
Staff Software Engineer, Konnect Core Platform
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in California, +1 more state.
β’ Design the multi-tenant identity platform for Kong Identity, accommodating intricate organizational structures, cross-tenant isolation, and enterprise-level security measures.
β’ Create and execute sophisticated token management systems featuring refresh token rotation, proof-of-possession tokens, custom introspection, and real-time revocation.
β’ Spearhead the development of a flexible claims engine with dynamic attribute resolution, contextual claim injection, and business logic assessment.
β’ Construct a global identity infrastructure optimized for edge performance, token caching, cross-region replication, and low-latency authentication.
β’ Develop systems for rate limiting, anomaly detection, and fraud prevention.
β’ Establish enterprise identity federation capabilities, incorporating SAML bridges, external IdP chaining, and custom protocol adapters.
β’ Drive developer experience initiatives, including SDKs, webhooks, audit logging, and real-time analytics dashboards.
β’ Design client management systems featuring dynamic registration, credential rotation, and programmatic policy enforcement.
β’ Create a plugin architecture for custom grant flows, protocol extensions, and third-party integrations.
β’ Lead compliance efforts encompassing SOC 2, FedRAMP, GDPR, audit trails, data residency, and privacy-preserving token designs.
β’ Oversee observability integrations for distributed tracing, metrics collection, and security event correlation.
β’ Mentor engineering teams on zero-trust architectures, workload identity, and service mesh integration patterns.
β’ Over 7 years of experience in developing production identity platforms at identity providers or enterprise software firms.
β’ Demonstrated success in managing millions of authentication requests daily.
β’ Extensive knowledge of OAuth 2.0 extensions, including PKCE, mTLS, JWT bearer assertions, and token exchange.
β’ Proficient in OpenID Connect, OAuth 2.1, and GNAP.
β’ Experience in architecting multi-tenant identity platforms with complex isolation, tenant-specific settings, and enterprise functionalities.
β’ Strong foundation in cryptographic protocols, advanced JWT patterns, key rotation, HSM integration, and considerations for post-quantum cryptography.
β’ Background in enterprise-scale analytics, real-time monitoring, and security event detection.
β’ Expertise in edge deployment, geo-distributed token validation, and cross-region data consistency.
β’ Familiarity with SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.
β’ Experience in building SDKs, webhook systems, and extensible APIs.
β’ Skills in threat modeling, coordination of penetration testing, and advanced attack prevention strategies.
β’ Background in compliance, audit trail design, data residency controls, and privacy engineering.
β’ Experience supporting complex organizational structures, delegated administration, and granular permissions.
β’ Expertise in horizontal scaling, caching architectures, and latency optimization.
β’ Knowledge of service mesh identity, workload identity bootstrapping, and integration with container orchestration.
β’ Experience with identity protocol extensions, custom grant flows, and extensible identity platforms.
β’ Capability to lead technical initiatives within complex, regulated environments.
β’ Equity
β’ Bonus
β’ Healthcare benefits
β’ 401(k) plan
β’ Short- and long-term disability benefits
β’ Basic life and AD&D insurance
Sigma Software Group
Collectly
Allata
Get handpicked remote jobs straight to your inbox weekly.