Staff Software Engineer, Identity and Access Management
Architects and leads development of a multi-tenant identity platform with advanced token management, federation, security, compliance, and global-scale infrastructure. Requires 7+ years building production identity systems and deep expertise in OAuth, OpenID Connect, cryptography, and enterprise integrations.
About the job
Responsibilities
- Architect and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation.
- Lead development of an extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business-logic evaluation at token issuance.
- Architect global identity infrastructure with edge optimization, intelligent token caching, and cross-region replication strategies for low-latency authentication.
- Design rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.
- Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy integrations.
- Lead technical strategy for developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.
- Architect client management systems supporting dynamic client registration, automated credential rotation, and programmatic policy enforcement.
- Design a plugin architecture enabling custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.
- Drive compliance initiatives for SOC 2, FedRAMP, and GDPR, including audit trails, data residency controls, and privacy-preserving token designs.
- Lead integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.
- Mentor engineering teams on zero-trust architectures, workload identity, and service mesh integration patterns.
Requirements
- 7+ years of experience building production identity platforms at identity providers or enterprise software companies, with experience handling millions of authentication requests daily.
- Deep expertise in OAuth 2.0 extensions, including PKCE, mTLS, JWT bearer assertions, and token exchange; OpenID Connect profiles; and emerging standards such as OAuth 2.1 and GNAP.
- Experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise features.
- Strong background in cryptographic protocols, advanced JWT patterns, key rotation, Hardware Security Module (HSM) integration, and post-quantum cryptography considerations.
- Experience building identity platforms with enterprise-scale analytics, real-time monitoring, and security event detection.
- Expertise in global identity infrastructure, edge deployment, geo-distributed token validation, and cross-region data consistency.
- Understanding of enterprise identity integrations, including SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.
- Experience building developer-first identity platforms with SDKs, webhook systems, and extensible APIs.
- Experience with identity platform security, threat modeling, penetration testing coordination, and attack prevention mechanisms.
- Background in compliance and regulatory requirements for identity systems, including audit trail design, data residency controls, and privacy engineering.
- Experience supporting complex organizational structures, delegated administration, and fine-grained permission models.
- Expertise in high-performance system design, horizontal scaling, caching architectures, and latency optimization.
- Knowledge of service mesh identity patterns, workload identity bootstrapping, and container orchestration integrations.
- Experience with identity protocol extensions, custom grant flows, and extensible identity platforms.
- Ability to lead technical initiatives in complex, regulated environments while balancing innovation, security, and compliance.
Skills
Oauth 2.0, Openid Connect, Oauth 2.1, Gnap, Pkce, Jwt, SAML, SCIM, Ldap, Hsm, Cryptography, Multi-Tenancy, Kubernetes, Distributed Tracing, Caching
Similar jobs
Backend Engineering jobsTechnical leader for the Metadata team, designing distributed cloud subsystems and leading complex initiatives across discovery, catalog, lineage, and run history services. Requires 8+ years of software engineering experience, backend or systems expertise, cloud infrastructure experience, and strong architecture, reliability, and mentoring skills.
Technical leader for the Metadata team, owning architecture and delivery of distributed backend services for discovery, catalog, lineage, and run history. The role requires 8+ years of software engineering experience, strong cloud and systems expertise, and a record of leading multi-engineer initiatives.
Staff backend engineer leading the design, delivery, and operation of highly scalable passwordless authentication systems. The role requires deep Java and distributed-systems expertise, technical leadership, and experience with passkeys, FIDO2/WebAuthn, and identity protocols.
Leads the architecture and development of scalable Java-based backend services for Okta’s device identity and access platform. The role requires 7+ years of software development experience, strong distributed-systems expertise, and technical leadership across teams.
Leads development of reliable, scalable database connectors and replication technology for enterprise data movement. The role requires strong Java or C/C++ experience, database internals expertise, distributed-systems design skills, and technical leadership through architecture, mentoring, and production investigations.