8 дней назад
Principal Platform Engineer (Identity Platform)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Platform Engineer (Identity Platform): Building shared authentication and authorisation services, APIs, and automation for a distributed multi-tenant enterprise software platform with an accent on Kubernetes, infrastructure as code, OAuth 2.0, OpenID Connect, and fine-grained access control. Focus on designing reliable self-service identity capabilities, operating Curity, Keycloak, and SpiceDB-based systems, and solving correctness, latency, consistency, and security challenges across multiple hosting environments.
Location: Krakow, Lesser Poland, Poland; hybrid work opportunities
Company
develops AI-native, cloud-based enterprise software for asset, operations, and critical-service management at global scale.
What you will do
- Build and operate shared authentication and authorisation platform services, APIs, integrations, and automation.
- Unify authorisation across cloud-native, legacy hosting, and lifecycle cloud environments.
- Develop secure, documented, automated self-service workflows for product engineering teams.
- Write and review infrastructure, automation, Go tooling, and platform service code.
- Operate production systems with observability, performance testing, safe rollouts, rollback, backup, and recovery practices.
- Provide technical leadership through architecture decisions, code reviews, engineering standards, and support for other engineers.
Requirements
- Substantial hands-on experience building and operating platforms or shared infrastructure for software engineering teams.
- Strong coding and scripting skills applied to infrastructure, automation, deployment tooling, or integrations, including automated testing.
- Production experience with Kubernetes, containers, a major public cloud, Infrastructure as Code, CI/CD, and GitOps.
- Practical experience implementing authentication and access control in applications, APIs, or shared platform services.
- Working knowledge of OAuth 2.0, OpenID Connect, token-based authentication, permission models, least privilege, and tenant isolation.
- Ability to troubleshoot distributed systems and translate security requirements into working software, automated tests, and maintainable platform capabilities.
Nice to have
- Production experience with Curity, Keycloak, SpiceDB, or comparable fine-grained authorisation engines.
- Experience with enterprise federation, SAML, policy-as-code, or authentication and authorisation in distributed multi-tenant systems.
- Production experience with Go, PostgreSQL, Kafka, or Redpanda.
- Experience building self-service identity APIs or SDKs for engineering teams.
Culture & Benefits
- Hybrid work opportunities with flexibility to support different working needs.
- Inclusive, international environment focused on collaboration, trust, sustainability, and technical ownership.
- Opportunity to work on AI-native enterprise software and critical platform capabilities used across the engineering organisation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →