Назад
37 минут назад

Staff Product Security Engineer (CIAM)

181 000 - 241 000$
Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer (CIAM): Building and operating backend identity services for registration, authentication, authorization, account lifecycle, and profile management across B2C and B2B platforms with an accent on OAuth 2.0, OIDC, SAML, SCIM, and secure authentication flows. Focus on designing scalable distributed systems, integrating identity platforms with internal services, automating infrastructure and deployments, and optimizing resilience and abuse detection at high scale.

Location: Remote Canada

Base pay: $181,000–$241,000 per year

Company

Affirm is a fintech company building consumer credit products with transparent fees and flexible payment options.

What you will do

  • Design, build, and operate CIAM backend services for registration, authentication, authorization, account lifecycle, and profile management.
  • Implement OAuth 2.0, OIDC, SAML, and SCIM standards through scalable code and integration patterns.
  • Develop Python and Kotlin APIs for web, mobile, and partner applications.
  • Integrate identity services with user data stores, messaging, fraud signals, and downstream customer platforms.
  • Own MFA, step-up authentication, device binding, consent, and adaptive authentication flows.
  • Automate infrastructure and deployments, then monitor and optimize services for performance, resilience, and abuse detection.

Requirements

  • 7+ years of experience designing, developing, and launching backend systems at scale, with at least 5 years of professional backend engineering experience.
  • Strong production experience with Python or a similar backend language; Kotlin experience is relevant.
  • Hands-on experience designing APIs, distributed systems, automation frameworks, CI/CD pipelines, and Infrastructure as Code.
  • Deep practical knowledge of CIAM systems and OAuth 2.0, OIDC, SAML, and SCIM.
  • Experience with cloud-native development, preferably AWS, plus technologies such as Kubernetes, MySQL, and Spark.
  • Strong security fundamentals covering access control, token handling, encryption, MFA, privacy by design, and observability.

Nice to have

  • Experience extending and integrating Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C with custom code, hooks, and APIs.
  • Familiarity with Cursor and other AI-augmented development environments.
  • Experience with GitHub workflows and Buildkite or similar build systems.

Culture & Benefits

  • Remote-first work model within the country of employment.
  • Health coverage with premiums fully covered for employees and dependents.
  • Flexible spending stipends for technology, food, lifestyle, and family-forming expenses.
  • Competitive vacation and holiday schedules.
  • Employee stock purchase plan with discounted shares.

Hiring process

  • Inclusive interview experience with reasonable accommodations available for candidates with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →