About QSE
QSE is building security products at the intersection of Zero Trust Access, hardware-rooted identity, post-quantum readiness, cryptographic asset discovery, and AI-native engineering.
We're seeking a Principal Security & AI-Native Systems Architect to work directly with the CTO as a technical peer. This is a hands-on leadership role for someone who can architect, validate, and help build security-critical systems while applying AI-assisted engineering practices without compromising security, correctness, or maintainability.
What You'll Do
- Lead the architecture of QGuard's endpoint and appliance security agents.
- Define trust boundaries, identity models, session security, policy enforcement, attestation, and revocation strategies.
- Architect secure systems spanning endpoints, gateways, connectors, and cloud services.
- Guide implementation using modern technologies including .NET, Rust, cloud-native infrastructure, and industry-standard security protocols.
- Produce threat models, architecture decisions, technical specifications, and operational guidance.
- Establish rigorous testing and validation frameworks for security-critical functionality.
- Mentor engineers and help build a world-class security engineering team.
- Contribute to the evolution of QPrime, QSE's cryptographic discovery and post-quantum migration platform.
AI-Native Engineering
This role requires demonstrated expertise using modern AI coding tools such as Claude Code, Cursor, Codex, or similar platforms to accelerate engineering outcomes while maintaining strong security, verification, and quality standards.
Successful candidates treat AI as an engineering accelerator, not a replacement for judgment. They establish guardrails, validate outputs, design evaluation frameworks, and maintain accountability for every design decision and release.
Required Qualifications
- Proven experience architecting and delivering security-critical systems in production.
- Expertise in at least three of the following:
- Endpoint security
- ZTNA and secure access platforms
- Identity and access management
- Applied cryptography and PKI
- Network security and secure gateways
- Appliance or embedded security
- Distributed security control planes
- Strong knowledge of WebAuthn, FIDO2, OAuth/OIDC, device identity, session security, policy enforcement, and key lifecycle management.
- Hands-on experience with C#/.NET, Rust, Go, Java, Python, or modern C/C++.
- Experience with secure software delivery, observability, cloud-native platforms, and software supply chain security.
- Strong communication skills and the ability to explain complex security concepts to technical and executive audiences.
Preferred Qualifications
- TPM-backed identity and attestation.
- Windows Hello, Windows CNG, or browser-native integrations.
- Rust-based systems programming.
- Envoy, secure gateways, proxies, or network data planes.
- Cedar or similar policy frameworks.
- Post-quantum cryptography and cryptographic migration planning.
- SBOM, CBOM, graph analytics, or security discovery platforms.
- Formal verification, fuzzing, reproducible builds, or advanced secure development practices.
What This Role Is Not
- Not a pure architecture or slideware role.
- Not a research-only cryptography position.
- Not a prompt-engineering role.
- Not "vibe coding." Strong technical judgment, verification, and accountability are essential.