Senior Backend Engineer (IAM)
We are hiring a Senior Backend Engineer (Identity & Access Management) for a project building a scalable distributed platform and delivering reliable backend solutions.
Our customer is an international organization operating in the financial and protection services domain. The company provides a diverse portfolio of customer-oriented solutions across multiple business areas and markets. With a strong focus on digital capabilities, operational excellence, and long-term development, the organization continuously invests in technology, process improvement, and service innovation to support evolving customer and business needs.
The project focuses on building and evolving a high-performance, scalable distributed platform designed to support complex business operations and rapid product growth. The system is developed in Go, with a strong emphasis on efficient concurrency models, reliability, and long-term maintainability.
Responsibilities:
- Designing, developing, and operating high-throughput, low-latency identity services: Single Sign-On (SSO), Multi-Factor Authentication (MFA), session management, and federation.
- Owning features end-to-end from design through production and support.
- Implementing and scaling modern authentication and authorization protocols and token formats (OAuth 2.0, OpenID Connect, JWTs), including secure token issuance, rotation, and revocation strategies.
- Writing clean, concurrent, and highly performant backend services primarily in Go.
- Designing idiomatic, testable code and clear API contracts (gRPC/HTTP).
- Using DevOps experience to deploy, manage, and automate identity infrastructure (CI/CD, monitoring, and incident response).
- Serving as the subject matter expert on authentication and identity: owning internal security reviews, threating modeling for identity flows, and guiding other teams on secure integrations with the platform.
- Integrating and maintaining solutions with custom and standard identity providers (e.g. Keycloak and AWS Cognito), and federation patterns.
- Mentoring engineers, conducting design reviews, and contributing to the team's technical roadmap and security posture.
Must-haves:
- Experience in backend engineering for 7+ years, including 5+ years with Go.
- Experience working with IAM in production environments.
- Strong production experience with Go and gRPC, building complex, distributed backend systems.
- Deep expertise in authentication and authorization, including OAuth 2.0, OIDC, SSO, MFA, RBAC, JWT signing/verification/assertions, token security, session management, and cryptography.
- Strong understanding of web security, federated identity, secure coding, and OWASP Top 10.
- Hands-on experience with cloud platforms (AWS preferred), container orchestration (Kubernetes), and Infrastructure as Code (Terraform, Terragrunt and OpenTofu/Tofu).
- Experience designing high-throughput, low-latency systems with a focus on security and correctness.
- Strong communication skills and ability to explain security and architecture trade-offs to technical and non-technical stakeholders.
Level of English โ from Upper-Intermediate and above.
Nice-to-haves:
- Experience with SAML, SCIM, PKI, JWKs/JWKS endpoints, key management (KMS/HSM) and token introspection.
- Working knowledge of identity platforms (commercial or open source), rate limiting, abuse mitigation, and adaptive authentication.