IFS

Principal Platform Engineer || Identity Platform (AuthN/AuthZ)

IFS
Apply
2 days ago
’s-Hertogenbosch, NetherlandsStaff+

Responsibilities

  • Design and build shared authentication and authorization platform services, APIs, integrations, and automation.
  • Unify authorization across cloud-native, legacy hosting, and lifecycle cloud environments for distributed multi-tenant systems.
  • Write and review infrastructure, automation, tooling, and Go-based service code.
  • Automate provisioning, configuration, deployment, upgrades, recovery, and self-service workflows through version-controlled repeatable pipelines.
  • Deploy, operate, and support containerized application services on Kubernetes.
  • Own platform capabilities in production, including observability, performance testing, safe rollouts, rollback, backup, recovery, and production troubleshooting.
  • Establish reusable patterns and technical standards that product engineering teams can adopt confidently.
  • Implement and maintain authentication flows, permission models, tenant isolation, federation, SSO, and identity-provider integrations.
  • Provide technical leadership through design decisions, code reviews, engineering standards, and support for other engineers.

Requirements

  • Substantial hands-on experience building and operating platforms or shared infrastructure for software engineering teams.
  • Strong coding and scripting skills applied to infrastructure, automation, deployment tooling, or integrations, with experience maintaining code, reviewing changes, and using automated tests.
  • Experience automating provisioning, configuration, deployment, and operational tasks through version-controlled repeatable workflows.
  • Production experience with Kubernetes and containers in an environment delivering and operating software applications.
  • Practical experience with a major public cloud platform, Infrastructure as Code, CI/CD, and GitOps.
  • Experience building reusable platform capabilities or self-service workflows that reduce manual engineering work.
  • Sound understanding of APIs, networking, data stores, and distributed-system behavior, including production troubleshooting.
  • Practical experience implementing authentication and access control in applications, APIs, or shared platform services.
  • Working knowledge of OAuth 2.0, OpenID Connect, token-based authentication, secure validation, permission models, least privilege, and tenant isolation.
  • Ability to translate security requirements into working software, automated tests, and maintainable platform capabilities.
  • Experience with role-based, attribute-based, or relationship-based authorization and understanding of correctness, latency, consistency, and traceability of access decisions.
  • Evidence of technical leadership through design decisions, code reviews, engineering standards, and support for other engineers.
  • Experience with Curity, Keycloak, SpiceDB, enterprise federation, SAML, policy-as-code, distributed multi-tenant identity systems, self-service identity capabilities, APIs, or SDKs is advantageous.
  • Production experience with Go, PostgreSQL, Kafka, or RedPanda is advantageous.
  • Application or backend service development experience is beneficial but not required; willingness to work with Go-based tooling and services is expected.

Benefits

  • Flexible and hybrid work opportunities are available, with flexibility to work in a way that suits individual needs while engaging with colleagues.
  • Opportunity to shape critical platform capabilities with substantial technical ownership and impact across the engineering organization.
  • Opportunity to work in a global, diverse environment on cloud-native enterprise software and production AI initiatives.
IFS

About IFS

5,001-10,000 employees

IFS builds IFS Cloud, an enterprise suite covering ERP, EAM, FSM, SCM, and project/service management for manufacturers and asset‑intensive organizations. Its business model centers on software subscriptions and services for cloud and hybrid deployments, plus industry-specific modules and consulting. Founded in 1983 and headquartered in Linköping, Sweden, the company is privately held under EQT ownership and operates globally across industrial and service-focused markets.

Contact me