Назад
Company hidden
6 дней назад

Principal Platform Engineer (Identity Platform)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Platform Engineer (Identity Platform) (SpiceDB/Curity/Go): Building and operating fine-grained, multi-tenant authorization and enterprise authentication infrastructure across cloud and legacy hosting environments with an accent on correctness, latency, consistency, and production reliability. Focus on designing Zanzibar-style permission models, operating Curity and Keycloak on Kubernetes, and solving distributed identity challenges at enterprise scale.

Location: Staines-upon-Thames, England, United Kingdom; hybrid work opportunities are available.

Company

hirify.global builds AI-native enterprise software for asset, operations, and critical-service management on a cloud-based platform.

What you will do

  • Architect and build a unified fine-grained authorization model across cloud-native, legacy hosting, and lifecycle cloud environments.
  • Operate SpiceDB-based relationship authorization on PostgreSQL for correct, fast, multi-tenant access decisions.
  • Architect and operate enterprise authentication with Curity while supporting Keycloak estate migrations.
  • Design identity patterns covering federation, SSO, directory integration, tenant signing keys, and token flows.
  • Run identity infrastructure on Kubernetes, including Helm deployments, persistent storage, cutovers, backup and restore, and disaster recovery.
  • Write Go code and improve observability, performance, and resilience of identity services under production load.

Requirements

  • Production-scale experience engineering fine-grained authorization systems in distributed, multi-tenant environments.
  • Hands-on experience with SpiceDB, OpenFGA, Ory Keto, or an equivalent Zanzibar-style authorization engine, including ReBAC, RBAC, ABAC, schemas, and permission models.
  • Production experience architecting and operating Curity and/or Keycloak, including configuration, customization, extensions, upgrades, and operations.
  • Strong knowledge of OAuth 2.0, OIDC, SAML 2.0, JWT and opaque token patterns, federation, SSO, LDAP, and Active Directory.
  • Experience with Go, PostgreSQL, Kafka or RedPanda, Kubernetes on AKS, containers, GitOps, infrastructure as code, and distributed systems.
  • Ability to operate identity providers under load and handle observability, JVM tuning, sizing, backup, restore, and disaster recovery.

Culture & Benefits

  • Hybrid work opportunities with an emphasis on inclusive workplace experiences and community.
  • Flexible working arrangements designed to support diverse needs and lifestyles.
  • International environment focused on collaboration, sustainability, innovation, and positive global impact.
  • Direct communication and strong technical opinions are encouraged.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →