Senior Software Engineer, Identity
Build and drive design of core identity infrastructure including authentication (SSO, MFA, SAML/OAuth/OIDC), authorization (ReBAC/ABAC/RBAC with OpenFGA/Authzed), and governance for compliance at an AI data platform powering leading LLMs. Requires 5+ years in identity/infrastructure engineering with distributed systems and cloud expertise.
About the job
Responsibilities
- Drive the design and implementation of identity infrastructure to ensure secure authentication and authorization across enterprise systems.
- Build software for authentication mechanisms such as Single Sign-On (SSO), Multi-Factor Authentication (MFA), and federated identity solutions (SAML, OAuth, OpenID Connect).
- Build software for authorization mechanisms such as Relation-based access control (ReBAC), Attribute-based access control (ABAC), Role-based access control (RBAC).
- Build software-defined identity governance policies to ensure compliance with security policies, industry regulations (e.g., NIST, SOC2, ISO 27001), and organizational standards.
- Present technical information to teams and stakeholders, providing guidance and insight on identity management and best practices.
Requirements
- 5+ years of full-time engineering experience, post-graduation with specialties in infrastructure and identity systems.
- Infrastructure expertise – IAM controls, Infrastructure as Code (Terraform, Pulumi), microservice deployment best practices.
- Hands-on experience working with OpenFGA, Authzed, Cedar, Topaz, or similar authorization frameworks at scale.
- Strong understanding of Zanzibar-based ReBAC models, relationship tuples, and access control evaluation.
- Strong knowledge of authentication standards such as OAuth 2.0, OIDC, SAML, and JWT, as well as industry standard IdP solutions like EntraID, Okta, etc.
- Extensive experience in software development and a deep understanding of distributed systems and public cloud platforms (AWS preferred).
- Track record of independent ownership of successful engineering projects.
- Excellent communication and collaboration skills, and the ability to translate complex technical concepts to non-technical stakeholders.
Nice-to-Haves
- Experience securing API access and implementing access control mechanisms at the application level.
- Multi-cloud infrastructure experience – AWS, Azure, GCP, and more.
- Proficiency in integrating IAM solutions with applications built using frameworks such as Java, Python, Node.js, or .NET.
- Mentorship/leadership experience supporting junior engineers.
Skills
IAM, Terraform, Pulumi, Openfga, Authzed, Cedar, Topaz, Rebac, Zanzibar, OAuth, OIDC, SAML, Jwt, Okta, Entraid
Similar jobs
Security Engineering jobsLeads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.