2 days ago
Kraków, PolandStaff+
Responsibilities
- Build and operate shared authentication and authorization platform services, APIs, integrations, and automation.
- Unify authorization across cloud-native, legacy hosting, and lifecycle cloud environments.
- Develop infrastructure, provisioning, configuration, deployment, upgrade, recovery, and self-service workflows through version-controlled repeatable pipelines.
- Deploy and operate containerized application services on Kubernetes in a software delivery environment.
- Implement authentication flows, permission checks, access-control models, tenant isolation, and secure validation.
- Own platform capabilities in production, including observability, performance testing, safe rollouts, rollback, backup, recovery, and incident prevention.
- Provide technical leadership through architecture decisions, code reviews, engineering standards, and support for other engineers.
- Contribute to Go-based tooling and services and remain hands-on with code, testing, and automation.
Requirements
- Substantial hands-on experience building and operating platforms or shared infrastructure for software engineering teams.
- Strong coding and scripting skills applied to infrastructure, automation, deployment tooling, or integrations.
- Experience automating provisioning, configuration, deployment, and operational tasks through version-controlled workflows.
- Production experience with Kubernetes and containers for software applications.
- Practical experience with a major public cloud platform, Infrastructure as Code, CI/CD, and GitOps.
- Experience creating reusable platform capabilities or self-service workflows that reduce manual intervention.
- Understanding of APIs, networking, data stores, distributed-system behavior, and production troubleshooting.
- Practical experience implementing authentication and access control in applications, APIs, or shared platform services.
- Working knowledge of OAuth 2.0, OpenID Connect, token-based authentication, permission models, least privilege, and tenant isolation.
- Ability to translate security requirements into working software, automated tests, and maintainable platform capabilities.
- Experience with Curity, Keycloak, SpiceDB or comparable authorization engines, enterprise federation, SAML, policy-as-code, or distributed multi-tenant identity systems is preferred.
- Experience with Go, PostgreSQL, and Kafka or RedPanda is preferred.
- Demonstrated technical leadership through design decisions, code reviews, engineering standards, and support for other engineers.
- Production experience designing, building, and shipping AI applications is requested by the posting.
Benefits
- Flexible and hybrid work opportunities are available.
- The role offers broad technical ownership and impact across the engineering organization.
- Employees work in a global, diverse environment with a stated commitment to sustainability, collaboration, and inclusion.
Tech Stack
About IFS
IFS builds IFS Cloud, an enterprise suite covering ERP, EAM, FSM, SCM, and project/service management for manufacturers and asset‑intensive organizations. Its business model centers on software subscriptions and services for cloud and hybrid deployments, plus industry-specific modules and consulting. Founded in 1983 and headquartered in Linköping, Sweden, the company is privately held under EQT ownership and operates globally across industrial and service-focused markets.
