Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Product Security Engineer (CIAM): Building and operating backend identity services for registration, authentication, authorization, account lifecycle, and profile management across B2C and B2B platforms with an accent on OAuth 2.0, OIDC, SAML, SCIM, and secure authentication flows. Focus on designing scalable distributed systems, integrating identity platforms with internal services, automating infrastructure and deployments, and optimizing resilience and abuse detection at high scale.
Location: Remote Canada
Base pay: $181,000–$241,000 per year
Company
Affirm is a fintech company building consumer credit products with transparent fees and flexible payment options.
What you will do
- Design, build, and operate CIAM backend services for registration, authentication, authorization, account lifecycle, and profile management.
- Implement OAuth 2.0, OIDC, SAML, and SCIM standards through scalable code and integration patterns.
- Develop Python and Kotlin APIs for web, mobile, and partner applications.
- Integrate identity services with user data stores, messaging, fraud signals, and downstream customer platforms.
- Own MFA, step-up authentication, device binding, consent, and adaptive authentication flows.
- Automate infrastructure and deployments, then monitor and optimize services for performance, resilience, and abuse detection.
Requirements
- 7+ years of experience designing, developing, and launching backend systems at scale, with at least 5 years of professional backend engineering experience.
- Strong production experience with Python or a similar backend language; Kotlin experience is relevant.
- Hands-on experience designing APIs, distributed systems, automation frameworks, CI/CD pipelines, and Infrastructure as Code.
- Deep practical knowledge of CIAM systems and OAuth 2.0, OIDC, SAML, and SCIM.
- Experience with cloud-native development, preferably AWS, plus technologies such as Kubernetes, MySQL, and Spark.
- Strong security fundamentals covering access control, token handling, encryption, MFA, privacy by design, and observability.
Nice to have
- Experience extending and integrating Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C with custom code, hooks, and APIs.
- Familiarity with Cursor and other AI-augmented development environments.
- Experience with GitHub workflows and Buildkite or similar build systems.
Culture & Benefits
- Remote-first work model within the country of employment.
- Health coverage with premiums fully covered for employees and dependents.
- Flexible spending stipends for technology, food, lifestyle, and family-forming expenses.
- Competitive vacation and holiday schedules.
- Employee stock purchase plan with discounted shares.
Hiring process
- Inclusive interview experience with reasonable accommodations available for candidates with disabilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Staff Security Engineer (IAM)
5 дней назад
Senior Cloud Security Engineer (AI Security)
123 000 - 181 000$
16 часов назад
Senior Security Engineer (AI)
150 000 - 190 000CAD
12 часов назад
Security Engineer (AWS)
104 148 - 140 000$
Snowflake
7 дней назад
Security Engineer (AI)
122 000 - 174 800$
5 дней назад