Remotery

Staff Software Engineer, Cloud Identity

Posted Jun 21

This is a fully remote position, open to applicants in United States.

πŸ“‹ Description

β€’ Develop and implement the comprehensive identity platform for Temporal Cloud, covering authentication (OAuth 2.0/2.1, OIDC, SAML, token exchange), authorization (RBAC/ReBAC/policy engines), and workload identity federation, enabling customers and workloads to authenticate without relying on long-lived secrets.

β€’ Enhance the authentication hot path to align with Temporal Cloud's service level objectives: including in-memory authentication bundles, JWKS caching, decision caching, and revocation strategies that minimize latency and remove single points of failure.

β€’ Collaborate with enterprise identity providers (IdPs) such as Okta, Entra ID, Google Workspace, SAML/OIDC, manage SCIM 2.0 provisioning, and evaluate identity flows against potential threats like token replay, confused deputy, scope escalation, and mix-up attacks.

β€’ Work alongside Security, Product, and platform teams to deliver secure-by-default patterns, establish IAM lifecycle and audit strategies, and influence the technical roadmap by monitoring emerging standards (IETF OAuth WG, OpenID Foundation).

β€’ Guide engineers, ensure clear architecture documentation is maintained, and engage directly with customers to grasp their requirements and facilitate adoption.


⛳️ Requirements

β€’ Extensive practical experience in building and managing production identity systems, including OAuth 2.0/2.1, OIDC, SAML, JWT/JOSE, JWKS rotation, SCIM, and some familiarity with workload identity (SPIFFE/SPIRE, WIF, mTLS, or short-lived federated credentials).

β€’ Solid understanding of large-scale authorization (RBAC, ABAC, ReBAC/Zanzibar) and experience with policy engines like OPA, Cedar, or OpenFGA.

β€’ Proven history of operating latency-sensitive distributed systems in production, encompassing on-call responsibilities and operational excellence.

β€’ Proficient in Go; familiarity with Python, Java, or Kotlin is an advantage.

β€’ Excellent communication skills, capable of aligning stakeholders across security, product, and engineering teams to drive execution from start to finish.


🏝️ Benefits

β€’ Unlimited PTO, 12 Holidays + 2 Floating Holidays

β€’ 100% Premiums Coverage for Medical, Dental, and Vision

β€’ AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)

β€’ Empower 401K Plan

β€’ Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!

People also viewed

Focus6 hours ago

Senior/Staff Software Engineer

US flagUnited States OnlyFull-timeFull-stack Engineer$100k – $205k/year
ApplyView job
Trellis6 hours ago

Full-Stack Team Lead

US flagUnited States OnlyFull-timeFull-stack Engineer
ApplyView job
Mattel, Inc.6 hours ago

Senior Engineer, EDI Onboarding

IN flagIndia OnlyFull-timeFull-stack Engineer
ApplyView job
Milliman6 hours ago

Senior Software Engineer – Cloud

US flagTexas OnlyFull-timeFull-stack Engineer$93.7k – $177.7k/year
ApplyView job
magentIQ6 hours ago

Mid-Level Full-Stack Software Engineer

PH flagPhilippines OnlyFull-timeFull-stack Engineer
ApplyView job
Stefanini LATAM6 hours ago

Desarrollador FullStack

CO flagColombia OnlyFull-timeFull-stack Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers