Staff Software Engineer, Identity & Authorization
Core
Design, build, and operate identity and authorization systems protecting critical interactions on Replit, including agent delegation and enterprise access control.
Role type
Staff Software Engineer, Identity & Authorization
Builds
Central authorization interfaces, Security Token Service, workload identity systems, and enterprise policy frameworks.
Domain
SaaS platform security, distributed systems, agentic AI workflows
Deliverable
production ML models | product features | infrastructure
Required skills
OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, policy engines, multi-tenant security, threat modeling, system migration, typed contracts, shadow evaluation
Preferred skills
TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, Restate
Technologies
OAuth 2.0, OIDC, JWT, mTLS, SPIFFE, SPIRE, TypeScript, Go, Rust, Postgres, gRPC, Protobuf, Kubernetes, Envoy, Restate
Responsibilities
Design central authorization interfaces with typed principals and explainable deny reasons; evolve enterprise roles and workspace policies; build and operate Security Token Service and workload identity; threat-model delegation and confused-deputy risks; lead compatible migrations with shadow evaluation and feature gates; partner with Agent and Enterprise teams to define platform primitives.
Seniority
Staff, hands-on IC with strategic scope
