Principal Platform Engineer || Identity Platform (AuthNAuthZ)
Job Summary
The job
Authorisation is the single biggest blocker to our next-generation platform right now. Two Principal Platform Engineers are joining to unblock it.
We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform our legacy hosting platform and our lifecycle cloud. It is built on SpiceDB (relationship-based access control) on PostgreSQL and it has to be correct fast and multi-tenant at enterprise scale. Alongside it we run enterprise authentication on Curity with Keycloak estates migrating onto it.
You will architect and build that own it in production and set the identity patterns the rest of engineering follows. This is a hands-on engineering role. You will write Go.
What we need to see
Authorisation
- Fine-grained authorisation systems you have built and run at production scale in distributed multi-tenant environments
- Hands-on production experience with a Zanzibar-style authorisation engine: SpiceDB OpenFGA Ory Keto or equivalent
- Authorisation schemas and permission models you have designed and the ability to reason about correctness latency and consistency together
- ReBAC RBAC and ABAC and a view on when each is the right answer
- Policy-as-code exposure: OPA/Rego Cedar or similar
- Running the authorisation engine in production on PostgreSQL with observability and traceability of the decisions it makes
Authentication
- Enterprise-scale authentication you have architected and operated not integrated with
- Hands-on production Curity and/or Keycloak: configuration customisation extensions upgrades operations
- OAuth 2.0 OIDC SAML 2.0 and token patterns at a level where you can explain why a given flow what its failure modes are and where PKCE belongs
- Enterprise federation SSO and directory integration in a bring-your-own-identity model with per-tenant signing keys
Operations and engineering
- Identity infrastructure on Kubernetes (AKS): Helm persistent volumes blue/green cutovers backup and restore DR
- An IdP under load: config import latency JVM tuning pod sizing dedicated node pools and a story about what fell over and how you found it
- Go PostgreSQL Kafka/RedPanda GitOps IaC. Exact match not required ability to get there fast is
- You still write code. These are principal engineers who build not IAM consultants who produce documents
How we work
We expect that AI tooling has changed how you work. We will ask what you delegate what you still do yourself and what you built to stop it breaking. Specifics not a list of tools.
We want strong opinions held out loud. If you would not push back on your director in week two this will not suit you.
Qualifications :
Authorisation (Must Have)
- Architecting and engineering fine-grained authorisation systems at production scale in distributed multi-tenant environments
- Hands-on production experience with a relationship-based / policy-based authorisation engine ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA Ory Keto or equivalent)
- Deep practical knowledge of authorisation models: relationship-based access control (ReBAC) role-based (RBAC) and attribute-based (ABAC) and knowing when to apply each
- Experience designing authorisation schemas and permission models and reasoning about correctness latency and consistency at scale
- Familiarity with policy-as-code approaches and tooling (OPA / Rego Cedar or equivalent)
- Understanding of the operational side: running the authorisation engine in production backed by PostgreSQL with observability and traceability of authorisation decisions
Authentication (Must Have)
- Architecting and engineering enterprise-scale AuthN solutions demonstrated at production scale
- Hands-on production experience with Curity and/or Keycloak: configuration customisation operations and integration
- Deep practical knowledge of OAuth 2.0 OpenID Connect (OIDC) SAML 2.0 and token-based authentication patterns (JWT opaque tokens token introspection)
- Experience with enterprise identity federation SSO and directory integration (LDAP Active Directory)
- Strong hands-on engineering capability across the NGA stack or the ability to get there fast:
- Backend: Go
- Messaging / Streaming: Apache Kafka / RedPanda
- Data: PostgreSQL
- Comfortable operating in a cloud-native environment: Kubernetes (AKS) containers GitOps Infrastructure as Code
- Event-driven and distributed systems architecture
- Secure coding practices and security-by-design principles
Additional Information :
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles while also valuing inclusive workplace experiences. By fostering a sense of community we drive innovation strengthen connections and nurture belonging. Our commitment ensures you can work in a way that suits you best while also engaging with colleagues to share ideas and build meaningful relationships.
Remote Work :
No
Employment Type :
Full-time
About Company
We are growing! At IFS we are constantly growing to deliver award-winning solutions to hundreds of partners and thousands of customers worldwide! We help companies who want to be their best when it matters most at their #momentofservice. Visit https://ifs.link/IzM0px to find out mo ... View more