
Team Lead, Backend Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Russia.
• Take ownership of the technical strategy and architecture for the Xsolla ID IAM platform, which includes authentication, authorization, and session management on a large scale.
• Design and enhance OAuth 2.0 / OIDC flows, token lifecycle management strategies, and security fundamentals.
• Lead decisions regarding the Ory ecosystem, custom authentication techniques, and the architecture of the Auth API orchestrator/plugin.
• Ensure web security principles are upheld across the platform.
• Oversee the CockroachDB strategy for geo-distributed data residency.
• Assess complex security-sensitive code and guarantee adherence to best practices.
• Lead the zero-downtime migration from the legacy Xsolla Login system, ensuring bidirectional identity synchronization.
• Identify systemic risks and performance bottlenecks, spearheading remediation efforts.
• Make pivotal decisions regarding system design, security architecture, and technology selections.
• Maintain active involvement in developing critical security features.
• Lead and mentor a team of up to 8 backend engineers.
• Conduct one-on-one meetings, performance evaluations, and career development discussions.
• Recruit and onboard team members possessing IAM/security expertise.
• Promote a security-first culture while managing team workload and delivery commitments.
• Ensure predictable delivery for the mission-critical platform.
• Collaborate with the Product team to outline the IAM roadmap and priorities.
• Coordinate with interdependent product teams, including Xsolla Pay, Wallet, App, and Backpack.
• Provide reports on security posture, platform reliability, and team progress.
• A minimum of 5 years of commercial experience with Go, or over 7 years with other backend programming languages with proficiency in Go.
• Extensive knowledge of OAuth 2.0 / OIDC and IAM systems.
• Familiarity with authorization code + PKCE, client credentials, device flow, token introspection, and refresh strategies.
• Understanding of JWT, token refresh processes, and session management.
• Knowledge of password hashing techniques (bcrypt, Argon2) and secure storage methods.
• Solid understanding of web security fundamentals: cookie security, CSRF, XSS, TLS, and secure session management.
• Strong expertise in MySQL/PostgreSQL and Redis.
• Experience with distributed systems and their associated trade-offs.
• Proven experience in designing high-availability systems that meet 99.9%+ uptime standards.
• Awareness of security best practices and common vulnerabilities as outlined by OWASP.
• Proficient in Docker, Kubernetes, and production deployment processes.
• At least 2 years of experience in leading engineering teams.
• Demonstrated success in delivering mission-critical infrastructure.
• Capacity to lead technical initiatives spanning multiple quarters across teams and to influence architecture beyond the immediate team.
• Experience with security-focused code review methodologies.
• Excellent written and verbal communication skills, including the ability to produce RFCs and design documents.
• Ability to balance security requirements with delivery schedules.
• Preferred hands-on experience with the Ory ecosystem.
• Experience with CockroachDB or other distributed SQL databases is preferred.
• Familiarity with NATS or Kafka is preferred.
• Experience with WebAuthn/FIDO2 passkey implementations is preferred.
• Knowledge of Web3 authentication is preferred.
• Experience with SCIM, SAML, or enterprise SSO is preferred.
• Background in fintech, payments, or gaming identity systems is preferred.
• Familiarity with SOC 2, ISO 27001, PCI DSS, GDPR data minimization, and audit logging is preferred.
• Contributions to open-source security or identity projects are preferred.
• Background in platform or infrastructure engineering is preferred.
• Experience with large-scale user migrations is preferred.
• Practical, current experience with modern AI tools is preferred.
• Unlimited Flexible Time Off to support work-life balance.
• Private health insurance (ДМС) with dental coverage for you and your family.
• Customized career roadmap with clearly defined growth paths.
• Opportunities for professional development through training, security certifications, and conferences.
• Annual corporate events and team gatherings.
• Remote-first culture with flexible working hours (10:00–19:00).
• Leadership development programs and executive coaching.
• Competitive compensation that reflects leadership and security expertise.
Händlerbund
ASRC Federal
SPD Technology
Get handpicked remote jobs straight to your inbox weekly.