19 hours ago
Staines-upon-Thames, United KingdomStaff+
Responsibilities
- Architect and build a unified fine-grained authorization platform across cloud-native, legacy hosting, and lifecycle cloud environments.
- Design authorization schemas and permission models using ReBAC, RBAC, ABAC, and policy-as-code approaches.
- Operate a Zanzibar-style authorization engine backed by PostgreSQL with observability and traceability of decisions.
- Architect, customize, upgrade, and operate enterprise authentication infrastructure using Curity and Keycloak.
- Implement and operate OAuth 2.0, OIDC, SAML 2.0, token-based authentication, enterprise federation, SSO, and directory integration.
- Build and maintain identity infrastructure on Kubernetes, including cutovers, backup and restore, disaster recovery, scaling, and performance tuning.
- Write production code in Go and contribute to distributed, event-driven identity systems.
- Own identity infrastructure in production, participate in on-call operations, and establish identity patterns for engineering teams.
- Use AI tooling thoughtfully and explain what work is delegated, retained, and protected against failure.
Requirements
- Production experience architecting and operating fine-grained authorization systems in distributed, multi-tenant environments.
- Hands-on production experience with SpiceDB, OpenFGA, Ory Keto, or an equivalent Zanzibar-style authorization engine.
- Experience designing authorization schemas and permission models and reasoning about correctness, latency, and consistency.
- Practical knowledge of ReBAC, RBAC, ABAC, OPA/Rego, Cedar, and related policy-as-code approaches.
- Production experience operating authorization infrastructure backed by PostgreSQL with decision observability and traceability.
- Enterprise-scale authentication architecture and operations experience, including hands-on Curity and/or Keycloak configuration, customization, extensions, upgrades, and operations.
- Deep practical knowledge of OAuth 2.0, OIDC, SAML 2.0, JWTs, opaque tokens, token introspection, federation, SSO, LDAP, and Active Directory.
- Strong engineering capability with Go, PostgreSQL, Apache Kafka and/or Redpanda, Kubernetes on AKS, containers, GitOps, and infrastructure as code, or the ability to learn the stack quickly.
- Experience with Kubernetes identity infrastructure, Helm, persistent volumes, blue/green cutovers, backup and restore, disaster recovery, JVM tuning, pod sizing, and dedicated node pools.
- Experience operating an identity provider under load and responding to production authentication failures.
- Knowledge of event-driven and distributed systems architecture and secure coding or security-by-design principles.
- The role requires a hands-on principal engineer who continues to write code and build systems, rather than performing IAM administration, governance, or documentation-only architecture.
Benefits
- Flexible and hybrid work opportunities are available.
- The role offers the opportunity to work in an inclusive, international, diverse environment with colleagues across the globe.
- Employees can contribute to enterprise software focused on innovation, sustainability, and worldwide impact.
Tech Stack
About IFS
IFS builds IFS Cloud, an enterprise suite covering ERP, EAM, FSM, SCM, and project/service management for manufacturers and asset‑intensive organizations. Its business model centers on software subscriptions and services for cloud and hybrid deployments, plus industry-specific modules and consulting. Founded in 1983 and headquartered in Linköping, Sweden, the company is privately held under EQT ownership and operates globally across industrial and service-focused markets.
