Security · Systems · Leadership

Hoss Shafagh

Security engineering leader and systems researcher.

I work at the intersection of security engineering, distributed systems, and technical leadership. I build and lead work on foundational security systems, including identity, cryptography, PKI, and secure infrastructure at scale.

Currently leading the Cryptography Services team at Netflix. Previously a researcher at ETH Zurich.

My research focused on data ownership, encrypted data processing, and cryptographic authorization across security, distributed systems, and networking.

Ph.D., ETH Zurich · M.Sc. and B.Sc., RWTH Aachen University

Portrait of Hoss Shafagh

Focus

Areas of work

Security engineering

Identity, PKI, cryptography, foundational security platforms, and secure systems design.

Technical leadership

Building teams, developing engineers, setting technical direction, and connecting security strategy to implementation.

Privacy and systems

Encrypted data processing, cryptographic authorization, distributed systems, and data ownership.

Selected work

Systems that establish trust

Security infrastructure and PKI at production scale

Leading foundational cryptography services and partnering across engineering teams on secure system design.

TimeCrypt

Scalable, real-time analytics over encrypted time-series data with cryptographic access control.

Droplet

Decentralized authorization and access control for encrypted data streams without intermediary trust entities.

Talos and Pilatus

Practical encrypted data processing and selective sharing for resource-constrained and mobile systems.

Explore research →

Selected publications

Research highlights

Zeph: Cryptographic Enforcement of End-to-End Data Privacy

OSDI 2021

Droplet: Decentralized Authorization and Access Control for Encrypted Data Streams

USENIX Security 2020

TimeCrypt: Encrypted Data Stream Processing at Scale with Cryptographic Access Control

NSDI 2020

Secure Sharing of Partially Homomorphic Encrypted IoT Data

SenSys 2017

Talos: Encrypted Query Processing for the Internet of Things

SenSys 2015

Delegation-based Authentication and Authorization for the IP-based Internet of Things

SECON 2014

View publication details →