • Document specifications for self-service platforms and tools to reduce manual intervention in certificate operations.
    • Develop automated testing scripts and define requirements for continuous compliance monitoring systems with automated remediation capabilities.
  • Technical Collaboration & Documentation
    • Partner with security engineering teams on threat modeling, secure coding practices, and vulnerability management.
    • Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance.
    • Establish technical documentation standards and compliance engineering requirements for CA-related systems.
    • Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns.

Qualifications

  • 8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership.
  • Strong technical background in languages such as Go, Python, Java, or C++.
  • Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryptographic primitives.
  • Proven experience translating CA/Browser Forum Baseline Requirements into technical specifications, including controls for key generation, certificate issuance, and audit logging.
  • Systems engineering background with experience in distributed systems, API design, database architecture, and cloud infrastructure (AWS/GCP/Azure).
  • Strong ability to define requirements for PKI protocols (ACME, Certificate Transparency, OCSP/CRL) and translate compliance requirements into technical specifications, detailed engineering requirements, and test automation scripts.

Requirements

  • Advanced degree in Computer Science, Cryptography, Mathematics, or Electrical Engineering.
  • Experience researching and evaluating post-quantum cryptographic algorithms (NIST PQC finalists, hybrid modes).
  • Security certifications such as CISSP, CEH, or specialized cryptography credentials.
  • Experience with security audit processes (WebTrust for CAs, ETSI EN 319 411) from a technical implementation perspective.
  • Contributions to PKI-related projects (Boulder, cert-manager, OpenSSL, BoringSSL, etc.).
  • Experience defining requirements for high-availability systems design, hardware security modules (HSMs), and secure key ceremony procedures.
  • Knowledge of DevSecOps practices, CI/CD pipelines for security-critical systems, and infrastructure automation (Terraform, Kubernetes, Ansible).
  • Familiarity with cryptographic libraries (OpenSSL, BoringSSL, PKCS#11) and performance considerations for cryptographic operations.
  • Experience developing test automation scripts for compliance validation.

Benefits

  • Competitive pay.
  • Generous time off, parental and wellness leave.
  • Healthcare benefits including medical, dental, and vision insurance.
  • 401(k)-retirement plan.
  • Paid sick time and flexible time off.
  • Paid parental leave.
  • Life insurance and short- and long-term disability.
  • AD&D insurance.
  • Mental health or EAP programs.
  • Remote or hybrid work options.
  • Paid holidays and Wellness days.
  • Tuition assistance and adoption, surrogacy, and fertility benefits.
  • Dependent daycare and backup care benefits.
  • Employee stock purchase plan.
  • Financial education and advice.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Principal Engineer Cryptography @GoDaddy
Engineering
Salary usd 165,500 - 3..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,845+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later