We are looking for Software Engineer - Authentication & Identity Management to join our team.
Key Responsibilities:
- Design, build, and support identity services such as SSO, MFA, session management, and federation;
- Own features from initial design through release and production support;
- Implement and maintain authentication and authorization flows using OAuth 2.0, OpenID Connect, and JWT;
- Build secure token handling processes, including issuance, rotation, and revocation;
- Develop backend services mainly in Go, with clear and reliable gRPC and HTTP APIs;
- Help deploy, operate, and improve identity infrastructure, including CI/CD, monitoring, and incident response;
- Act as the main technical expert for authentication and identity topics;
- Lead or support security reviews and threat modeling for identity-related flows;
- Integrate with identity providers such as Keycloak, AWS Cognito, and other federation solutions;
- Support other teams with secure integrations and best practices;
- Review designs, mentor engineers, and contribute to the team’s technical direction.
What we are looking for:
- Strong experience building distributed backend systems in production;
- Good hands-on experience with Go and gRPC;
- Strong understanding of authentication and authorization concepts, including: OAuth 2.0, OpenID Connect, JWT, session management, RBAC;
- Good understanding of token security and basic cryptography concepts related to identity systems;
- Solid knowledge of web security, secure coding practices, and common security risks such as OWASP Top 10;
- Experience with AWS, Kubernetes, and Terraform;
- Experience building systems that handle high traffic and low latency;
- Ability to explain technical and security decisions clearly to both technical and non-technical stakeholders;
- Strong communication and cross-team collaboration skills.
Nice to have:
- Experience with SAML, SCIM, PKI, JWK/JWKS, KMS/HSM, and token introspection;
- Experience with commercial or open-source identity platforms;
- Familiarity with rate limiting, abuse prevention, and adaptive authentication.
We offer:
- Maximum flexibility;
- Professional trainings, conferences and certifications;
- Corporate events and benefits;
- Professional literature;
- English courses.
If you are interested, please let us know job@zfort.com