About the role
What will you do at CoreWeave?
CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers,
CoreWeave delivers a platform of technology, tools, and teams that enables
innovators to build and scale AI with confidence. Trusted by leading AI labs,
startups, and global enterprises, CoreWeave combines superior infrastructure
performance with deep technical expertise to accelerate breakthroughs and turn
compute into capability. Founded in 2017, CoreWeave became a publicly traded
company (Nasdaq: CRWV) in March 2025. Learn more at www.coreweave.com
[http://www.coreweave.com/].
WHAT YOU'LL DO:
The Security Foundations organization at CoreWeave keeps CoreWeave Cloud secure
by design, from data centers and GPU fleets to the platform layers powering our
customers' AI workloads. The PKI & Secrets team owns the cryptographic
infrastructure underpinning the confidentiality, integrity, and authenticity of
CoreWeave's data and systems: PKI, secrets management, HSMs, key management, and
code signing.
We partner with teams across the company to deliver cryptographic services that
are secure, reliable, and easy to use at scale.
ABOUT THE ROLE:
As a Senior Security Engineer on the PKI & Secrets team, you will shape how
CoreWeave manages cryptographic infrastructure across its global fleet. You'll
design and operate PKI hierarchies, secrets management platforms, HSM
infrastructure, and key management systems; working hands-on with engineering
teams to integrate these capabilities into their services and workflows.
IN THIS ROLE, YOU WILL:
* Contribute to the design, implementation, and operation of CoreWeave's PKI
infrastructure, including CA hierarchies, issuance policies, certificate
lifecycle management, and trust distribution across Kubernetes clusters and
bare-metal hosts.
* Manage and evolve secrets management platforms, including access policies,
secret lifecycle governance, and integration patterns using External Secrets
Operator and cert-manager.
* Operate and scale HSM infrastructure, including PKCS#11 integration, key
ceremony procedures, and high-availability designs backing our certificate
authorities and signing services.
* Contribute to the design of key management and data encryption solutions for
internal and customer-facing use cases, including envelope encryption and KMS
API design.
* Deliver PKI-based solutions supporting workload identity, mutual TLS, and
hardware attestation.
* Maintain and extend code signing infrastructure for firmware images, UEFI
binaries, container images, and application binaries.
* Develop and enforce cryptographic best practices and policies, and contribute
to post-quantum cryptography readiness.
WHO YOU ARE:
* (5)+ years of experience in security engineering or infrastructure
engineering.
* Strong understanding of PKI concepts including CA hierarchies, certificate
profiles, issuance policies, revocation, and trust distribution.
* Hands-on experience operating HashiCorp Vault or similar secrets management
platforms in production.
* Experience with hardware security modules (HSMs), PKCS#11 interfaces, and key
ceremony procedures.
* Solid understanding of applied cryptography: symmetric and asymmetric
algorithms, digital signatures, envelope encryption, and TLS.
* Proficiency in Go, Python, or similar languages, with the ability to build
production tooling and automation.
* Experience with Kubernetes, including cert-manager, trust-manager, or
External Secrets Operator.
* Demonstrated ability to drive cross-functional initiatives across
infrastructure, platform, and product teams.
PREFERRED
* Experience operating PKI backed by HSMs in a cloud provider or hyperscaler
environment.
* Familiarity with code signing workflows (Authenticode, Cosign/Sigstore,
transparency logs, timestamping).
* Experience with KMS design, including customer-managed keys and multi-tenant
key isolation.
* Understanding of hardware attestation and workload identity (TPM, SPDM,
SPIFFE/SPIRE).
* Exposure to post-quantum cryptography standards and migration planning.
WONDERING IF YOU'RE A GOOD FIT?
We believe in investing in our people, and value candidates who can bring their
own diversified experiences to our teams, even if you aren't a 100% skill or
experience match. If some of this describes you, we'd love to talk.
* You think deeply about how trust is established in complex distributed
systems — and you enjoy making that infrastructure invisible to the teams
that depend on it.
* You're comfortable operating at multiple levels of abstraction, from HSM key
ceremonies to Kubernetes operator design and developer experience.
* You're a pragmatic builder who ships durable solutions in fast-moving
environments.
WHY COREWEAVE?
At CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage
of hyper-growth that you will not want to miss out on. We’re not afraid of a
little chaos, and we’re constantly learning. Our team cares deeply about how we
build our product and how we work together, which is represented through our
core values:
* Be Curious at Your Core
* Act Like an Owner
* Empower Employees
* Deliver Best-in-Class Client Experiences
* Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We
foster an environment that encourages collaboration and enables the development
of innovative solutions to complex problems. As we get set for takeoff, the
organization's growth opportunities are constantly expanding. You will be
surrounded by some of the best talent in the industry, who will want to learn
from you, too. Come join us!
The base salary range for this role is $165,000 to $242,000. The starting salary
will be determined based on job-related knowledge, skills, experience, and
market location. We strive for both market alignment and internal equity when
determining compensation. In addition to base salary, our total rewards package
includes a discretionary bonus, equity awards, and a comprehensive benefits
program (all based on eligibility).
What We Offer
The range we’ve posted represents the typical compensation range for this role.
To determine actual compensation, we review the market rate for each candidate
which can include a variety of factors. These include qualifications,
experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support
your needs. The benefits below reflect our US-based offerings; for roles in
other locations, benefits vary and are shared during the hiring process. These
include:
* Medical, dental, and vision insurance - 100% paid for by CoreWeave
* Company-paid Life Insurance
* Voluntary supplemental life insurance
* Short and long-term disability insurance
* Flexible Spending Account
* Health Savings Account
* Tuition Reimbursement
* Ability to Participate in Employee Stock Purchase Program (ESPP)
* Mental Wellness Benefits through Spring Health
* Family-Forming support provided by Carrot
* Paid Parental Leave
* Flexible, full-service childcare support with Kinside
* 401(k) with a generous employer match
* Flexible PTO
* Catered lunch each day in our office and data center locations
* A casual work environment
* A work culture focused on innovative disruption
California Applicants
California Consumer Privacy Act
[https://drive.google.com/file/d/1gPBRBhUNAMBmj7Yn4_M-hCugm7ZJD4hr/view? usp=sharing]
Equal Opportunity & Accommodations
CoreWeave is an equal opportunity employer, committed to fostering an inclusive
and supportive workplace. All qualified applicants and candidates will receive
consideration for employment without regard to race, color, religion, sex,
disability, age, sexual orientation, gender identity, national origin, veteran
status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities
Act (ADA)
[https://www.eeoc.gov/laws/guidance/fact-sheet-disability-discrimination],
CoreWeave will ensure that qualified applicants and candidates with disabilities
are provided reasonable accommodations for the hiring process, unless such
accommodation would cause an undue hardship. If reasonable accommodation is
needed, please contact: [email protected] [[email protected]].
Export Control Compliance
This position requires access to export controlled information. To conform to
U.S. Government export regulations applicable to that information, applicant
must either be (A) a U.S. person, defined as a (i) U.S. citizen or national,
(ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8
U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the
export controlled information without a required export authorization, or (C)
eligible and reasonably likely to obtain the required export authorization from
the applicable U.S. government agency. CoreWeave may, for legitimate business
reasons, decline to pursue any export licensing process.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Security Engineer
Brightspot · Reston, Virginia, United States
Security Engineer - Directory Services
Truist · Atlanta, Georgia, United States
ML Security Engineer
Bright Vision Technologies · Kirkland, Washington, United States
IT & Security Engineer
Albedo · Broomfield, Colorado, United States
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
Role information can change. Confirm current details on the original application page.
