3 months ago
Responsibilities
- Drive the architecture and delivery of a new permission service from design through production.
- Define authentication and authorization standards, including authentication flows, token issuance, scoped authorization, and role- or attribute-based access control.
- Design the permission service API contract, policy definitions, access-decision requests, and enforcement model.
- Develop the token strategy covering JWT issuance, rotation, scoping, revocation, and human or machine callers.
- Partner with product and platform teams to create reusable permission primitives across more than 180 product domains.
- Lead architectural reviews for features with authentication or authorization implications.
- Collaborate with Security and Compliance on auditability, least privilege, and zero-trust requirements.
- Mentor engineers, lead RFCs, and ensure implementation quality aligns with architectural intent.
Requirements
- 10+ years of software engineering experience, including at least 3 years operating at Staff or Principal level.
- Deep expertise in identity and access management, including OAuth 2.0, OIDC, SAML, RBAC, ABAC, ReBAC, JWTs, opaque tokens, and token lifecycle management.
- Demonstrated experience designing and building AuthN/AuthZ systems at scale.
- Strong knowledge of policy-as-code, permission modeling, and evolvable access-control data models.
- Experience designing or reviewing OpenAPI specifications, event-driven architectures, and cross-service communication patterns.
- Strong backend engineering fundamentals and comfort working in a PHP monolith.
- Ability to drive organization-wide architectural decisions through RFCs, reviews, and consensus building.
- Excellent written and verbal communication skills.
- Preferred experience building a permission service or authorization framework from scratch, including Zanzibar-style, OPA-based, or custom policy engines.
- Familiarity with Okta, Auth0, or similar identity platforms.
- Experience with fine-grained authorization, multi-tenant SaaS, API token systems, secrets management, certificate rotation, secure credential storage, and zero-trust architecture.
Benefits
- Remote position available in the listed state
- Comprehensive health, life, and disability insurance
- Four weeks of vacation, 12 company holidays, parental leave, and volunteer time off
- 401(k) plan with up to 6% company match
- $2,000 paid vacation bonus
- Employee assistance program through Headspace
About BambooHR
BambooHR provides cloud-based HR software for small and mid-sized businesses, including a core HRIS with applicant tracking, time tracking, payroll integrations, and employee self-service. Delivered as a SaaS subscription, it centralizes people data and supports workflows from hiring to performance. Founded in 2008 and headquartered in Draper, Utah, the privately held company reports serving over 34,000 customers worldwide and lists clients such as Quora and MasterClass.