Software Engineer, Identity
Build and manage secure identity infrastructure including authentication (SSO, MFA, SAML/OAuth/OIDC) and authorization (ReBAC, RBAC, ABAC) systems for AI data platforms. Requires 4+ years in infrastructure/identity engineering with hands-on authorization frameworks like OpenFGA/Authzed and IaC tools.
About the job
Responsibilities
- Drive the design and implementation of identity infrastructure to ensure secure authentication and authorization across enterprise systems.
- Manage authentication mechanisms such as Single Sign-On (SSO), Multi-Factor Authentication (MFA), and federated identity solutions (SAML, OAuth, OpenID Connect).
- Manage authorization mechanisms such as Relation-based access control (ReBAC), Attribute-based access control (ABAC), Role-based access control (RBAC).
- Work with auditors and security teams to enforce identity governance policies to ensure compliance with security policies, industry regulations (e.g., NIST, SOC2, ISO 27001), and organizational standards.
- Present technical information to teams and stakeholders, providing guidance and insight on identity management and best practices.
Requirements
- 4+ years of full-time engineering experience, post-graduation with specialties in infrastructure and identity systems.
- Infrastructure expertise – IAM controls, Infrastructure as Code (Terraform, Pulumi), microservice deployment best practices.
- Hands-on experience working with OpenFGA, Authzed, Cedar, Topaz, or similar authorization frameworks at scale.
- Strong understanding of Zanzibar-based ReBAC models, relationship tuples, and access control evaluation.
- Strong knowledge of authentication standards such as OAuth 2.0, OIDC, SAML, and JWT.
- Extensive experience in software development and a deep understanding of distributed systems and public cloud platforms (AWS preferred).
- Track record of independent ownership of successful engineering projects.
- Excellent communication and collaboration skills, and the ability to translate complex technical concepts to non-technical stakeholders.
Nice-to-Haves
- Experience securing API access and implementing access control mechanisms at the application level.
- Multi-cloud infrastructure experience – AWS, Azure, GCP, and more.
- Proficiency in integrating IAM solutions with applications built using frameworks such as Java, Python, Node.js, or .NET.
Compensation and Benefits
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The base salary range for this full-time position in the locations of San Francisco, New York, Seattle is: $216,000–$270,000 USD. Employees in eligible roles are also granted equity based compensation. Benefits include comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. This role may be eligible for additional benefits such as a commuter stipend.
Skills
IAM, Terraform, Pulumi, Openfga, Authzed, Cedar, Topaz, Rebac, Oauth 2.0, OIDC, SAML, Jwt, AWS
Similar jobs
Security Engineering jobsThis role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.