
Sr Software Engineer II
- Seattle, WA
- Permanent
- Full-time
- Own control-plane architecture for multi-tenant, planet-scale IoT fleets: device provisioning and lifecycle, device identity & PKI, configuration/state management (twin/shadow), command & control, policy/RBAC enforcement, OTA updates and rollout strategies, and authoritative device state.
- Drive reliability, safety, and security-by-design: zero-trust defaults, mutual TLS, certificate rotation at scale, least-privilege key management (HSM/KMS), robust secrets hygiene, threat modeling, and defense-in-depth for multi-tenancy.
- Lead cross-org technical strategy: set engineering standards (APIs, versioning, deprecation, rollout, testing), create long-range roadmaps, and mentor/level-up senior engineers across cloud and device teams.
- Partner with device teams on transport and protocol choices, schema and API contracts, edge-cloud sync models, staged rollouts, failure injection, and field-safe rollback.
- Establish end-to-end observability (metrics, tracing, structured/audit logs), actionable dashboards, incident response runbooks, and capacity planning with empirical load testing and cost guardrails.
- 10+ years building and operating distributed systems at scale; proven track record of owning critical paths and SLOs.
- Deep expertise in control planes, service discovery, orchestration, partitioning/placement, and consistency models(CAP tradeoffs, CRDTs, leader/follower, quorum).
- Strong coding in Go (also acceptable: Java/Rust); design-first mindset, profiling and performance tuning (allocations, tail latency, lock contention).
- Cloud-native foundations: Kubernetes, containers, service mesh (Istio/Envoy), gRPC/HTTP/2, backpressure and circuit-breaking patterns.
- Streaming/eventing: Kafka/NATS/Pub-Sub, schema evolution (Protobuf/Avro), idempotency keys, and exactly-once vs at-least-once tradeoffs.
- Security: mTLS, OAuth/OIDC, JWT, x.509, HSM/KMS, structured threat modeling and mitigation.
- IoT protocols & fleet ops: MQTT, WebSockets, device twin/shadow patterns and FIDO Device Onboarding (FDO).
- Hardware root of trust: TPM / TPM 2.0 fundamentals-measured/verified boot device identity & remote attestation, key sealing/unsealing-and integrating TPM-backed identity with cloud HSM/KMS.
- Large-scale telemetry pipelines, time-series storage, adaptive sampling, backpressure, and edge-cloud synchronization.
- Multi-region active/active, blue/green and canary for device fleets, ring-based or attribute-based rollout tooling with automatic pause/rollback.
- Experience in regulated or safety-critical domains (e.g., public safety, medical, automotive), with audit and compliance rigor.
- Mission you can see: Your work directly helps first responders move faster with clearer context, improving community safety.
- Scale and complexity: Build a global, multi-region control plane for millions of devices with tight SLOs and strict security.
- Growth: Influence technical strategy across cloud and device teams; mentor senior engineers; pursue Staff+ leadership paths.
- Compensation & support: Competitive pay and equity, comprehensive benefits and generous leave.
- Environment: “Own It“ culture that values engineering excellence, pragmatic safety-at-scale, and measurable outcomes.
- Competitive salary and 401k with employer match
- Discretionary paid time off
- Paid parental leave for all
- Medical, Dental, Vision plans
- Fitness Programs
- Emotional & Mental Wellness support
- Learning & Development programs
- And yes, we have snacks in our offices