Senior Backend Engineer (Identity & Access Management)
Tech Stack / Keywords
Firma i stanowisko
Our customer is an international organization operating in the financial and protection services domain. The project focuses on building and evolving a high-performance, scalable distributed platform designed to support complex business operations and rapid product growth. The system is developed in Go, emphasizing efficient concurrency models, reliability, and long-term maintainability.
Wymagania
- 7+ years of backend engineering experience, including 5+ years with Go.
- Experience with Identity and Access Management (IAM) in production.
- Strong experience building complex distributed backend systems using Go and gRPC.
- Expertise in authentication and authorization: OAuth 2.0, OIDC, SSO, MFA, RBAC, JWT signing/verification, token security, session management, and cryptography.
- Strong understanding of web security, federated identity, secure coding, and OWASP Top 10.
- Hands-on experience with cloud platforms, preferably AWS, container orchestration (Kubernetes), and Infrastructure as Code (Terraform, Terragrunt, OpenTofu/Tofu).
- Experience designing high-throughput, low-latency systems prioritizing security and correctness.
- Strong communication skills for explaining security and architecture decisions to diverse stakeholders.
- Upper-Intermediate or higher English proficiency.
Nice to have:
- Experience with SAML, SCIM, PKI, JWKs/JWKS endpoints, key management (KMS/HSM), and token introspection.
- Knowledge of identity platforms, rate limiting, abuse mitigation, and adaptive authentication.
Obowiązki
- Designing, developing, and operating high-throughput, low-latency identity services including Single Sign-On (SSO), Multi-Factor Authentication (MFA), session management, and federation.
- Owning features end-to-end from design through production and support.
- Implementing and scaling authentication and authorization protocols and token formats (OAuth 2.0, OpenID Connect, JWTs) with secure token issuance, rotation, and revocation.
- Writing clean, concurrent, and performant backend services primarily in Go.
- Designing idiomatic, testable code and clear API contracts (gRPC/HTTP).
- Deploying, managing, and automating identity infrastructure using DevOps practices (CI/CD, monitoring, incident response).
- Acting as subject matter expert on authentication and identity, including security reviews and threat modeling.
- Integrating and maintaining solutions with identity providers like Keycloak and AWS Cognito.
- Mentoring engineers, conducting design reviews, and contributing to the technical roadmap and security posture.
Benefity
- Opportunity to work with leaders in FinTech, Healthcare, Retail, Telecom, and others.
- Ability to change projects or develop expertise in various business domains.
- Work conditions allowing fully remote, office-based, or hybrid options.
- Professional, financial, and career growth with mentoring and adaptation systems.
- Potential to earn up to an additional 1,000 EUR monthly bonus.
- Access to a corporate training portal continuously updated.
- Social events including parties, pizza days, gaming, fruits, coffee, snacks, and movies.
- Certification compensation (e.g., AWS, PMP).
- Referral program.
- Private health insurance and sports compensation depending on employment type.
Inne informacje
Informujemy, że administratorem danych jest Andersen Soft UAB z siedzibą w Krakow, ul. Al. Pokoju 18, 31 - 564 dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
Andersen
56 aktywnych ofert