Job Description
Senior Software Engineer – IAM
Responsibilities
- Design, build, and harden identity and access flows — OIDC/OAuth 2.0, SAML 2.0, Active Directory integrations — that sit in front of mission-critical systems.
- Own token and assertion lifecycle correctness: issuance, validation, expiry, rotation, and failure-mode handling for JWT/JWKS and SAML assertions.
- Apply strong applied-cryptography and PKI practices (X.509 certs, key rotation, TLS) to keep the auth path secure by default, not as an afterthought.
- Build and maintain reverse-proxy/HTTP-layer components (TLS termination, header handling) that front customer authentication traffic.
- Debug and resolve customer-facing identity/access issues, working with support to triage escalations quickly.
- Contribute to build/release and cross-platform packaging (Linux deb/rpm, Windows MSI) as needed.
- Maintain a small Windows companion application written in C#/.NET.
- Write and enhance end-to-end tests covering auth flows, failure modes, and edge cases (clock skew, revoked tokens, malformed assertions, etc.).
- Document known issues, workarounds, and design decisions in the team knowledge base as the team and product mature.
- Communicate clearly with product and engineering stakeholders on design tradeoffs, security posture, and escalation status.
Requirements
Must-have
- Strong hands-on programming skills in Golang.
- Deep, practical knowledge of identity protocols: OIDC/OAuth 2.0 and SAML 2.0 — including token/assertion internals, standard flows, and failure modes.
- Working knowledge of Active Directory.
- Applied cryptography/PKI experience: X.509, JWT/JWKS, key rotation, TLS.
- Strong security engineering discipline — comfortable reasoning about threat models and building software to protect mission-critical systems, not just make features work.
- Solid understanding of OS fundamentals, networking, and concurrency.
- Working knowledge of Linux; comfortable writing shell/bash scripts.
- Simple, effective written and verbal communication.
Nice-to-have
- Directory internals (schema, bind operations).
- HTTP internals and reverse proxying (TLS, header injection).
- Build/release and cross-platform packaging (Linux deb/rpm, Windows MSI).
- Secret-manager internals, Redis, Win32, policy engines.
- Basic C#/.NET (to maintain the companion app).
About this job listing
This job opportunity is provided through our
external job listing network. MyJobAlerts helps
you discover job opportunities and redirects you
to the original listing to apply.