Careers

Principal Software Engineer / Manager, Security - India

Full Time
India

Team:  Engineering

Reports to:  VP of Engineering

Location:  Remote / Hybrid (global)

About Rafay Systems

Rafay Systems powers the GPU cloud and Kubernetes infrastructure behind some of the most demanding AI and modern application workloads in the world. We serve two fast-moving markets at once: the emerging Neo Cloud space, where GPU cloud and AI infrastructure providers build differentiated services on top of Rafay, and the enterprise space, where large organizations run AI and modern applications across their own clouds and data centers. We deliver our platform both as a multi-tenant SaaS service and as a self-managed, on-premises deployment, which means we secure everything from our own cloud control plane to software that runs inside our customers' most sensitive environments.

As GPU and AI infrastructure moves to the center of both Neo Cloud offerings and enterprise computing, the trust customers place in that infrastructure becomes a defining product attribute. We're looking for a security leader who can make security a first-class, differentiating property of the Rafay platform.

The Role

This is a hands-on technical leadership role that sits at the intersection of product engineering and security. You will own security as it is designed into the product, and you will run the security programs that keep the company and its customers protected and compliant. You'll work across the full footprint of our offering, both the SaaS control plane and the on-premises form factor, and you'll partner closely with engineering, product, and go-to-market teams.

We're deliberately flexible on the title. Depending on your background and how you want to grow, this can be shaped as an individual-contributor Principal Software Engineer focused on security, or as an Engineering Manager leading a small security team. You'll report directly to the VP of Engineering.

What You'll Do

Product security leadership

  • Serve as the security design authority for new software and features across the SaaS and on-premises products, embedding security into architecture from the earliest design stages rather than bolting it on afterward.
  • Lead the design and implementation of trusted computing capabilities, including hardware roots of trust, attestation, measured/secure boot, and confidential computing patterns relevant to GPU and multi-tenant workloads.
  • Own the architecture and implementation of secret management, covering the lifecycle of keys, tokens, and credentials, secure storage, rotation, and integration with customer-managed key and vault systems.
  • Drive network security design across the platform, including tenant isolation, segmentation, encryption in transit, zero-trust access patterns, and the boundaries between the SaaS control plane and customer-operated clusters.
  • Own the secure software development lifecycle (SDLC) end to end, defining and operationalizing secure coding standards, code and dependency scanning, CI/CD security gates, artifact signing, and software supply-chain integrity across both the SaaS and on-premises release pipelines.
  • Own the security architecture review process, serving as the design authority who reviews new services and features, produces and maintains threat models and reference architectures, and provides clear guidance that scales, so secure design becomes a shared engineering competency rather than a bottleneck.

Compliance and assurance

  • Lead the technical direction of the company's compliance programs, including SOC 2 Type 2, ISO 27001, and FIPS 140 validated cryptography, translating control requirements into concrete engineering work.
  • Apply working familiarity with the NIST 800 series (for example, 800-53 and 800-171) to prepare the platform for FedRAMP and other public-sector requirements.
  • Partner with auditors, GRC, and engineering teams to gather evidence, close gaps, and keep certifications current as the product evolves.

Security program execution

  • Own and mature the company's vulnerability management program, from scanning and triage through prioritization, remediation SLAs, and reporting across code, containers, dependencies, and infrastructure.
  • Build and run the penetration testing program, coordinating internal testing and third-party engagements, and driving findings to closure.
  • Write clear, credible security position documents, whitepapers, and customer-facing security narratives that explain how Rafay protects data and workloads, supporting sales, security questionnaires, and customer trust conversations.
  • Contribute to incident readiness and response, and help establish the metrics and cadences that demonstrate the security program is working.

Global and jurisdictional awareness

  • Account for the fact that Rafay and its customers operate across multiple jurisdictions, and factor regional data protection, sovereignty, and regulatory considerations (for example, GDPR and data-residency expectations) into design and program decisions.
  • Help the organization make informed, geography-aware choices about where and how data is stored, processed, and protected.

What We're Looking For

  • Significant experience in software or product security, ideally with time spent building or securing SaaS platforms and software distributed for on-premises or customer-managed deployment.
  • Deep, hands-on knowledge in several of: trusted/confidential computing, cryptography and secret management, network and infrastructure security, and cloud-native security (Kubernetes and containers strongly preferred).
  • Experience establishing or owning a secure SDLC and a security architecture review process, including secure coding practices, CI/CD security controls, and software supply-chain security.
  • Demonstrated experience taking one or more compliance programs (SOC 2 Type 2, ISO 27001, FIPS, or FedRAMP/NIST 800) from requirements to audited reality.
  • Track record of running security programs such as vulnerability management and penetration testing, with a bias for measurable outcomes.
  • Strong written communication: the ability to produce whitepapers, security posture documents, and design docs that hold up to both engineering and customer scrutiny.
  • Comfort operating as a technical leader, whether guiding as a principal IC or managing a small team, and the judgment to balance security rigor with shipping velocity.

Nice to Have

  • Direct FedRAMP authorization experience.
  • Familiarity with GPU, HPC, or AI/ML infrastructure and the specific isolation and trust challenges it raises.
  • Experience with hardware attestation, TPMs, or confidential-computing hardware (for example, SEV-SNP, TDX, or GPU confidential computing).
  • Prior success owning security narratives in enterprise sales cycles.

Why Rafay

You'll help define what secure, trustworthy GPU and AI infrastructure looks like for both Neo Cloud providers and enterprises, with the scope to shape both the product and the program, direct access to engineering leadership, and the ability to see your work reflected in real customer trust.

Rafay Systems is an equal opportunity employer. We welcome applicants of all backgrounds and are committed to building an inclusive team.

Max file size 10MB.
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
Your application has been successfully submitted.
Oops! Something went wrong while submitting the form.