Назад
Company hidden
16 часов назад

Principal Platform Engineer (Identity and Access Management)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Platform Engineer (Identity and Access Management): Architecting and operating unified enterprise-scale authorization and authentication platforms across Nexus, F1, and LEC with an accent on fine-grained access control, identity federation, and cloud-native reliability. Focus on building SpiceDB-based ReBAC systems, implementing Curity or Keycloak with OAuth 2.0, OIDC, and SAML, and integrating IAM services with developer platforms.

Location: Staines-upon-Thames, England, United Kingdom; hybrid work opportunities

Company

hirify.global develops AI-native, cloud-based enterprise software for asset, operations, and critical-service management, with more than 7,000 employees worldwide.

What you will do

  • Architect and engineer a unified, enterprise-scale authorization platform across Nexus, F1, and LEC using SpiceDB.
  • Design fine-grained ReBAC, RBAC, and ABAC models, schemas, relationships, and permission checks for distributed multi-tenant workloads.
  • Operate SpiceDB on PostgreSQL, including migration to cloud-native PostgreSQL and blue-green deployment support.
  • Build authorization APIs and SDKs and define secure IAM standards, patterns, and golden paths for product teams.
  • Architect and operate enterprise authentication infrastructure with Curity and/or Keycloak, including OAuth 2.0, OIDC, SAML, token lifecycle management, and claims-based authorization.
  • Integrate identity and access services with the Internal Developer Platform and advise platform, product, architecture, and security stakeholders.

Requirements

  • Production-scale experience architecting fine-grained authorization systems in distributed, multi-tenant environments.
  • Hands-on experience with relationship-based or policy-based authorization engines, ideally SpiceDB or comparable Zanzibar-inspired systems.
  • Deep practical knowledge of ReBAC, RBAC, ABAC, policy-as-code, authorization schemas, and permission-model correctness, latency, and consistency.
  • Production experience with Curity and/or Keycloak, OAuth 2.0, OIDC, SAML 2.0, JWTs, opaque tokens, token introspection, SSO, LDAP, and Active Directory.
  • Engineering capability with Go, Apache Kafka or RedPanda, PostgreSQL, Kubernetes on AKS, containers, GitOps, and Infrastructure as Code.
  • Experience with event-driven and distributed systems, observability, secure coding, and security-by-design.

Culture & Benefits

  • Hybrid and flexible work opportunities.
  • International, diverse environment serving customers across the globe.
  • Collaborative work with platform, product, architecture, and security teams.
  • Opportunity to contribute to AI-native enterprise software and sustainability-focused initiatives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →