15 hours ago
Staines-upon-Thames, United KingdomStaff+
Responsibilities
- Architect and build fine-grained, multi-tenant authorization systems across cloud-native, legacy hosting, and lifecycle cloud environments.
- Design authorization schemas and permission models using ReBAC, RBAC, ABAC, and policy-as-code approaches.
- Build, operate, and troubleshoot enterprise authentication infrastructure using Curity and Keycloak.
- Implement and support OAuth 2.0, OIDC, SAML 2.0, token-based authentication, federation, SSO, and directory integrations.
- Run identity infrastructure on Kubernetes/AKS, including deployments, cutovers, backup, restore, and disaster recovery.
- Write production Go code and develop distributed, event-driven backend systems with PostgreSQL and Kafka or Redpanda.
- Own identity infrastructure in production, including observability, traceability, performance tuning, upgrades, and on-call response.
Requirements
- Production experience building and operating fine-grained authorization systems in distributed, multi-tenant environments.
- Hands-on experience with Zanzibar-style authorization engines such as SpiceDB, OpenFGA, Ory Keto, or equivalent.
- Practical expertise with ReBAC, RBAC, ABAC, authorization schemas, permission models, correctness, latency, consistency, and policy-as-code tools such as OPA/Rego or Cedar.
- Production experience architecting and operating enterprise authentication systems, including hands-on Curity and/or Keycloak configuration, customization, extensions, upgrades, and operations.
- Strong knowledge of OAuth 2.0, OIDC, SAML 2.0, JWTs, opaque tokens, token introspection, identity federation, SSO, LDAP, and Active Directory.
- Experience operating identity providers under load, including configuration import latency, JVM tuning, pod sizing, dedicated node pools, and production failure investigation.
- Strong Go backend engineering capability, or the ability to develop it quickly, plus experience with PostgreSQL, Apache Kafka or Redpanda, Kubernetes/AKS, containers, GitOps, and infrastructure as code.
- Understanding of event-driven and distributed systems architecture, secure coding, and security-by-design principles.
- Willingness to remain hands-on, write code, make technical decisions, and challenge senior stakeholders when appropriate.
Benefits
- Flexible and hybrid work opportunities are available, with an emphasis on inclusive workplace experiences and collaboration.
- The role offers the opportunity to work in a global, diverse environment on enterprise software with worldwide impact.
- The company highlights sustainability, innovation, collaboration, trust, and opportunities to contribute to meaningful business and societal outcomes.
Tech Stack
About IFS
IFS builds IFS Cloud, an enterprise suite covering ERP, EAM, FSM, SCM, and project/service management for manufacturers and asset‑intensive organizations. Its business model centers on software subscriptions and services for cloud and hybrid deployments, plus industry-specific modules and consulting. Founded in 1983 and headquartered in Linköping, Sweden, the company is privately held under EQT ownership and operates globally across industrial and service-focused markets.
