Remote job
Staff Software Engineer - Customer Identity & Access Management (CIAM)
Job details
About this role
Role overview A staff software engineer role on a Customer Identity and Access Management team building centralized identity services for an edge cloud platform. The position involves leading the design and delivery of authentication, authorization, and identity lifecycle capabilities while serving as a technical anchor across multiple workstreams that empower customers with advanced access controls and a unified identity experience.
Responsibilities - Design and build secure, scalable identity services covering authentication, authorization, identity lifecycle, and related platform capabilities. - Lead complex technical initiatives from design through production, balancing long-term architecture with practical delivery milestones. - Act as technical lead for one or more core areas of the platform, guiding architecture, reviewing designs, and supporting sound technical decisions. - Partner with engineering, product, and security counterparts to shape implementation plans, prioritize investments, and surface risks early. - Translate ambiguous technical problems into incremental, high-quality solutions that hold a strong engineering bar. - Champion modern, standards-based identity patterns and mentor engineers through design reviews and collaborative problem solving. - Participate in on-call support rotation as needed to maintain reliability of identity services.
Requirements - Significant production experience designing and operating authentication and authorization systems, typically 7+ years of relevant work. - Deep understanding of identity and access standards and technologies such as OIDC, OAuth, SAML, SCIM, JWT, and SSO. - Experience with service-to-service authentication and secure communication patterns in distributed systems. - Strong background in software architecture and system design across scalability, performance, reliability, and security. - Demonstrated ability to provide technical leadership across multiple teams through architectural guidance and delivery of complex initiatives. - Strong written and verbal communication skills, with the ability to produce clear documentation and align diverse stakeholders.
Nice to have - Experience with Go, Java, or Ruby. - Hands-on experience with Keycloak. - Production experience implementing Role-based and Attribute-based Access Control systems. - Background designing secure identity systems with attention to authentication threats, authorization models, and operational resilience.
Benefits and work setup - Estimated salary range of $211,370 to $253,644, with eligibility for equity and discretionary bonus programs. - Comprehensive medical, dental, and vision coverage, plus life, disability, and accident insurance starting day one. - Family planning benefits, mental health support, an Employee Assistance Program, flexible vacation, and up to 18 days of accrued paid sick leave. - 401(k) with company match and an Employee Stock Purchase Program. - 11 paid local holidays and 12 paid company wellness days for the year. - Strong preference for hybrid work near a local office, with potential to consider qualified remote candidates within the US; quarterly travel may be required to align on technical direction.