# Staff Software Engineer, Identity and Access Management

**Company:** [Kong](https://hotfix.jobs/companies/kong)
**Location:** Remote
**Role:** Backend Engineering
**Salary:** CA$164k – CA$246k/yr
**Experience:** 7+ years
**Skills:** Oauth 2.0, Openid Connect, Oauth 2.1, Gnap, Pkce, Jwt, SAML, SCIM, Ldap, Hsm, Cryptography, Multi-Tenancy, Kubernetes, Distributed Tracing, Caching
**Posted:** 2026-04-15

> Architects and leads development of a multi-tenant identity platform with advanced token management, federation, security, compliance, and global-scale infrastructure. Requires 7+ years building production identity systems and deep expertise in OAuth, OpenID Connect, cryptography, and enterprise integrations.

## Job Description

## Responsibilities
- Architect and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation.
- Lead development of an extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business-logic evaluation at token issuance.
- Architect global identity infrastructure with edge optimization, intelligent token caching, and cross-region replication strategies for low-latency authentication.
- Design rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.
- Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy integrations.
- Lead technical strategy for developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.
- Architect client management systems supporting dynamic client registration, automated credential rotation, and programmatic policy enforcement.
- Design a plugin architecture enabling custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.
- Drive compliance initiatives for SOC 2, FedRAMP, and GDPR, including audit trails, data residency controls, and privacy-preserving token designs.
- Lead integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.
- Mentor engineering teams on zero-trust architectures, workload identity, and service mesh integration patterns.

## Requirements
- 7+ years of experience building production identity platforms at identity providers or enterprise software companies, with experience handling millions of authentication requests daily.
- Deep expertise in OAuth 2.0 extensions, including PKCE, mTLS, JWT bearer assertions, and token exchange; OpenID Connect profiles; and emerging standards such as OAuth 2.1 and GNAP.
- Experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise features.
- Strong background in cryptographic protocols, advanced JWT patterns, key rotation, Hardware Security Module (HSM) integration, and post-quantum cryptography considerations.
- Experience building identity platforms with enterprise-scale analytics, real-time monitoring, and security event detection.
- Expertise in global identity infrastructure, edge deployment, geo-distributed token validation, and cross-region data consistency.
- Understanding of enterprise identity integrations, including SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.
- Experience building developer-first identity platforms with SDKs, webhook systems, and extensible APIs.
- Experience with identity platform security, threat modeling, penetration testing coordination, and attack prevention mechanisms.
- Background in compliance and regulatory requirements for identity systems, including audit trail design, data residency controls, and privacy engineering.
- Experience supporting complex organizational structures, delegated administration, and fine-grained permission models.
- Expertise in high-performance system design, horizontal scaling, caching architectures, and latency optimization.
- Knowledge of service mesh identity patterns, workload identity bootstrapping, and container orchestration integrations.
- Experience with identity protocol extensions, custom grant flows, and extensible identity platforms.
- Ability to lead technical initiatives in complex, regulated environments while balancing innovation, security, and compliance.

## Similar jobs

- [Staff Software Engineer, Metadata](https://hotfix.jobs/jobs/16e23b4d-e57c-4aa5-a453-30ec7d50efaa) - Fivetran - Remote - $162k – $199k/yr
- [Staff Software Engineer, Metadata](https://hotfix.jobs/jobs/3aba1f31-fbd1-4d79-97b5-de7abf0aa37c) - Fivetran - Remote - $162k – $199k/yr
- [Staff Backend Engineer, Passwordless](https://hotfix.jobs/jobs/075c0aef-e358-4517-817d-0ee022321fb5) - Okta - Toronto, Canada - CA$160k – CA$220k/yr
- [Staff Software Engineer, Backend](https://hotfix.jobs/jobs/ac4518ac-dba1-4750-b9fa-2378da223cfc) - Okta - Toronto, Canada - CA$160k – CA$220k/yr
- [Staff Software Engineer](https://hotfix.jobs/jobs/17cd70e1-50a9-4da8-937a-a0eba74dec8f) - Fivetran - Toronto, Canada - CA$168k – CA$209k/yr

**Apply:** https://hotfix.jobs/jobs/3c0a5c92-f9ee-408d-8725-29ed61903e8f
**Canonical:** https://hotfix.jobs/jobs/3c0a5c92-f9ee-408d-8725-29ed61903e8f