Staff Software Engineer, Identity & Access Management
Staff Software Engineer on the IAM team designing, delivering, and supporting digital identity, authentication, and access systems. Requires 10+ years backend experience, deep IAM expertise, and proficiency in Go/Python/Java/TypeScript.
About the job
What You'll Do
Engineering & Integration
- Develop, scale and maintain Reddit’s core IAM internal identity capabilities, platforms and infrastructure
- Design and deploy high-quality API integrations and custom enterprise IGA connectivity solutions
Observability & Data Analytics
- Build proactive monitoring frameworks, executive-friendly dashboards, and advanced alerting
- Use synthetic transactions and anomaly detection to measure system availability (aiming for multiple 9s)
- Utilize identity data to track license utilization, aid in fiscal planning, and drive platform adoption
Process & Compliance
- Create and maintain documentation, audit logs, and reports to continuously improve business processes and ensure seamless compliance execution
Operations & Support
- Troubleshoot complex production incidents, analyze failure conditions, and perform root-cause analysis to support a 24x7 operation
Collaboration & Mentorship
- Guide global, cross-functional partners on IAM best practices
- Raise the engineering bar through code reviews, technical standards, and optimized workflows
Technologies We Use
- Languages: Go, Python, Java, TypeScript, SQL
- Datastores: Postgres, Directory architectures (e.g., LDAP)
- Tools: Docker, Kubernetes, AWS, SailPoint, Okta
What We Are Looking For
Experience and Core Capabilities
- 10+ years of backend development experience across multiple layers of the stack—from databases and networking to efficient computing
- In-depth knowledge of corporate IAM experience covering the full workforce identity lifecycle (Joiner, Mover, Leaver, Access Requests, and Certifications)
- Ability to design and implement complex distributed systems operating under high load
- Proficiency in Go, Python, Java, or TypeScript, with a strong DevOps mindset and end-to-end code ownership (testing, monitoring, deploying, and maintaining)
- Deep understanding of modern authentication protocols (OAuth, OIDC, SAML) and secure-by-design principles
- Hands-on familiarity with enterprise identity solutions including IGA, MFA, PAM / PIM, JIT and Directory architectures (e.g., Okta, LDAP, SailPoint)
Governance and Compliance
- Familiarity with governance and compliance frameworks (SOC2, SOX, PCI), including driving audit-related access certification reviews
Collaboration Skills
- Strong collaborative communicator thriving in Agile environments, with a continuous learning mindset and a resourceful, "can-do" approach to complex problem-solving
Benefits
- Comprehensive Healthcare Benefits and Income Replacement Programs
- 401k with Employer Match
- Global Benefit programs that fit your lifestyle, from workspace to professional development to caregiving support
- Family Planning Support
- Gender-Affirming Care
- Mental Health & Coaching Benefits
- Flexible Vacation & Paid Volunteer Time Off
- Generous Paid Parental Leave
Skills
Go, Python, Java, TypeScript, SQL, Postgres, Ldap, Docker, Kubernetes, AWS, Sailpoint, Okta, OAuth, OIDC, SAML
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.