Назад
Company hidden
5 дней назад

Principal Platform Engineer (Identity Platform)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Platform Engineer (Identity Platform): Building a multi-tenant authorization platform on SpiceDB and PostgreSQL alongside enterprise authentication infrastructure on Curity, with an accent on ReBAC, production-scale identity operations, and distributed systems. Focus on designing permission models, operating Curity and Keycloak on Kubernetes, writing Go, and solving correctness, latency, consistency, backup, restore, and disaster-recovery challenges.

Location: Staines-upon-Thames, England, United Kingdom; hybrid work opportunities are available.

Company

hirify.global develops AI-native enterprise software on a cloud-based platform for asset, operations, and critical-service management.

What you will do

  • Architect and build a unified fine-grained authorization model across cloud-native, legacy hosting, and lifecycle cloud environments.
  • Develop and operate relationship-based authorization with SpiceDB on PostgreSQL for distributed, multi-tenant enterprise systems.
  • Architect and operate enterprise authentication on Curity while supporting Keycloak migrations, federation, SSO, and directory integration.
  • Design authorization schemas and permission models, balancing correctness, latency, consistency, observability, and traceability.
  • Run identity infrastructure on Kubernetes using Helm, persistent volumes, blue/green cutovers, backup and restore, and disaster recovery.
  • Write Go and contribute to distributed, event-driven systems using Kafka or RedPanda, GitOps, and infrastructure as code.

Requirements

  • Principal-level experience architecting and engineering fine-grained authorization systems at production scale in distributed, multi-tenant environments.
  • Hands-on production experience with SpiceDB, OpenFGA, Ory Keto, or an equivalent Zanzibar-style authorization engine.
  • Practical knowledge of ReBAC, RBAC, ABAC, policy-as-code approaches such as OPA/Rego or Cedar, and authorization schema design.
  • Hands-on production experience operating Curity and/or Keycloak, including configuration, customization, extensions, upgrades, and troubleshooting under load.
  • Deep knowledge of OAuth 2.0, OIDC, SAML 2.0, JWT and opaque-token patterns, enterprise federation, SSO, LDAP, and Active Directory.
  • Experience with Go, PostgreSQL, Kubernetes or AKS, containers, GitOps, infrastructure as code, and event-driven distributed systems.

Culture & Benefits

  • Hybrid work opportunities with flexibility to support different working styles.
  • Work in a global and diverse enterprise software environment.
  • Strong emphasis on collaboration, sustainability, inclusion, and practical impact.
  • Hands-on engineering culture that values clear technical opinions and constructive challenge.
  • Use of AI tooling is expected, with emphasis on understanding what engineers delegate and what they build themselves.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →