Назад
2 дня назад

Software Engineer (Identity & Authorization)

250 000 - 375 000$
Формат работы
hybrid
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Software Engineer (Identity & Authorization): Building and operating identity, authorization, token, and workload-identity systems for Replit's web product, Agent, enterprise controls, and internal services with an accent on multi-tenant security, delegation, and reliable policy enforcement. Focus on designing typed authorization contracts, securing Agent delegation, operating OAuth 2.0/OIDC and mTLS infrastructure, and leading safe migrations with observability and rollback plans.

Location: Foster City, California, United States; hybrid

Salary: $250,000–$375,000 per year, plus equity

Company

Replit is an agentic software creation platform that enables people to build applications using natural language.

What you will do

  • Design and operate central authorization interfaces with typed principals, actions, resources, decisions, deny reasons, delegations, and obligations.
  • Evolve enterprise roles, groups, workspace policies, app access, entitlements, and application-level grants.
  • Build and operate the Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS.
  • Threat-model delegation, confused-deputy risks, and cross-tenant movement while enforcing secure, fail-closed behavior.
  • Lead security-sensitive migrations using shadow evaluation, feature gates, telemetry, and rollback plans; own SLOs, incidents, and operational health.
  • Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to develop shared platform primitives.

Requirements

  • Experience shipping and operating security-sensitive backend or distributed systems in production.
  • Depth in authentication, authorization, or identity systems, including technologies or concepts such as OAuth 2.0/OIDC, JWT, mTLS, identity federation, RBAC, ReBAC, PBAC, Zanzibar, or policy engines.
  • Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling.
  • Experience migrating security-sensitive systems without breaking callers through typed contracts, shadow evaluation, or staged enforcement.
  • Production backend experience with at least one relevant stack; the systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate.
  • Ability to balance security, reliability, latency, product experience, delivery speed, and maintainability.

Culture & Benefits

  • Autonomous work environment with a small, collaborative Identity & Authorization team.
  • Competitive salary, equity, and a 401(k) program with a 4% match for US employees.
  • Health, dental, vision, life, short-term disability, and long-term disability insurance.
  • Paid parental, medical, and caregiver leave, flexible time off, and holidays.
  • Wellness stipend, commuter benefits, in-office setup reimbursement, office amenities, and quarterly team gatherings.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →