Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a Software Engineer II to join our Security Products team working on Key Management Systems (KMS). Our KMS platform is foundational to DigitalOcean's security posture, managing the full lifecycle of cryptographic keys that protect customer data across the platform, from envelope encryption for block storage and databases to API credential management and secrets handling.
In this role, you will contribute meaningfully to building and maintaining the systems that power DigitalOcean's key management platform. You will work within established technical frameworks, implement features against well-scoped designs, and grow your expertise in applied cryptography and security engineering. If you are passionate about writing clean, reliable code and want to develop deep expertise in cryptographic systems, this is the team for you.
What You'll Do- Build & Extend: Implement features and bug fixes across DigitalOcean's key management services in Go, working within established architectural patterns and contributing to a high-reliability, security-critical platform.
- Contribute to Key Lifecycle Systems: Work on key generation, rotation, and revocation workflows, learning the cryptographic principles deeply and contributing to reliable, well-tested implementations.
- Write Quality Code: Participate in code reviews, write comprehensive unit and integration tests, and maintain high engineering standards — with particular attention to the correctness requirements of security-sensitive code.
- Operate What You Build: Participate in on-call rotations, investigate production issues, write runbooks, and develop operational ownership of the services you contribute to.
- Support Envelope Encryption Work: Implement data encryption key (DEK) wrapping and unwrapping logic using established key encryption key (KEK) hierarchies, translating well-defined requirements into working, tested code.
- Learn & Grow: Partner with senior engineers to develop your understanding of HSM integration, cryptographic protocol design, and compliance requirements (FIPS 140-2, SOC 2) — building the skills to take on increasing ownership over time.
- Collaborate Cross-Functionally: Work with teammates across IAM, Storage, and Database teams to understand how your work fits into the broader platform security model.
- Experience: 2–4 years of software engineering experience, with a strong foundation in building and shipping production services.
- Language Proficiency: Proficiency in Go or a strong background in another typed systems language with demonstrated ability to ramp quickly.
- Security Fundamentals: Understanding of core cryptographic concepts — symmetric vs. asymmetric encryption, key derivation, hashing — and genuine curiosity to go deeper into applied cryptography.
- Systems Thinking: Understanding of how distributed systems work — replication, latency trade-offs, failure modes — with an appreciation for the higher stakes of failures in security-critical systems.
- Cloud Native: Exposure to containerized environments (Kubernetes) and SQL databases (Postgres, mySQL); experience with Terraform is a plus.
- Problem Solver: Comfort working through ambiguous bugs and production issues, and a disciplined approach to correctness over cleverness in security-sensitive code.
- Communication: Ability to clearly document your work, ask good questions, and collaborate effectively with teammates and stakeholders.
- Familiarity with Hardware Security Modules (HSMs) or cloud KMS services (AWS KMS, GCP Cloud KMS, HashiCorp Vault).
- Exposure to FIPS 140-2 compliance requirements or cryptographic standards (AES-GCM, RSA, ECDSA).
- Prior experience working on security-sensitive or compliance-adjacent systems.
- Familiarity with gRPC microservices architecture.
*This job is located in Bengaluru, India
JR: 2026-7963
#LI-Hybrid
- We innovate with purpose. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
- We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
- We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
- We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
- DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.

