5 months ago
Toronto, CanadaStaff+
Responsibilities
- Design and implement advanced token management, refresh token rotation, proof-of-possession tokens, token introspection, and real-time revocation.
- Lead development of an extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and business logic evaluation.
- Architect globally distributed identity infrastructure with edge optimization, token caching, cross-region replication, and low-latency authentication.
- Build rate limiting, anomaly detection, fraud prevention, identity federation, protocol adapters, client management, and extensible plugin capabilities.
- Drive compliance frameworks, audit trails, data residency controls, privacy-preserving token designs, and identity security initiatives.
- Lead developer experience and observability initiatives involving SDKs, webhooks, audit logging, analytics dashboards, distributed tracing, metrics, and security event correlation.
- Set technical strategy and mentor engineering teams on zero-trust architecture, workload identity, and service mesh integration.
Requirements
- 7+ years of experience building production identity platforms, including systems handling millions of authentication requests daily.
- Deep expertise in OAuth 2.0 extensions including PKCE, mTLS, JWT bearer assertions, token exchange, OAuth 2.1, GNAP, and OpenID Connect.
- Experience architecting multi-tenant identity platforms with tenant isolation, tenant-specific configuration, delegated administration, and fine-grained permissions.
- Strong cryptography background including JWT patterns, key rotation, HSM integration, and post-quantum cryptography considerations.
- Experience with enterprise identity integrations including SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.
- Experience building identity analytics, monitoring, security event detection, SDKs, webhooks, extensible APIs, and developer-first platforms.
- Knowledge of threat modeling, penetration testing coordination, attack prevention, compliance, audit trails, data residency, and privacy engineering.
- Experience with edge deployment, geo-distributed token validation, cross-region consistency, horizontal scaling, caching, and latency optimization.
- Knowledge of service mesh identity, workload identity bootstrapping, and container orchestration integrations.
- Ability to lead technical initiatives and mentor teams in complex, regulated environments.
