Software Development Engineer II (UM), Bespoke Solutions
About the role
Bespoke Solutions is seeking a Software Development Engineer to design, build, and operate a mission-critical, multi-tenant platform for managing large-scale fleets of embedded devices across highly secure and enterprise network environments.
Responsibilities
- Build and maintain cryptographic trust infrastructure supporting multiple certificate authority hierarchies with offline validation mechanisms suited to disconnected environments
- Implement multi-tenant data isolation using attribute-based access control (ABAC), row-level security, and transparent query rewriting — designed to scale from single-tenant to hundreds of tenants over a 5-year horizon
- Engineer cryptographic integrity mechanisms for configuration and audit data, including chained signatures and append-only tamper-evident logging
- Design emergency access ("break-glass") workflows with time-bounded credentials, multi-party approval, and segregated audit trails
- Ensure all cryptographic operations leverage FIPS 140-2 Level 3 validated key management with strict key isolation boundaries
- Develop reconciliation protocols where edge devices remain the recommended source of truth, with backend systems maintaining synchronized projections
Requirements
- Bachelor's degree in computer science or equivalent
- 3+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience
- 2+ years of experience with at least one system programming language such as C, C++, or Rust
- Strong background in security-hardened system design, including PKI, mutual TLS, and cryptographic signing
- Proficiency with PostgreSQL or similar relational databases, including row-level security and policy-based access control
- Current, active US Government Security Clearance of Top Secret with SCI eligibility or above
Qualifications
- 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience
- Knowledge of security technology and concepts (Authentication, Authorization, Single sign-on, Cryptography, etc.)
- 2+ years of experience in Rust
- Background in embedded device fleet management or IoT platforms at scale
- Knowledge of FIPS-validated cryptographic modules and NIST-approved algorithms
Skills
- Experience with distributed systems and fleet operations
- Expertise in cryptography and security engineering
- Strong understanding of system design and reliability
- Proficiency with system programming languages and database technologies
Benefits
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit here for more information.
Pay
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location.
Schedule
By working together on behalf of our customers, we are building the future one innovative product, service, and idea at a time. If you're ready to embrace the challenge, come build the future with us.