# Senior Software Engineer - Identity, Data Security and Trust
**Company:** [Snowflake](https://scaleengineer.com/companies/snowflake)
Senior Software Engineer role at Snowflake focused on building the security backbone of their Data Cloud platform. You'll design and implement critical AI-native security capabilities, foundational identity and access management systems, and security infrastructure spanning secret management and encryption. This position requires 5+ years of distributed systems experience with proficiency in Java, C++, Python, Golang, or Rust, alongside strong foundational computer science skills and a track record of shipping production services at scale.
**Role:** Senior Software Engineer
**Seniority:** Senior
**Locations:** US-WA-Bellevue
**Salary:** 200000–287500 USD
[Apply](https://jobs.ashbyhq.com/snowflake/5f731aa9-26a6-4760-8941-9f4aff96864d)
Canonical: https://scaleengineer.com/jobs/snowflake/senior-software-engineer-identity-data-security-and-trust
---
## Responsibilities

- Design and Implement AI Security Capabilities: Architect and develop critical AI security capabilities including controlled, audited agent workflows, Model Context Protocol (MCP) server and client security, agent identity frameworks, and administrative guardrails that form the foundation for secure agentic enterprise adoption across Snowflake's platform.
- Build Identity and Access Management Systems: Develop and evolve foundational identity and access management (IAM) systems at scale, including authentication protocols, Single Sign-On (SSO) integrations, multi-factor authentication (MFA), OAuth/OIDC, SAML, SCIM, and fine-grained Role-Based Access Control (RBAC) supporting millions of objects and users.
- Design Core Security Infrastructure: Architect and develop security infrastructure spanning secret management, key management, service identity, and end-to-end encryption across a natively multi-cloud environment, ensuring data protection at every layer.
- Develop Security Monitoring and Enforcement Tools: Build and maintain comprehensive security tooling to define, monitor, enforce, and detect policy violations across the platform. Implement automation and self-service processes that increase developer autonomy while promoting secure-by-default engineering practices.
- Create Extensible Security Components: Design and implement extensible, plug-and-play platform components that enable first-party, second-party, and third-party security detectors, responders, and visualizations to be integrated with Snowflake's Trust Center.
- Develop Security Posture Assessments: Leverage industry-accredited benchmarks such as CIS to develop standards-based security posture assessments. Contribute to behavioral analytics pipelines and PII attribution capabilities that help detect, prevent, and respond to threats and abuse vectors.
- Collaborate Across Engineering Teams: Partner with engineering teams throughout the company to understand security pain points, requirements, and constraints. Deliver innovative security solutions that reduce friction and implementation complexity without compromising platform safety or compliance.
- Lead Secure Network Architecture Design: Design and enforce secure network architectures to actively defend against ransomware attacks and detect sophisticated data exfiltration attempts, ensuring resilience against evolving security threats.
- Maintain High Code Quality Standards: Participate in design reviews, code reviews, and on-call rotations. Hold a high bar for code quality, reliability, performance, and sound technical decision-making across the security infrastructure.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Related Field","description":"BS in Computer Science, Computer Engineering, or a related technical discipline such as mathematics, physics, or software engineering."}
- {"name":"Equivalent Practical Experience","description":"Equivalent practical engineering experience demonstrating mastery of core computer science concepts and production system design, with documented track record of shipping complex systems."}

### technical

- {"name":"Distributed Systems Design","description":"5+ years of industry experience designing, building, and operating large-scale distributed systems in production cloud environments with deep understanding of system scalability, fault tolerance, and eventual consistency patterns."}
- {"name":"Programming Language Proficiency","description":"Proficiency in one or more of Java, C++, Python, Golang, or Rust with demonstrated ability to write production-grade, maintainable code. Strong SQL skills for implementing data-driven features and security queries."}
- {"name":"Cloud Platform Experience","description":"Hands-on experience shipping and on-calling production services with a focus on availability, reliability, observability, and performance monitoring in cloud environments."}
- {"name":"Foundational Computer Science","description":"Strong computer science fundamentals including data structures, algorithms, systems design principles, and distributed computing concepts such as consensus, replication, and partitioning."}

### experience

- {"name":"5+ Years Production Systems Experience","description":"Minimum 5+ years of industry experience designing, building, and operating large-scale distributed systems in production cloud environments with demonstrated impact on system reliability and security."}
- {"name":"Production Service Operations","description":"Proven experience shipping and on-calling production services with measurable focus on maintaining high availability, reliability standards, and observable system health through comprehensive monitoring."}
- {"name":"Collaborative Engineering Approach","description":"Demonstrated collaborative, low-ego approach to software engineering. Comfortable iterating rapidly, incorporating feedback, and working effectively across product management, design, and peer engineering teams."}

## Skills

### required

- {"name":"Java","description":"Production-level proficiency in Java for building scalable, reliable backend services and distributed systems. Experience with modern Java frameworks and performance optimization."}
- {"name":"C++","description":"Strong C++ capabilities for systems-level programming, performance-critical components, or database/platform internals work. Understanding of memory management and concurrency primitives."}
- {"name":"Python","description":"Competency in Python for backend services, scripting, data analysis, or ML-adjacent security features. Experience with async frameworks and production deployment."}
- {"name":"Golang","description":"Proficiency in Golang for microservices, cloud-native applications, or systems programming. Understanding of goroutines, channels, and concurrent patterns."}
- {"name":"Rust","description":"Advanced Rust capabilities for systems programming, memory safety, and high-performance components. Experience with async Rust and performance optimization."}
- {"name":"SQL","description":"Solid SQL proficiency for writing complex queries, understanding query performance, and designing data models. Ability to optimize queries for large-scale analytical workloads."}
- {"name":"Distributed Systems Design","description":"Deep expertise in designing and building distributed systems including consensus protocols, replication strategies, eventual consistency, and fault tolerance mechanisms."}
- {"name":"Systems Design and Architecture","description":"Demonstrated ability to design scalable systems architecture, make sound technical trade-offs, and communicate technical decisions clearly across teams."}

### preferred

- {"name":"Identity and Access Management (IAM) Protocols","description":"Knowledge of IAM concepts and protocols including SAML, SCIM, OAuth, OIDC, Federation, Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC). Understanding of modern authentication flows and delegation patterns."}
- {"name":"Security Infrastructure","description":"Familiarity with security infrastructure domains such as secret management, key management, service identity, authentication, authorization, encryption, and cryptographic systems."}
- {"name":"Database Internals and Data Platforms","description":"Experience with database internals, query optimization engines, data platform systems, or data warehouse architecture. Understanding of columnar storage, indexing strategies, or distributed query processing."}
- {"name":"Machine Learning and Anomaly Detection","description":"Exposure to machine learning or AI systems, particularly applied to anomaly detection, behavioral analytics, risk classification, or security use cases. Experience with ML pipelines and feature engineering."}
- {"name":"Developer Platforms and Extensibility","description":"Contributions to developer platforms, Software Development Kits (SDKs), plugin architectures, or multi-tenant extensibility frameworks that enable third-party integrations."}
- {"name":"Kubernetes and Cloud Operations","description":"Experience deploying, configuring, and operating services on Kubernetes or production cloud platforms including AWS, Azure, or Google Cloud Platform (GCP). Understanding of container orchestration and cloud-native patterns."}
- {"name":"AI and Agentic Systems Security","description":"Familiarity with emerging AI and agentic systems, including Model Context Protocol (MCP), agent orchestration, AI safety, or governance frameworks for autonomous AI systems."}
- {"name":"Observability and Monitoring","description":"Strong experience with observability practices, distributed tracing, metrics collection, log aggregation, and building comprehensive monitoring systems for production services."}

## Tech stack

### tools

- {"name":"Kubernetes","description":"Container orchestration and management platform for deploying and scaling security services across distributed cloud environments."}
- {"name":"Docker","description":"Containerization platform for packaging security services, ensuring consistent deployment across development, testing, and production environments."}
- {"name":"Git and Version Control","description":"Distributed version control system for code management, collaboration, and maintaining audit trails of security infrastructure changes."}
- {"name":"Prometheus and Grafana","description":"Monitoring and observability stack for collecting metrics, building dashboards, and alerting on security service health and performance."}
- {"name":"Vault (HashiCorp)","description":"Secrets management tool for securely storing, rotating, and managing cryptographic keys, database credentials, and sensitive configuration."}
- {"name":"CI/CD Platforms","description":"Continuous Integration and Continuous Deployment pipelines (Jenkins, GitLab CI, or GitHub Actions) for automated testing, building, and deploying security services."}
- {"name":"AWS, Azure, and GCP","description":"Multi-cloud platforms where Snowflake's security infrastructure runs. Experience with cloud services, networking, identity services, and cloud security features."}

### others

- {"name":"CIS Benchmarks","description":"Industry-standard security benchmarks and frameworks for defining, assessing, and maintaining security posture standards across the platform."}
- {"name":"RBAC and Fine-grained Access Control","description":"Role-Based Access Control and attribute-based access control mechanisms for implementing least-privilege access policies at scale across millions of resources."}
- {"name":"Encryption and Cryptography","description":"End-to-end encryption, key management, cryptographic protocols, and secure communication channels for protecting sensitive data across the platform."}
- {"name":"Behavioral Analytics and Anomaly Detection","description":"Machine learning techniques for detecting unusual patterns, anomalous access, potential security threats, and malicious behavior in user and system activity."}
- {"name":"Secure Software Development Lifecycle (SSDLC)","description":"Security best practices integrated throughout the development process including code reviews, threat modeling, security testing, and vulnerability management."}
- {"name":"Model Context Protocol (MCP)","description":"Emerging protocol for standardizing AI agent integrations and interactions. Understanding of how to secure agentic systems, workflows, and orchestration."}

### databases

- {"name":"Snowflake Data Cloud","description":"Cloud-native data platform serving as the core system where security capabilities are built. Understanding of Snowflake's architecture, query engine, and multi-tenant design."}
- {"name":"PostgreSQL","description":"Relational database system commonly used for security-sensitive applications, user management, and operational data store for security services."}
- {"name":"Redis","description":"In-memory data store used for caching, session management, rate limiting, and real-time security decision-making in distributed systems."}
- {"name":"Elasticsearch","description":"Distributed search and analytics engine used for security event logging, threat detection, and searchable audit trails of platform activity."}

### languages

- {"name":"Java","description":"Primary backend language for building scalable distributed systems and security services. Used extensively for production services requiring high performance and reliability."}
- {"name":"C++","description":"Systems programming language for performance-critical security components and database internals. Provides fine-grained control over resources and memory."}
- {"name":"Python","description":"Used for backend services, security automation, data analysis pipelines, and machine learning integration for threat detection and behavioral analytics."}
- {"name":"Golang","description":"Cloud-native systems programming language for microservices, security infrastructure, and concurrent service development with lightweight concurrency primitives."}
- {"name":"Rust","description":"Modern systems programming language for memory-safe, high-performance components in cryptography, encryption, and critical security infrastructure."}
- {"name":"SQL","description":"Essential for querying large-scale datasets, implementing security analytics, PII detection, and compliance monitoring across Snowflake's data platform."}

### frameworks

- {"name":"OAuth 2.0 and OIDC","description":"Modern authentication and authorization frameworks for implementing federated identity, delegated access, and secure token-based authentication across distributed systems."}
- {"name":"SAML 2.0","description":"Enterprise security assertion markup language for Single Sign-On (SSO) implementations and identity federation in enterprise environments."}
- {"name":"SCIM (System for Cross-domain Identity Management)","description":"Standardized protocol for automating user provisioning, deprovisioning, and identity lifecycle management across cloud applications and services."}
- {"name":"Spring Framework","description":"Enterprise Java framework for building secure, scalable microservices and backend systems with integrated security libraries and dependency injection."}
- {"name":"Kubernetes","description":"Container orchestration platform for deploying, scaling, and managing containerized security services and microservices in production cloud environments."}

## Benefits

### benefits

## Compensation

- **max:** 0
- **min:** 0
- **currency:** 
- **stockOptions:** false

## Interview process

### steps

## Full description
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Senior Software Engineer across our Identity, Data Security and Trust organization. These teams builds the security backbone of Snowflake — enabling customers to confidently bring their most sensitive data and workloads to the Data Cloud, empowering every Snowflake engineer to deliver the most secure platform at scale, and giving customers the tools to monitor, achieve, and maintain a strong security, governance, privacy, and compliance posture. As the agentic era accelerates, these teams are at the forefront of building AI-native security capabilities that protect the world's data.

# AS A SENIOR SOFTWARE ENGINEER AT SNOWFLAKE, YOU WILL:

* Design and implement critical AI security capabilities — including controlled, audited agent workflows, MCP server and client security, agent identity frameworks, and admin guardrails — that form the foundation for secure agentic enterprise adoption
* Build and evolve foundational identity and access management systems, including authentication protocols, SSO integrations, multi-factor authentication, OAuth/OIDC, SAML, SCIM, and fine-grained RBAC that scales to millions of objects and users
* Design and develop core security infrastructure spanning secret management, key management, service identity, and end-to-end encryption across a natively multi-cloud environment
* Build and maintain security tooling to define, monitor, enforce, and detect policy violations across the platform; implement automation and self-service processes that increase developer autonomy and promote secure-by-default engineering
* Design and implement extensible, plug-and-play platform components that enable first-, second-, and third-party security detectors, responders, and visualizations to be built on top of Snowflake's Trust Center
* Leverage industry-accredited benchmarks (e.g., CIS) to develop standards-based security posture assessments; contribute to behavioral analytics pipelines and PII attribution capabilities that help detect, prevent, and respond to threats and abuse vectors
* Partner with engineering teams across the company to understand security pain points and deliver solutions that reduce friction without compromising safety
* Lead the design and enforcement of secure network architectures to actively defend against ransomware attacks and detect sophisticated data exfiltration attempts.
* Participate in design reviews, code reviews, and on-call rotations; hold a high bar for code quality, reliability, and sound technical decisions

# OUR IDEAL SENIOR SOFTWARE ENGINEER WILL HAVE:

* 5+ years of industry experience designing, building, and operating large-scale distributed systems in production cloud environments
* Strong foundational computer science skills — data structures, algorithms, systems design, and distributed computing
* Proficiency in one or more of Java, C++, Python, Golang, or Rust, with solid SQL skills for data-driven features
* Experience shipping and on-calling production services with a focus on availability, reliability, and observability
* A collaborative, low-ego approach to engineering — comfortable iterating quickly and working across PM, design, and peer engineering teams
* BS in Computer Science, Computer Engineering, or a related technical discipline, or equivalent practical experience

# BONUS POINTS FOR THE FOLLOWING:

* Knowledge of identity and access management concepts and protocols — SAML, SCIM, OAuth, OIDC, Federation, MFA, or RBAC
* Familiarity with security infrastructure domains such as secret management, key management, service identity, authentication, or authorization
* Experience with database internals, query engines, or data platform systems
* Exposure to machine learning or AI systems, particularly applied to anomaly detection, behavioral analytics, or risk classification
* Contributions to developer platforms, SDKs, or multi-tenant extensibility frameworks
* Experience deploying and operating services on Kubernetes or production cloud platforms (AWS, Azure, or GCP)

# WHY JOIN OUR IDENTITY, DATA SECURITY AND TRUST TEAM AT SNOWFLAKE?

These teams sit at a rare intersection: the security, identity, infrastructure, and customer trust layers of one of the fastest-growing data platforms in the world. You won't be maintaining someone else's security layer; you'll be defining it. These are teams that value craft, curiosity, and collaboration, and that take pride in making complex security invisible to the developers and customers who depend on it. If you want a role where your technical decisions matter and your growth is tied directly to the scale of the platform you're protecting — and you're energized by the challenge of securing the agentic era before it fully arrives — this is it.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: [careers.snowflake.com](http://careers.snowflake.com)
