Full-Time

Staff Software Engineer

Certificate Lifecycle Management

Keeper Security

Keeper Security

501-1,000 employees

Zero-knowledge data protection platform

No salary listed

Remote in USA

Remote

Bachelor's

Category
Software Engineering (1)
Required Skills
Claude
Kubernetes
Python
Distributed Systems
Computer Networking
Java
C#
Go
Cryptography
REST APIs
C/C++
DevOps

Get referred to Keeper Security

See people who can refer or advise you

Requirements
  • The candidate must have 8 or more years of professional software engineering experience, including significant experience building backend, infrastructure, or security-focused systems.
  • The candidate must have deep hands-on experience with certificate lifecycle management, public key infrastructure, machine identity security, or a closely related domain.
  • The candidate must understand X.509 certificates, certificate authorities, certificate chains, trust stores, private keys, and public key cryptography.
  • The candidate must have experience with certificate lifecycle operations including discovery, enrollment, issuance, deployment, renewal, rotation, revocation, and expiration management.
  • The candidate must know certificate and public key infrastructure protocols and technologies such as ACME, SCEP, EST, OCSP, CRLs, and TLS.
  • The candidate must have strong backend software engineering experience using languages such as Java, Go, Python, C++, C#, or similar.
  • The candidate must have experience designing scalable application programming interfaces, distributed systems, and automation workflows.
  • The candidate must have experience integrating with enterprise public key infrastructure systems, certificate authorities, cloud platforms, or infrastructure technologies.
  • The candidate must understand secure key handling, authentication, authorization, and cryptographic trust.
  • The candidate must have experience working with cloud-native and enterprise infrastructure environments.
  • The candidate must be able to lead architecture discussions and make sound technical tradeoffs across security, scalability, reliability, and usability.
  • The candidate must be able to mentor engineers and influence technical direction across teams.
  • The candidate must be able and willing to use artificial-intelligence-assisted tools effectively for engineering, research, debugging, prototyping, and technical documentation.
  • The candidate must have a Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
Responsibilities
  • Architect and develop certificate lifecycle management capabilities spanning discovery, inventory, enrollment, issuance, deployment, renewal, rotation, and revocation.
  • Design scalable backend services and application programming interfaces for managing certificates, machine identities, and related cryptographic metadata across enterprise environments.
  • Build certificate discovery and automation workflows across cloud platforms, Kubernetes, web servers, load balancers, databases, network devices, and other infrastructure.
  • Design integrations with public and private certificate authorities and enterprise public key infrastructure environments.
  • Develop secure workflows for certificate enrollment, key handling, trust validation, and certificate deployment.
  • Solve engineering challenges involving certificate chains, trust stores, expiration, ownership, policy enforcement, and cryptographic compliance.
  • Design systems that support automated certificate renewal and remediation while minimizing operational disruption.
  • Provide technical leadership on public key infrastructure architecture, machine identity, cryptographic standards, and certificate automation.
  • Partner with Product and Engineering leadership on technical strategy, architecture, requirements, and long-term platform direction.
  • Lead technical design reviews, mentor engineers, and help establish engineering standards for security-sensitive certificate management capabilities.
  • Evaluate emerging public key infrastructure, machine identity, and cryptographic technologies and recommend architectural approaches.
  • Use artificial-intelligence-assisted development tools such as Claude, ChatGPT, GitHub Copilot, or similar platforms to improve technical research, software development, debugging, documentation, and engineering efficiency.
Desired Qualifications
  • Experience building or contributing to a commercial certificate lifecycle management, public key infrastructure, or machine identity platform.
  • Familiarity with platforms such as Keyfactor, DigiCert, Venafi, AppViewX, Sectigo, or similar technologies.
  • Experience with Microsoft Active Directory Certificate Services or other enterprise certificate authority environments.
  • Experience automating certificate management across Kubernetes, cloud workloads, continuous integration and continuous delivery pipelines, web servers, load balancers, or service meshes.
  • Familiarity with hardware security modules, key management systems, and cloud key management services.
  • Experience with cryptographic policy, algorithm transitions, and crypto-agility initiatives.
  • Experience with non-human identity, secrets management, privileged access management, or workload identity.
  • Experience building security-sensitive enterprise software-as-a-service products at scale.

Keeper Security provides a zero-knowledge data protection platform for individuals and businesses, delivered on a subscription basis. It protects sensitive information by encrypting data so that even Keeper cannot access it, ensuring user privacy. The platform is scalable to fit anyone from individuals to large enterprises and offers features like advanced provisioning, reporting tools, delegated administration, and 24/7 support. What sets Keeper apart is its zero-knowledge architecture combined with extensive auditing and certification, giving customers strong privacy guarantees and trust. The company also offers multiple plan options (personal, family, student, business, enterprise) and multi-year subscriptions to reduce costs and ensure ongoing access to updates and support. Overall, Keeper’s goal is to provide a trusted, private, and scalable security platform that keeps user data protected and accessible to authorized users through continuous improvements and reliable service.

Company Size

501-1,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$60.3M

Headquarters

Chicago, Illinois

Founded

2011

Get referred to Keeper Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Keeper crossed $225 million ARR on July 9, 2026 and adds 850 organizations monthly.
  • KeeperPAM launched in February 2025 and posted tenfold year-over-year revenue growth by July 2026.
  • JTP’s May 26, 2026 Japan launch and Azure, Teams, Wiz integrations broaden distribution fast.

What critics are saying

  • Microsoft, Wiz, and Okta control adjacent workflows, compressing Keeper’s pricing power by 2027.
  • Bitwarden, 1Password, and LastPass commoditize password management, forcing Keeper into tougher enterprise sales cycles.
  • A breach, audit failure, or zero-knowledge flaw would destroy trust and kill enterprise expansion.

What makes Keeper Security unique

  • KeeperPAM unifies passwords, secrets, sessions, endpoint privilege, and ZTNA in one cloud platform.
  • Keeper’s August 19, 2026 Microsoft Power Platform connector embeds zero-knowledge secrets into Azure automation.
  • Keeper’s June 16, 2026 Wiz integration turns detection into remediation across humans, machines, and AI agents.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

2%

2 year growth

0%
PR Newswire
Aug 19th, 2026
Keeper Security launches certified Microsoft Power Platform Connector for Secrets Manager, bringing zero-knowledge credential management to Azure Logic Apps.

Keeper Security launches certified Microsoft Power Platform Connector for Secrets Manager, bringing zero-knowledge credential management to Azure Logic Apps. Aug 19, 2026, 07:00 ET Connector enables enterprise teams to retrieve and manage credentials at runtime within Azure Logic Apps and Power Automate, eliminating hardcoded secrets from automated workflows CHICAGO, Aug. 19, 2026 /PRNewswire/ - Keeper Security, the leading zero-trust and zero-knowledge identity security platform, today announces the availability of a certified connector integrating Keeper Secrets Manager with Microsoft Azure Logic Apps. The connector, now published on the Microsoft Power Platform marketplace, enables enterprise teams to create and retrieve credentials at runtime directly within automated workflows without ever hardcoding sensitive values in flows. As organizations scale workflow automation across cloud environments, secrets management has become a critical, and frequently overlooked, gap. Hardcoded credentials in automation scripts and workflows represent one of the most persistent and exploitable vulnerabilities in enterprise environments. The Keeper Secrets Manager connector for Azure Logic Apps addresses this directly, giving teams a zero-knowledge, policy-enforced path to secrets management inside Microsoft Power Platform. "Workflow automation is only as secure as the secrets powering it, and most organizations are still hardcoding those secrets which creates massive cyber risk," said Darren Guccione, CEO and Co-founder of Keeper Security. "This connector eliminates that exposure by bringing Keeper's zero-knowledge architecture directly into the Microsoft automation layer: secrets stay encrypted in the vault and are retrieved only at the moment they are needed, so there is nothing hardcoded to steal." The connector operates through a lightweight Python middleware service deployed as an Azure Function App, communicating with the Keeper Vault via the Keeper Secrets Manager SDK. All secrets remain encrypted under Keeper's zero-knowledge security architecture and are decrypted locally within the customer's Azure environment - never transmitted in plaintext through Keeper's infrastructure. "The architecture here reflects a principle Keeper holds across the entire platform," said Craig Lurey, CTO and Co-founder of Keeper Security. "Secrets should be decrypted as close to the workload as possible and only when needed. The Azure Function middleware gives customers a deployment model where the Keeper SDK runs inside their own Azure environment, their own key management handles the configuration and plaintext credentials are never in motion across a network boundary they do not control." Key capabilities of the Keeper Secrets Manager Connector for Azure Logic Apps * Certified connector: Integrates natively in the Logic App Designer with no custom import required for standard deployments. * Runtime secrets retrieval: Fetches credentials on demand within any Logic App flow without storing them in the workflow definition. * One-click deployment: Provisions all required infrastructure - including the Azure Function App, Key Vault and Managed Identity - in minutes using an Azure Resource Manager (ARM) template. * Dynamic dropdowns: Auto-populates secret and folder pickers in the Logic App designer, reducing configuration error and accelerating deployment. * Credential creation: Provisions secrets directly from automated workflows, supporting employee onboarding and scheduled compliance audits. The connector supports five operations, including List Secrets, Get Secret, Create Secret, Update Secret and List Folders, covering workflows from API credential injection and database connection string retrieval to GitHub secret synchronization and vault compliance auditing. The Keeper Secrets Manager connector for Azure Logic Apps is available now. Full documentation, the middleware repository and deployment instructions are available at docs.keeper.io. About Keeper Security Keeper Security is the leading zero-trust and zero-knowledge identity security solution, trusted by millions of people and thousands of organizations globally. KeeperPAM(R) is Keeper's privileged access management platform that unifies password and passkey management, secrets management, privileged session management and endpoint privilege management in a single cloud-native platform, protected with quantum-resistant encryption. KeeperAI delivers real-time, AI-native threat detection across every privileged session. As AI agents proliferate and identity becomes the defining attack surface, Keeper governs access for humans, machines, non-human identities and AI agents, serving as the unified control plane for access, compliance and visibility across the enterprise. For more information, visit KeeperSecurity.com. SOURCE Keeper Security

NorthRock Systems
Jul 30th, 2026
Partnership with Keeper Security password manager.

Partnership with Keeper Security password manager. Securing your business: why Northrock Systems and Keeper Security are the ultimate password management duo. In today's digital landscape, compromised credentials remain one of the leading causes of data breaches. If your organization is still relying on sticky notes, spreadsheets, or unmanaged browser vaults to store passwords, you are leaving your infrastructure exposed. To bring its clients the highest tier of protection, Northrock Systems is proud to partner with Keeper Security to deliver fully managed, enterprise-grade password services. By combining Keeper's industry-leading zero-trust platform with Northrock's dedicated management and competitive Value-Added Reseller (VAR) pricing, securing your organization has never been more cost-effective. Why Northrock Systems chose Keeper Security: the industry standard. When evaluating identity and password management solutions, Keeper consistently stands above the competition. It isn't just a password vault; it is a unified control plane built on a zero-trust and zero-knowledge architecture. This means encryption and decryption occur locally on the user's device - Keeper (and cybercriminals) can never access your plaintext data. Keeper's dedication to protection is backed by the highest levels of compliance and reliability: * Elite Compliance: Keeper holds rigorous certifications, including SOC 2 Type 2, SOC 3, ISO 27001, and HIPAA compliance. * Government-Grade Security: Keeper is FedRAMP Authorized at the Moderate and High impact levels, and GovRAMP Authorized, exceeding the stringent security standards required by federal agencies. * Uptime & Reliability: Built as a cloud-first platform, Keeper delivers seamless cross-platform syncing with unmatched uptime, ensuring your team has access to their credentials when they need them, without compromising security. The Northrock Systems advantage: better Service, lower TCO. While Keeper provides the engine, Northrock Systems ensures it runs perfectly for your unique business needs. As a Value-Added Reseller (VAR) and Managed Service Provider (MSP), Northrock Systems offer advantages you won't get by purchasing software licenses off the shelf. 1. Fully managed password services (new SKUs available). Deploying a password manager across an organization requires user onboarding, policy enforcement, and constant monitoring. Northrock Systems takes this off your plate. Northrock Systems offer customized SKUs for fully managed password services, handling everything from initial deployment and Active Directory/SSO integration to continuous dark web monitoring (BreachWatch) and automated credential rotation. 2. The best pricing through VAR support. Software pricing can be rigid, but its VAR relationship with Keeper allows Northrock Systems to advocate for its clients. Northrock Systems leverage its partnership to secure the most competitive pricing tiers for your organization, scaling seamlessly whether you have 50 employees or 5,000. 3. Dramatically lower total cost of ownership (TCO). Unmanaged passwords are a massive hidden cost. Up to 50% of IT help desk tickets are password reset requests, costing organizations thousands of dollars annually. By wrapping Keeper's intuitive platform in Northrock's managed services, Northrock Systems drastically reduce help desk overhead, eliminate the need for disjointed security tools, and provide a lower overall TCO. Curious about how much an unmanaged password environment is actually costing your IT department? Use the calculator below to compare the hidden costs of password resets against a managed solution. Key takeaway: Shifting from reactive password resets to a proactive, Northrock-managed Keeper deployment usually pays for itself in IT helpdesk savings alone. Ready to upgrade your identity security? Don't wait for a data breach to rethink your password strategy. With Northrock Systems and Keeper Security, you get military-grade encryption paired with white-glove managed support. How can Northrock Systems help?

PR Newswire
Jul 29th, 2026
Keeper tops PAM market with 93% recommendation rate and +89 emotional footprint score

Keeper Security has topped the SoftwareReviews 2026 Privileged Access Management comparison report, leading across key satisfaction metrics. The platform scored 93% likeliness to recommend, 87% fair cost-to-value rating, and a +89 net emotional footprint — the highest among evaluated vendors. KeeperPAM also led implementation metrics with 85% ratings for ease of implementation and IT administration, plus 81% satisfaction for usability. The report analysed independent, user-validated data from Info-Tech Research Group's SoftwareReviews platform. "This recognition reflects our commitment to delivering a modern, unified platform that prioritises both security and user experience," said Darren Guccione, CEO and co-founder of Keeper Security. The cloud-native platform consolidates enterprise password management, secrets management, privileged session management, and endpoint privilege management into a single solution.

DuPont Solutions
Jul 28th, 2026
Access control.

Access control. As businesses adopt AI initiatives, digital transformation and cloud technologies, one critical question becomes increasingly important: Who has access to your most critical systems - and should they? Cybercriminals are increasingly targeting privileged accounts to access business infrastructure, so firms need to strengthen visibility and control over who can access which critical systems, data and applications. For many businesses, the challenge isn't a lack of security controls, it's a lack of visibility and governance over who has access to what. Common risks include: * Weak passwords or passwords that are reused across business applications * Employees having access to systems they no longer need * Inconsistent use of Multi-Factor Authentication (MFA) * Shared passwords with little accountability * Third-party suppliers or contractors retaining access after projects end * Limited reporting on who has access to critical business systems When privileged access is compromised, the consequences can be significant: ransomware attacks and data breaches, operational disruption, regulatory penalties and reputational damage. Reducing this risk requires a modern approach to Privileged Access Management (PAM) that delivers visibility, control and governance across your environment. Through its partnership with Keeper Security, Du Pont helps organisations strengthen their security posture by enabling: Secure access management across users, service accounts and machine identities | Just-in-Time (JIT) access to eliminate unnecessary standing privileges | Passwordless access to critical systems and applications | Automated credential management and password rotation | Continuous monitoring and auditing of privileged sessions | Enhanced compliance through detailed reporting and audit trails Unlike traditional solutions that often require complex infrastructure and lengthy deployments, KeeperPAM provides: * Cloud-native, agentless deployment * Zero-knowledge security architecture * Outbound-only connections with no inbound firewall changes * Fast deployment across hybrid and multi-cloud environments * Unified PAM, Secrets Management, Password Management and Zero-Trust Network Access As businesses adopt AI, automation and cloud technologies, privileged identities remain one of the most attractive targets for attackers. Strengthening control over these identities is becoming a critical component of cyber resilience. According to industry research, more than 80% of data breaches involve compromised credentials or identity-based attack techniques. If you're evaluating how to strengthen your organisation's security posture, contact Dupont Solutions to discuss how a modern PAM solution could support your goals. Graeme Victor is the Founder and Chief Executive Officer of Du Pont Solutions, a leading South African IT Managed Services and technology solutions provider. With more than two decades of experience in technology, engineering and business leadership, Graeme combines exceptional technical insight with strategic business acumen to help organisations get the most from their IT and telecommunications investments.

IT Security Guru
Jul 21st, 2026
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite.

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite. Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM(R) to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper's unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure. Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities. According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects. "The deployment of KeeperPAM was extremely easy, one of the best in my experience," said Tiago Rosado, Chief Information Security Officer at Asite. "I wish other tools were as easy to deploy." As part of the rollout, Asite standardised password management across its workforce using Keeper's platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials. Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams. The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture. "Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems," said Darren Guccione, CEO and Co-founder of Keeper Security. "Asite's deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale." The full customer case study is available on the Keeper Security website.