Your role and responsibilities
About the TeamThe Secure Compute team builds and operates the foundational infrastructure layer that powers Confluent Cloud. Our mission is to enable the safe execution of code and data processing in multi-tenant environments across AWS, Azure, and GCP at scale. We provide the essential building blocks-including isolation, identity, and networking-that empower both our customers and internal product teams to innovate without compromising security.
As Confluent's product portfolio expands, our team sits at the center of the company's growth. We own a polyglot, container-based runtime that operates across thousands of clusters globally, solving some of the most complex challenges in distributed systems and cloud-native architecture. By balancing world-class security with operational cost-efficiency, we ensure that Confluent Cloud remains the trusted platform for mission-critical workloads in even the most highly regulated industries.
About the Role:As a Staff Software Engineer on the
Secure Compute Platform team, you will be a key technical leader in building and evolving a next-generation, multi-tenant, cloud-native compute platform that safely runs both trusted and untrusted workloads at scale. Our platform is built on Kubernetes and runs across a large fleet of clusters in multiple public clouds, providing a unified abstraction layer for workload execution, lifecycle management, security, and operational excellence.
You'll work on critical systems including:
- Secure Compute Infrastructure - Build and evolve the secure, multi-tenant compute substrate and isolation primitives that safely execute customer and internal workloads in a shared environment.
- Platform APIs & Abstractions - Design and evolve APIs that provide clear, safe abstractions for polyglot workloads (containers, functions, and services) with diverse performance and isolation needs.
- Core Platform Integration - Integrate the Secure Compute platform with core data and application services so that teams can onboard new workloads with minimal friction.
- Multi-Tenancy & Security - Implement and harden workload isolation, network policies, identity and access, and secure execution environments required to safely run customer-supplied code.
- Observability & Operations - Drive operational excellence through rich observability, automated health checks, self-healing workflows, and robust rollout and rollback practices.
As a senior technical leader, you think strategically and help drive end-to-end technical delivery-from platform APIs and developer experience down to runtime, capacity, and security. You leverage your expertise in cloud-native distributed systems to take the Secure Compute platform to the next level while ensuring high availability, reliability, security, and cost efficiency for mission-critical customer workloads.
What You Will Do- Define and drive the technical direction for Secure Compute, including platform architecture, runtime, and security for running trusted and untrusted workloads at scale.
- Design and implement platform APIs and Kubernetes controllers/operators (primarily in Go) that power workload lifecycle, autoscaling, placement, and isolation for containers and serverless-style functions.
- Partner with product and platform teams to shape and deliver the roadmap for Secure Compute, enabling new customer-facing features and internal platforms to build on a common compute substrate.
- Deliver high-impact initiatives in areas such as workload scheduling, failure and disruption handling, private and public networking patterns, rollout strategies, and fleet-level resource management.
- Lead technical design reviews and influence architecture across teams, ensuring Secure Compute primitives are easy to adopt, safe by default, and aligned with broader platform strategy.
- Mentor and grow engineers on the team through design guidance, code reviews, pair programming, and sharing best practices for secure, reliable, operable platform development.
- Own operational excellence for key Secure Compute services, including availability, reliability, SLOs, performance, on-call response, incident management, and disaster recovery.
This job can be performed from anywhere in the US.Required education
Bachelor's Degree
Preferred education
Master's Degree
Required technical and professional expertise
- 10+ years of experience delivering scalable backend or infrastructure software in production.
- Proven track record of leading the delivery of large-scale, highly available, low-latency distributed systems.
- Deep expertise in Kubernetes, including controller development, operator patterns, and preferably multi-region or multi-cluster architectures.
- Strong proficiency in Go with experience building production-grade services and control planes.
- Experience with multi-tenant platform architectures and security/isolation patterns (for example, namespaces, network policies, sandboxing, secrets and identity management), plus hands-on work with secure container runtimes and low-level Linux internals (for example, Kata Containers, Cloud Hypervisor, cgroups, namespaces, seccomp) and performance troubleshooting and tuning for containerized/virtualized workloads.
- Familiarity with gRPC, Protobuf, and internal platform API design for service-to-service communication.
- Hands-on experience with observability and operational practices (metrics, logs, traces, alerting, SLOs, rollout strategies, incident response).
- Experience with public cloud environments (such as AWS, GCP, Azure) and cloud-provider integrations.
- Demonstrated technical leadership and mentorship, including driving cross-team alignment on architecture and execution.
Preferred technical and professional experience
- Strong collaboration skills and history of working effectively with product, SRE/operations, security, and peer engineering teams.
- A smart, humble, and empathetic attitude with a strong sense of ownership and teamwork.
- Drive and excitement about building foundational cloud infrastructure in a fast-paced, innovative environment.
OTHER RELEVANT JOB DETAILSIBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), cash balance pension plan, the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.
The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.