Staff Software Engineer - Identity and Access Management (IAM)
Core
Lead the technical design and implementation of a unified Identity and Access Management (IAM) platform serving as the foundation for authentication, authorization, governance, and compliance across a large portfolio of cloud products.
Role type
Staff Software Engineer (IAM Platform)
Builds
A centralized identity governance layer supporting customers, partners, employees, APIs, services, and autonomous systems.
Domain
Cybersecurity / Cloud Infrastructure / Identity Management
Deliverable
production ML models | product features | infrastructure
Required skills
Distributed systems architecture, Identity and Access Management (IAM), OAuth 2.0, OpenID Connect (OIDC), SAML, JWTs, MFA, enterprise SSO, delegated authorization, multi-tenant SaaS architectures, RBAC, ABAC, policy-based authorization, secure API platforms, service-to-service authentication, machine identity systems, cloud-native architectures, infrastructure automation.
Preferred skills
Zitadel, Microsoft Entra ID, Okta, Google Workspace, Ping Identity, Active Directory, Open Policy Agent (OPA), Cedar, machine identity lifecycle management, secrets management, certificate management, workload identities, audit and compliance systems, SOC 2, ISO 27001, HIPAA, PCIDSS, NIST, FedRAMP, AI agents, autonomous systems.
Technologies
Zitadel, Keycloak, Authentik, ForgeRock, Ping Identity, Okta, Auth0, Microsoft Entra ID, Google Workspace, Open Policy Agent, Cedar
Responsibilities
Define long-term architecture and technical roadmap for the IAM platform; Lead identity, authentication, authorization, and access governance initiatives; Design, implement, and operate core IAM platform services; Build integrations between identity providers, API gateways, and SaaS products; Design authorization models supporting RBAC, ABAC, and multi-tenant environments; Establish engineering practices for platform reliability, performance, and maintainability.
Seniority
Staff, hands-on technical leadership