Full-Time

Staff Security Risk & Compliance Program Manager

Access Management

Updated on 9/10/2026

Confluent

Confluent

1,001-5,000 employees

Delivers Apache Kafka-based real-time data streams

Compensation Overview

$222.1k - $261k/yr

Company Historically Provides H1B Sponsorship

Remote in USA + 1 more

More locations: Texas, USA

Remote

Category
Cybersecurity (1)
Required Skills
LLM
Kubernetes
Microsoft Azure
Role-based Access Control
AWS
Data Analysis
Google Cloud Platform

Get referred to Confluent

See people who can refer or advise you

Requirements
  • At least 8 years of experience in security program management, identity and access management, or a closely related security discipline, including at least 3 years running an enterprise- or platform-scale access program in a technology company.
  • Deep expertise in identity and access management concepts, including least privilege, separation of duties, role-based access control, attribute-based access control, just-in-time access, privileged access management, and access review or certification.
  • Working knowledge of machine and workload identity, including service-to-service authentication, non-human identity, service accounts, secrets and key management, and AI-agent access patterns.
  • Strong security engineering fundamentals across cloud infrastructure security controls in Google Cloud Platform, Amazon Web Services, and/or Microsoft Azure, including Kubernetes and cloud control-plane access models.
  • Familiarity with identity platforms and access tooling such as Okta and just-in-time or access-orchestration tooling, including how access controls are enforced in production.
  • Experience integrating access processes, controls, or findings into governance, risk, and compliance and access-orchestration platforms.
  • Strong project management and organizational skills.
  • Exceptional analytical and problem-solving skills with a data-driven approach to decision-making.
  • Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.
  • Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.
  • Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams.
Responsibilities
  • Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as its central focus.
  • Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.
  • Lead the program to enforce service-to-service authentication across Trust and Security-owned surfaces and take ownership of the enforcement hand-off from the identity engineering team.
  • Formalize non-human identity, including service accounts, keys, and workload credentials, from pilot into a funded and governed program.
  • Establish access controls for AI agents as agentic workloads acquire production access.
  • Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access.
  • Ensure the Access Management Standard keeps pace with the evolving access surface and remains audit-ready.
  • Own access metrics and reporting, including just-in-time or unilateral-access volume, broad-privilege usage, and production-access reduction.
  • Define and track program objectives and key results and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership.
  • Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
  • Integrate the access management program with adjacent governance, risk, and compliance domains and partner teams, including Insider Threat, IT/Identity, Detection and Response, and engineering owners, with clear responsibility assignment across governance and operations.
  • Automate access decisions and reduce reliance on manual operations.
  • Maintain a coherent access posture across distributed access operations.

Prepare a concise company summary describing what Confluent does, how its products work, how it differs from competitors, and its goal.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Mountain View, California

Founded

2014

Get referred to Confluent

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • March 10, 2026 FedRAMP Moderate authorization opened U.S. public-sector demand.
  • May 20, 2026 Confluent launched managed MCP, Agent Skills, and PII redaction for AI.
  • July 30, 2026 East Japan Railway adopted Confluent, proving international enterprise traction.

What critics are saying

  • February 2026 merger litigation and demand letters increased closing and integration distraction.
  • IBM's March 2026 takeover replaced Confluent's board, shrinking autonomy and brand control.
  • Kafka 5.0 removals and Apache ecosystem alternatives pressure Confluent's pricing power by 2027.

What makes Confluent unique

  • Confluent owns Kafka's premium governance stack: Schema Registry, Flink, connectors, and Control Center.
  • March 17, 2026 IBM closed the $11 billion purchase, validating Confluent's enterprise moat.
  • June 1, 2026 Kafka 4.3 shipped 25 KIPs, reinforcing Confluent's upstream influence.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Best Teammates on Planet Earth - Loving your job has a lot to do with the people around you. Luckily at Confluent, you will find some of the most genuine people who make you excited to come to work each day.

Adjustable Working Arrangements - While most of our employees work typical business hours, we encourage everyone to partner with their manager to make a schedule that works best for them and Confluent.

Robust Benefits - Health and wellness is important and Confluent is proud to offer a total benefits program that ranks in the top percentile of companies similar in size to our industry in our established geographies.

Rest and Recharge Days - Personal time off is great but it is even better when your whole team has the day. Each quarter, teams have three recharge days where the entire team logs off and refreshes before coming back to work.

Weekly Lunch Spend - At Confluent, we have a weekly lunch program called “No Pay Thursday.” On Thursdays, lunch is provided by Confluent at local restaurants and grocery stores, taxes may apply for some countries.

Flexible Paid Time Off (PTO) - Confluent employees work really hard to meet the needs of our growing and scaling business. To make sure that we don’t burn out, we encourage everyone to balance their PTO in an adequate way.

Growth & Insights and Company News

Headcount

6 month growth

4%

1 year growth

4%

2 year growth

5%
mgks.dev
Sep 3rd, 2026
Time series foundation models change how we build real-time AI.

Time series foundation models change how Mgks build real-time AI. I've watched teams spend months wiring ML models into production only to watch them drift within weeks. The plumbing always takes longer than the math. IBM and Confluent just announced something that sidesteps that entire problem: time series foundation models that live natively inside streaming infrastructure, callable from SQL, swappable with a parameter change. This matters more than the typical integration announcement because it reorganizes where the work actually happens. The old way still dominates. Most forecasting today is statistical models and spreadsheets dressed up as decisions. Teams model the few hundred products or systems where the money is obvious, then cover everything else with safety margins. Extra inventory. Extra headroom. Extra tolerance. That margin gets paid every cycle, and nobody could forecast it anyway. Bespoke ML promised better. One model per series. Hand-tuned. Refit monthly. But one model per series means specialization: data scientists build pipelines, data engineers wire them, and the domain expert who actually owns the decision waits. A demand planner can't touch it. A process engineer can't tune it. A fraud analyst can't customize it for new corridors without filing a ticket. So most organizations still don't bother. The tail of their catalog, their equipment, their transactions runs on margins because modeling thousands of series is not rational when each one takes specialist time. What changes with a foundation model at the edge. A time series foundation model trained across millions of signals learns patterns that generalize. Give it a window of measurements it has never seen and it forecasts what comes next, scores how far behavior sits from normal, finds similar history, and optimizes toward a target. More important: a demand planner can point it at their data stream. A process engineer can customize it on their line. No data science ticket required. IBM ran these in their own operations first, then with design partners in cement, steel, food, telecom. The numbers are real: every point of accuracy in forecasting is worth millions in working capital. Productivity gains run 5 to 10 times. Work that waited for specialists now sits with the people who own the decision. But running a model is not the same as running it in time. A signal's value decays with time. A pump caught drifting today is a work order. The same pump next week is an outage. That's why Confluent matters here: they bring the live state of the business to the model, managed as stateful streams inside Apache Flink, keyed per series and fault-tolerant. No separate database hit. No external feature store query. The model gets the history it needs to make the next call matter. The portfolio approach beats the silver bullet. Here's what I find most pragmatic about this: IBM is not offering one model. They're offering four, all related to foundation models but built for different questions. PatchTST-FM reads time series the way language models read text, patch by patch, each variable in its own channel so noise doesn't cascade. It returns a full distribution so a planner can set reorder points off the 90th percentile. FlowState keeps a running summary with every point and handles both seconds-level sensor data and hourly market data because its dynamics are continuous in time. TTM drops attention for tiny mixing networks so a million-parameter model covers a hundred thousand series nightly on CPU. TSPulse pairs time and frequency views for anomaly detection and the question every operator asks: have Mgks seen this before? Switch models with one SQL parameter. No pipeline redesign. No separate ML stack. That's not a feature, that's a philosophy. Why this matters for how you ship. I think the deeper shift here is about where decisions live. Right now, forecasting and anomaly detection and optimization are typically batch jobs. Nightly runs. Reports. The business reacts the next morning. But in a streaming context, forecasts become triggers. A replenishment order fires automatically. A fraud alert lands before money moves. An optimizer recommends the next setpoint as conditions change. The gap between an event and knowing about it shrinks from days to seconds. And because the model understands context, the score that lands on the downstream topic is already actionable: not just anomaly detected, but here's the closest past case and here's what happened then. Streaming data was always supposed to enable this. Now the ML tooling catches up. Small model size was a deliberate choice, not a compromise: inference runs on your own CPUs or natively inside Confluent Cloud with no external API call per decision. No cloud ingress or egress. That keeps architecture simple and cost rational at scale. The real test will be adoption: whether domain experts actually use these models on their own, or whether bottlenecks just move upstream. But the path is clearer now than it was last year, and that matters.

AInvest Fintech Inc.
Jul 13th, 2026
Confluent secures $510M term loan to fund A&E Networks acquisition

Confluent has secured a $510 million term loan B facility to fund its acquisition of A&E Networks. The financing, finalised on 13 July 2026, forms part of a broader capital structure adjustment for the strategic deal. The senior secured debt will finance the transaction and related expenses. It will be used alongside existing equity and other debt instruments as a key component of the capital stack. The acquisition is expected to expand Confluent's market reach and diversify its revenue streams. The transaction remains subject to regulatory approvals and customary closing conditions. Investors are advised to monitor the company's upcoming earnings call for further details on the financing structure and integration plans.

Confluent
Jun 1st, 2026
Apache Kafka 4.3.0 release announcement.

Apache Kafka 4.3.0 release announcement. Jun 1, 2026Read Time: 5 min Confluent Enterprise is proud to announce the release of Apache Kafka(R) 4.3. This release contains many new features and improvements. This blog post will highlight some of the more prominent ones. For a full list of changes, be sure to check the release notes. With 25 KIPs and over 600 commits since 4.2.0, this release introduces many new features, improvements and bug fixes to all the components. See the Upgrading to 4.3 section in the documentation for the list of notable changes and detailed upgrade steps. Deprecation notices. * KIP-1244 Drop support for streams-scala in Kafka 5.0 (deprecate in 4.3)Deprecates the streams-scala module. Marked for removal in Apache Kafka 5.0. * KIP-1237: Deprecate group.coordinator.rebalance.protocols configDeprecates the group.coordinator.rebalance.protocols broker configuration. Marked for removal in Apache Kafka 5.0. * KIP-1280: Update MirrorMaker to use KIP-877 to emit metricsDeprecates the existing MirrorMaker metrics. They are marked for removal in Apache Kafka 5.0. Users should transition to the new metric names. Kafka broker, controller, producer, consumer and admin client. * KIP-1023: Follower fetch from tiered offsetAdds a new broker configuration, follower.fetch.last.tiered.offset.enable (default: false). When enabled the last tiered offset is used as the start offset when bootstrapping a new follower. * KIP-1066: Mechanism to cordon brokers and log directoriesIntroduces a new configuration, cordoned.log.dirs to cordon log directories. New partitions cannot be placed on a cordoned log directory. This can be used when scaling or decommissioning brokers or log directories. * KIP-1196: Introduce group.coordinator.append.max.buffer.size configIntroduces the group.coordinator.append.max.buffer.size and share.coordinator.append.max.buffer.size configurations to set the maximum buffer size the coordinators can use. There are also metrics to track the buffer usage. * KIP-1208: Add prefix to TopicBasedRemoteLogMetadataManagerConfig to enable setting admin configsIntroduces a new prefix remote.log.metadata.admin. for setting configurations for the admin client used by the tiered storage's RemoteLogMetadataManager. * KIP-1211: Align the behavior of num.partitions and default.replication.factor for topic creationFixes inconsistencies how num.partitions and default.replication.factor were applied when creating topics. * KIP-1219: Configurations for KRaft Fetch and FetchSnapshot Byte SizeAdds new broker configurations, controller.quorum.fetch.snapshot.max.bytes and controller.quorum.fetch.max.bytes, to control the maximum amount of data Fetch and FetchSnapshot requests can retrieve. * KIP-1235: Correct the default min.insync.replicas to 2 for the __remote_log_metadata topic Adds a new broker configuration, remote.log.metadata.topic.min.isr, to set the minimum in-sync replicas for the internal topic used by tiered storage. * KIP-1240: Additional group configurations for share groupsAdds a number of new broker and group configurations to control the behavior of share groups. * KIP-1251: Assignment epochs for consumer groupsImproves the member epoch validation logic to avoid unnecessary fencing of group members. * KIP-1257: Partition Size Percentage Metrics for Storage MonitoringIntroduces new metrics to track how much of the maximum retention each topic-partition currently uses. * KIP-1258: Add Support for OAuth Client Assertion to client_credentials Grant TypeAdds support for client assertion authentication to client_credentials grant type with OAuth to enhance security and compatibility with OAuth providers. * KIP-1263: Group Coordinator Assignment Batching and OffloadImproves the group coordinator assignment logic to avoid recomputing assignments when unnecessary. * KIP-1274: Deprecate and remove support for Classic rebalance protocol in KafkaConsumer (Phase 1)Logs a message when starting a consumer with the classic rebalance protocol recommending to use the new consumer rebalance protocol instead as the classic protocol will be deprecated in a future release. Kafka Streams. * KIP-1035: StateStore managed changelog offsetsAdds methods to the StateStore API to manage changelog offsets. This is an internal runtime change, and only relevant for custom StateStore implementations. * KIP-1247: Make Bytes utils class part of the public APIExposes the Bytes class as part of the public API so it appears in the javadoc. * KIP-1250: Add metric to track size of in-memory state storesAdds new metrics tracking the number of keys in the in-memory state stores. * KIP-1259: Add configuration to wipe Kafka Streams local state on startupAdds a new configuration, state.cleanup.dir.max.age.ms, to automatically delete state directories that have not been modified for that duration on startup. * KIP-1270: Extend ProcessingExceptionHandler for GlobalThreadAdds a new configuration, processing.exception.handler.global.enabled, to enable ProcessingExceptionHandler to handle GlobalKTable exceptions. * KIP-1271: Allow to Store Headers in State StoresExtends the Processor API to support record headers in state stores. * KIP-1285: DSL Opt-in Support for Headers-Aware State StoresExposes Headers-Aware State Stores (KIP-1271) to the DSL API. Kafka Connect. * KIP-1239: Batch offset translation in RemoteClusterUtilsAdds a new method RemoteClusterUtils.translateOffsets to translate the committed offsets of several consumer groups at the same time. * KIP-1273: Improve Connect configurable components discoverabilityIntroduces a new interface, ConnectPlugin, that all Kafka Connect plugins implement to ensure common methods across all plugin types. * KIP-1280: Update MirrorMaker to use KIP-877 to emit metricsAdds a new configuration, metric.names.formats, for MirrorSourceConnector and MirrorCheckpointConnector to opt-in to the new metric names. Summary. Ready to get started with Apache Kafka 4.3.0? Check out all the details in the upgrade notes and the release notes, and download Apache Kafka 4.3.0. This was a community effort, so thank you to everyone who contributed to this release, including all its users and its 147 contributors (and 3 AIs): 高春晖, 조형준, Abhijeet Kumar, Abhinav Dixit, Alieh Saeedi, Alyssa Huang, Andrew Schofield, Aneesh Garg, Angelo R., Anton Vasanth, ANUSHREE BONDIA, Apoorv Mittal, Arpit Goyal, Artem Livshits, averemee-si, Bill Bejeck, Bolin Lin, Calvin Liu, Chang-Chi Hsu, Chang-Yu Huang, Chia-Ping Tsai, Chia-Yi Chiu, ChickenchickenLove, Chih-Yuan Chien, Chirag Wadhwa, Chris Egerton, Christo Lolov, Claude, Claude Sonnet 4.6, Copilot, cui, Dale Lane, David Arthur, David Jacot, Deepak Goyal, Dejan Stojadinović, dengziming, Ding, Dmitry Werner, Dongnuo Lyu, Donny Nadolny, Edoardo Comar, Eduwer Camacaro, Emanuele Rabino, Emmanuel Oppong, Eric Chang, Erik Anderson, Evan Zhou, Federico Valeri, Fiore Mario Vitale, gabriellefu, Gaurav Narula, Gianmarco, Giuseppe Lillo, gomudayya, Gyeongwon, Do, Harish Vishwanath, Hector Geraldino, high.lee, Himanshu Verma, Hong-Yi Chen, Hy (하이), hy-rice, Ibuki Kaji, Ilyas Toumlilt, Ismael Juma, Izzy Harker, J.V.S Aarathi, Jacob Montemayor, JeevanYewale, Jhen-Yung Hsu, Jian, Jiayao Sun, jimmy, Jinhe Zhang, Joanna-D, Jonah Hooper, José Armando García Sancio, Josep Prat, Jun Rao, Justine Olshan, k-apol, Kamal Chandraprakash, Ken Huang, Kevin Wu, khilesh Chaganti, Kirk True, Kuan-Po Tseng, Lan Ding, Levani Kokhreidze, Lianet Magrans, Lucas Brutschy, Lucy Liu, Luke Chen, Ma Jialong, Mahsa Seifikar, manan.gupta, Manikumar Reddy, mannoopj, Maros Orsak, Matthias J. Sax, Mickael Maison, Ming-Yen Chung, Moshe Blumberg, Murali Basani, Nandini Singhal, Nick Guo, Nick Telford, Nikita Shupletsov, Nilesh Kumar, Lan Ding, Paolo Patierno, Park Jiwon, Parker Chang, Philippus Baalman, PoAn Yang, Prabhash Kumar, Raghu Baddam, Rajarshi Misra, Rion Williams, Rion Williams,, Ritika Reddy, Robin Marechal, runom, S.Y. Wang, Saket Ranjan, Sanskar Jhajharia, Santhan3159, Sean Quah, Shashank, Shivsundar R, Siddhartha Devineni, sstremler, Steven Schlansker, Stig Døssing, Sushant Mahajan, TaiJuWu, TengYao Chi, Tirth, tison, Uladzislau Blok, Viktor Somogyi-Vass, Vincent Jiang, Vincent Potuček, Xuan-Zhang Gong, Zheguang Zhao, Zhiyan Tang, zoo-code Table of Contents * Mickael Maison is a committer and the chair of the Project Management Committee (PMC) for Apache Kafka. He has been contributing to Apache Kafka and its wider ecosystem since 2015. Mickael is a software engineer with over 15 years of software development experience. He is currently working in the Kafka team at Red Hat. He really enjoys sharing expertise and teaching and has been writing monthly Kafka digests since 2018 and enjoys presenting at conferences.

CXO DX
May 20th, 2026
Confluent expands real-time AI capabilities with new security and developer tools.

Confluent expands real-time AI capabilities with new security and developer tools. May 20, 2026 Confluent, an IBM company and the data streaming pioneer, today announced new capabilities in Confluent Intelligence and Confluent Cloud that streamline how real-time artificial intelligence (AI) applications are built and secured. These updates remove the security and complexity barriers that stop organizations from moving AI workloads into the real world. Confluent unifies the AI life cycle with tools that developers already live in, integrating Apache Flink pipelines with dbt (data build tool) and introducing a fully managed Model Context Protocol (MCP) server and Agent Skills that let AI manage streaming operations. With automated personally identifiable information (PII) redaction and private connectivity to external models via Azure Private Link, Confluent also embeds enterprise-grade governance directly into the data streams. "Most AI projects fail before they reach a single customer because the data layer breaks down," said Sean Falconer, head of AI at Confluent. "Teams have the models and the mandate, but security risks and fragmented data stop them from shipping. We're fixing that by making the streaming layer the foundation for secure, production-ready AI." The problem is widespread, according to a McKinsey report that says, "... eight in ten companies cite data limitations as a roadblock to scaling agentic AI." Root causes are often tied to security teams blocking data from entering AI pipelines due to exposure risks and developers losing hours to tool-switching to inspect and manage the data streams their AI depends on. The resulting slow, manual process turns what should be a fast iteration cycle into a bottleneck. Confluent Cloud and Confluent Intelligence form the data streaming foundation for production-ready AI that continuously processes historic and real-time data and delivers it as trusted context into AI applications. New capabilities add the security controls and developer tooling that high-stakes industries require. Natural language operations allow developers to use Confluent MCP as a control plane, enabling AI to build, manage, and debug streaming operations using natural language. Agent Skills add a second layer, encoding best practices and workflows so those operations are executed consistently and in line with organizational standards. Together, they enable developers to create and continuously improve real-time applications using AI-powered tools, bringing streaming into modern, agent-driven development workflows. This is generally available for Confluent Cloud. Automated data privacy introduces a new built-in ML function for PII detection and redaction that protects sensitive information directly in Flink SQL, without custom code, external services, or moving data to a warehouse first. This unlocks more AI use cases across highly regulated industries such as financial services, healthcare, and insurance. It is available in early access for Confluent Intelligence. Secure connectivity support for Azure Private Link ensures that AI workloads stay off the public internet with secure, private paths to calling external models and querying external tables. Flink jobs can securely connect to Azure-hosted services such as Azure OpenAI, Azure SQL, and Cosmos DB over Microsoft's private backbone. This capability is generally available on Confluent Cloud. Unified engineering workflows are enabled through the free open source dbt adapter that brings Flink SQL on Confluent Cloud into dbt, the industry-standard framework data engineers use to build and manage data pipelines. Teams can immediately define, test, and deploy streaming pipelines using the same dbt commands and project structure they rely on today. This lowers the barrier to Flink adoption and makes it easier to extend existing data workflows into real-time use cases. It is generally available on Confluent Cloud. Confluent also provides flexibility with additional model support, including support for TimesFM models for robust anomaly detection as well as Anthropic and Fireworks AI models, which developers can directly use in Flink stream processing workflows to build sophisticated real-time AI applications. Highlights include the general availability of the Real-Time Context Engine, which continuously delivers fresh, governed context for AI applications, and new fully managed connectors in Confluent Cloud that further simplify data integration. These capabilities extend recent announcements at IBM Think that integrate Confluent Cloud further into IBM solutions. With Confluent, watsonx.data delivers an AI-ready data foundation and a real-time context layer for AI across hybrid environments.

InfoQ
May 1st, 2026
Confluent moves Schema IDs to Kafka headers to simplify schema governance.

Confluent moves Schema IDs to Kafka headers to simplify schema governance. Write for infoq. Feed your curiosity. Help 550k+ global senior developers each month stay ahead. Get in touch Confluent has introduced a new approach to managing schema metadata in Apache Kafka by enabling schema IDs to be stored in message headers rather than in the payload. The update is designed to simplify data governance and enable teams to adopt schema validation without changing existing event formats. The feature builds on Kafka's native header support and integrates with Confluent Schema Registry, which is widely used by organizations managing event-driven architectures across microservices, analytics pipelines, and data platforms. In traditional Kafka deployments using Confluent's wire format, schema IDs are embedded directly in the message payload. This ensures consumers can correctly deserialize events, but it tightly couples schema metadata with the data itself. Over time, this coupling complicates schema evolution, especially in environments where multiple teams and systems consume the same event streams. It also increases coordination overhead when schema changes are introduced across producers and consumers. With the new approach, schema identifiers are stored in Kafka record headers while the payload remains unchanged. Consumers retrieve the schema from the schema registry at runtime using the ID in the header. This maintains compatibility with formats such as Avro, Protobuf, and JSON Schema while reducing dependence on tightly coupled wire formats. Schema resolution is decoupled from the payload, making event streams more flexible and easier to integrate across downstream systems and tooling. Schema handling before and after moving schema IDs to Kafka headers (Source: Confluent Blog Post) Patrick Neff, CSTA Team Lead CEMEA at Confluent, highlights the importance of schema governance in enabling reuse across streaming and analytics systems in a LinkedIn post. Schemas are the key enabler for unlocking the full value of your data. The header-based approach also supports incremental adoption. Organizations can introduce schema governance without large-scale rewrites or coordinated changes across all producers and consumers. Schema IDs can be attached to existing event streams, allowing teams to gradually adopt stricter schema management practices while maintaining backward compatibility. Gunnar Morling, Technologist at Confluent, emphasized improved interoperability with storage systems and downstream processing frameworks in post. Schema ids into Kafka message headers rather than the message payload is a massive quality of life improvement: payloads become valid, self-contained. Separating schema metadata from payloads enables independent evolution of producers and consumers, with validation centralized in the schema registry. This reduces coordination overhead and simplifies schema evolution at scale. It also improves interoperability with tools like Apache Flink and analytics or ML systems by enabling consistent reuse of structured event data across pipelines. David Araujo, Director of Product Management at Coflunent, describes how the feature enables zero downtime and client-independent adoption patterns. By moving schema IDs to headers, you can attach schemas to existing data in Kafka without touching payload formats. The transition may require updates to Kafka connectors and downstream tools that assume schema metadata is embedded in payloads, creating a period where both approaches may coexist, depending on ecosystem readiness. The feature is available in Confluent Cloud and is expected in Confluent Platform with Schema Registry support under existing licensing models. Leela kumili. Leela is a Lead Software Engineer at Starbucks with deep expertise in building scalable, cloud-native systems and distributed platforms. She drives architecture, delivery, and operational excellence across the Rewards Platform, leading efforts to modernize systems, improve scalability, and enhance reliability. In addition to her technical leadership, Leela serves as an AI Champion for the organization, identifying opportunities to improve developer productivity and workflows using LLM-based tools and establishing best practices for AI adoption. She is passionate about building production-ready systems, enhancing developer experience, and mentoring engineers to grow in both technical and strategic impact. Her interests include platform engineering, distributed systems, developer productivity, and bridging technical solutions with business and product goals. This content is in the Apache Kafka topic.