16 часов назад
Principal Platform Engineer (Identity and Access Management)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Platform Engineer (Identity and Access Management): Architecting and operating unified enterprise-scale authorization and authentication platforms across Nexus, F1, and LEC with an accent on fine-grained access control, identity federation, and cloud-native reliability. Focus on building SpiceDB-based ReBAC systems, implementing Curity or Keycloak with OAuth 2.0, OIDC, and SAML, and integrating IAM services with developer platforms.
Location: Staines-upon-Thames, England, United Kingdom; hybrid work opportunities
Company
develops AI-native, cloud-based enterprise software for asset, operations, and critical-service management, with more than 7,000 employees worldwide.
What you will do
- Architect and engineer a unified, enterprise-scale authorization platform across Nexus, F1, and LEC using SpiceDB.
- Design fine-grained ReBAC, RBAC, and ABAC models, schemas, relationships, and permission checks for distributed multi-tenant workloads.
- Operate SpiceDB on PostgreSQL, including migration to cloud-native PostgreSQL and blue-green deployment support.
- Build authorization APIs and SDKs and define secure IAM standards, patterns, and golden paths for product teams.
- Architect and operate enterprise authentication infrastructure with Curity and/or Keycloak, including OAuth 2.0, OIDC, SAML, token lifecycle management, and claims-based authorization.
- Integrate identity and access services with the Internal Developer Platform and advise platform, product, architecture, and security stakeholders.
Requirements
- Production-scale experience architecting fine-grained authorization systems in distributed, multi-tenant environments.
- Hands-on experience with relationship-based or policy-based authorization engines, ideally SpiceDB or comparable Zanzibar-inspired systems.
- Deep practical knowledge of ReBAC, RBAC, ABAC, policy-as-code, authorization schemas, and permission-model correctness, latency, and consistency.
- Production experience with Curity and/or Keycloak, OAuth 2.0, OIDC, SAML 2.0, JWTs, opaque tokens, token introspection, SSO, LDAP, and Active Directory.
- Engineering capability with Go, Apache Kafka or RedPanda, PostgreSQL, Kubernetes on AKS, containers, GitOps, and Infrastructure as Code.
- Experience with event-driven and distributed systems, observability, secure coding, and security-by-design.
Culture & Benefits
- Hybrid and flexible work opportunities.
- International, diverse environment serving customers across the globe.
- Collaborative work with platform, product, architecture, and security teams.
- Opportunity to contribute to AI-native enterprise software and sustainability-focused initiatives.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →