SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer, KPI & Cryptographic Systems

Cloudflare - Remote - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: EUR 66,000 - 83,000 / annual

Cloudflare is seeking a Senior Software Engineer to design and build next-generation PKI and cryptographic infrastructure. The role sits at the intersection of applied cryptography, distributed systems, and security engineering, working on infrastructure that a large fraction of the Internet depends on. You will own the design and implementation of core PKI systems including certificate lifecycle management, X.509 issuance and validation logic, key parameter enforcement, and policy engines aligned with industry standards (CA/Browser Forum, browser root programs). You will integrate with FIPS 140-2 Level 3/4 HSMs via PKCS#11, build key ceremony and key-lifecycle tooling, and enforce strict key-usage boundaries in code. Responsibilities include building ACME-based issuance and renewal pipelines at Cloudflare's global scale, implementing Certificate Transparency integration and append-only tamper-evident logging, maintaining compliance under CA/B Forum and WebTrust frameworks, and representing Cloudflare in the WebPKI community through public incident reports and technical discourse. You will contribute to Cloudflare's post-quantum migration, own code end-to-end from design through production incident response, and mentor engineers on an early-stage team while establishing engineering standards and secure-development practices. This is an early-days role on a growing team; design decisions made in the first year will shape Cloudflare's certificate and key infrastructure for years to come. You will partner across SSL/TLS product teams, HSM and data-centre infrastructure teams, the Cloudflare Research applied cryptography group, and adjacent product teams consuming PKI as a platform. **Requirements:** - 5+ years of production systems software experience with a strong operational track record (on-call experience with high-consequence services) - Deep working knowledge of applied cryptography and PKI: X.509, ASN.1/DER, RFC 5280, CRL distribution, Certificate Transparency, ACME, and CA/Browser Forum Baseline Requirements - Familiarity with HSMs: PKCS#11 integration, key ceremonies, key-attestation flows, and understanding of FIPS 140-2/3 validation in production - Strong systems programming background in Go, Rust, or C/C++ - Distributed systems fluency: experience building or operating globally replicated, availability-critical services with strict correctness guarantees - Experience designing and operating database schemas for high-integrity systems (Postgres or equivalent) - Security-hardened system design instincts: threat modelling, defence in depth, least privilege, secure key handling - Comfort with high-consequence work and the temperament to move quickly while maintaining discipline **Bonus experience:** - Direct work on publicly-trusted or private CAs, or large-scale internal PKI (Let's Encrypt, Google Trust Services, DigiCert, Sectigo, ISRG, Entrust, Microsoft PKI, HashiCorp Vault, step-ca, CFSSL) - Experience with crypto/x509, BoringSSL, OpenSSL/AWS-LC, CFSSL, or equivalent PKI codebases - WebTrust for CAs audit experience - Post-quantum cryptography familiarity (ML-DSA, ML-KEM, hybrid signature schemes) - Participation in CA/Browser Forum, IETF working groups (LAMPS, TLS, PLANTS, PQUIP), transparency.dev, or browser root program reviews - Offline key ceremony automation - Certificate Transparency log infrastructure or CT monitoring at scale - Formal methods, differential fuzzing, or property-based testing for cryptographic code - Kubernetes experience

Similar roles