
Principal Engineer (CC)
About OPAQUE
OPAQUE is the Confidential AI company. Born from UC Berkeley’s RISELab, we solve the core challenge blocking AI adoption at scale: security concerns about data leaks or compliance violations. OPAQUE provides verifiable privacy and governance for AI so organizations can safely run models, agents, and workflows on their most sensitive data. Its Confidential AI platform delivers verifiable runtime governance backed by cryptographic proof that data, models, and agent actions remain private, governed, and compliant with approved policies throughout every AI workflow. This extends traditional data governance tools with real runtime verification, enabling teams to responsibly deploy AI using their most valuable proprietary data, and move from pilot to production 4-5X faster. Customers and partners include ServiceNow, Anthropic, Encore Capital, Accenture, and leaders across high tech, financial services, insurance, and healthcare.
Learn More at Opaque.co
Read about our Values at Opaque.co/about
ABOUT THIS JOB
As a Principal Engineer at Opaque Systems, you will play a critical role in shaping the architecture and driving the technical direction of the core OPAQUE platform, with a focus on the confidential computing infrastructure. You’ll collaborate closely with cross-functional teams to design, develop, and scale solutions for confidential AI. This is an opportunity to solve complex technical challenges while making a significant impact on the development of next-generation technologies.
Key Responsibilities
- Lead the design, architecture, and implementation of core software components for Opaque’s confidential computing platform
- Design, implement, and maintain end-to-end attestation services and infrastructure
- Lead integration of TEE technologies (CNCF CoCo, hyperscaler CC offerings) with OPAQUE's platform
- Design and operate multi-cloud CC deployments at the Kubernetes platform layer — runtime classes, TEE node pools, custom admission controllers, and service mesh security for confidential workloads
- Define and enforce cryptographic standards: key derivation, signing schemes, secure channel establishment, and secrets management within TEE boundaries
- Drive code quality and security review standards across the security engineering team — review at the correctness and side-channel level, not just design
- Collaborate with product, engineering, and AI teams to deliver scalable, high-performance, and secure solutions.
- Drive technical excellence across the engineering team, setting best practices for coding, architecture, testing, and deployment.
- Mentor and guide junior engineers, fostering a culture of continuous improvement and technical innovation.
- Work closely with stakeholders to define technical requirements and ensure alignment with business objectives.
- Optimize system performance, scalability, and fault tolerance while ensuring the security and privacy of data in all phases of computation.
- Stay ahead of industry trends and advancements in confidential AI and confidential computing
- Act as a key decision-maker in technical strategies, contributing to both tactical and strategic goals.
Qualifications
- 10+ years of software engineering experience, with a focus on distributed systems, cloud computing, or security.
- Deep hands-on experience in confidential computing / TEE technologies (e.g., CNCF CoCo)
- Fluency in attestation protocols: attestation quote generation and verification, RATS (RFC 9334), EAT/EAR standards
- Systems programming at production scale in Go and/or Rust; kernel modules, ioctl interfaces, or TEE SDK integration code a strong plus
- Cloud-native platform depth — Kubernetes operators, custom admission controllers, runtime classes, and TEE workload orchestration across multiple clouds
- Cryptographic engineering fundamentals: key hierarchies, AEAD schemes, digital signatures, and the ability to reason about threat models at the hardware boundary
- Expertise in system architecture and design, with a strong understanding of scalability, fault tolerance, and performance optimization.
- Proven track record of delivering large-scale, high-performance, and secure software systems.
- Strong communication skills, with the ability to collaborate effectively across technical and non-technical teams.
- Bonus: Track record of open-source contribution or standards engagement: CNCF CoCo, Project Oak, IETF RATS, or equivalent
Apply for this job
*
indicates a required field