
Identity Backend Engineer, IAM Software Engineer
Posted Aug 24

Posted Aug 24
This is a fully remote position, open to applicants in United States.
• Design, create, and integrate RESTful APIs that facilitate identity workflows and partner application authentication.
• Implement OAuth 2.0, OpenID Connect, PKCE, and secure token management methodologies.
• Develop secure API authentication and authorization services utilizing JWT, access tokens, and refresh tokens.
• Integrate backend services with Okta Identity Engine, Okta Embedded SDK, and Department of Defense (DoD) enterprise IAM solutions.
• Connect identity services with authoritative identity repositories and enterprise data sources.
• Create secure backend web services using Java, Spring Boot, .NET, or similar technologies.
• Support API gateway configurations, microservices architecture, and service orchestration.
• Implement JSON/XML data exchange models and establish API contracts.
• Apply enterprise integration patterns and asynchronous messaging techniques.
• Design services for authentication workflow orchestration and session management.
• Develop backend services that support mobile authentication for native iOS and Android applications.
• Implement API security practices, including OWASP API Security Top 10, mTLS, and certificate-based authentication.
• Ensure secure database integration and data access methodologies.
• Create reusable identity services for Partner Applications.
• Implement API Gateway integrations, enterprise audit logging, and operational telemetry.
• Contribute to CI/CD pipelines, automated builds, and DevSecOps processes.
• Conduct unit, integration, and API testing.
• Engage in Agile development, utilize Git-based version control, and maintain secure configuration management.
• Integrate enterprise ICAM/CIAM platforms in cloud or hybrid environments.
• Ensure adherence to NIST SP 800-63 Digital Identity Guidelines and Zero Trust Architecture principles.
• Support DoD cybersecurity requirements, including Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) compliance.
• Assist the Department of Defense in advancing its next-generation ICAM platform to replace DS Logon for secure authentication services.
• 5 years of experience with a BS/BA; 3 years with an MS/MA; 0 years with a PhD; 9 years with a high school diploma.
• Ability to obtain and maintain a Public Trust clearance.
• U.S. Citizenship is required.
• Experience in designing, developing, and integrating RESTful APIs.
• Strong understanding of OAuth 2.0, OpenID Connect (OIDC), PKCE, and token management.
• Proven experience in implementing secure API authentication and authorization using JWT, access tokens, and refresh tokens.
• Familiarity with integrating the Okta Identity Engine (OIE) and enterprise IAM services.
• Experience in connecting identity services with authoritative identity repositories.
• Secure backend development experience using Java, Spring Boot, .NET, or comparable frameworks.
• Experience with API gateways, microservices, and backend orchestration.
• Proficiency in JSON/XML and API contract development.
• Experience in applying enterprise integration patterns and asynchronous messaging.
• Understanding of authentication workflow orchestration and session management.
• Experience in building backend services that support native mobile authentication.
• Knowledge of OWASP API Security Top 10, mTLS, and certificate-based authentication.
• Experience with databases and secure data access methodologies.
• Familiarity with CI/CD pipelines and DevSecOps environments.
• Hands-on experience with unit, integration, and API testing tools such as Postman and Swagger/OpenAPI.
• Experience in supporting enterprise ICAM/CIAM solutions in cloud or hybrid architectures.
• Knowledge of NIST SP 800-63 and Zero Trust Architecture principles.
• Experience in supporting RMF and STIG cybersecurity compliance.
• Preferred: Experience with Okta Identity Engine Embedded SDK, large-scale Federal ICAM/CIAM programs, DoD identity services, CAC/PIV, derived credentials, enterprise credentialing, event-driven architectures, high-security distributed systems, and DoD Zero Trust initiatives.
• Potential eligibility for overtime pay.
• Potential eligibility for shift differentials.
• Potential eligibility for a discretionary bonus.
• 100% remote work opportunity.
Stefanini Brasil
Fusion AI Labs
Fusion AI Labs
Peratera
Get handpicked remote jobs straight to your inbox weekly.