18 days ago
Washington, DC, USA or San Francisco, CA, USAStaff+
Base Salary
$150k - $275k/yr
Responsibilities
- Design and implement token management systems with refresh token rotation, proof-of-possession tokens, introspection, and real-time revocation.
- Lead development of an extensible claims engine supporting dynamic attributes, contextual claims, and business logic at token issuance.
- Architect global identity infrastructure with edge optimization, token caching, cross-region replication, and low-latency authentication.
- Build rate limiting, anomaly detection, fraud prevention, identity federation, protocol adapters, and enterprise client management capabilities.
- Lead developer experience initiatives involving SDKs, webhooks, audit logging, analytics dashboards, plugin architecture, and extensible APIs.
- Drive compliance, data residency, privacy, observability, and security event correlation initiatives for Kong Identity.
- Mentor engineering teams on zero-trust architecture, workload identity, service mesh integration, and advanced identity concepts.
Requirements
- 7+ years of experience building production identity platforms at identity providers or enterprise software companies, including systems handling millions of authentication requests daily.
- Deep expertise in OAuth 2.0 extensions including PKCE, mTLS, JWT bearer assertions, and token exchange, as well as OpenID Connect, OAuth 2.1, and GNAP.
- Experience architecting multi-tenant identity platforms with tenant isolation, tenant-specific configuration, enterprise features, delegated administration, and fine-grained permissions.
- Strong knowledge of cryptographic protocols, JWT patterns, key rotation, HSM integration, and post-quantum cryptography considerations.
- Experience with enterprise identity integrations including SAML federation, LDAP/AD bridges, SCIM provisioning, external identity providers, and custom protocol adapters.
- Experience building identity platforms with analytics, monitoring, security event detection, threat modeling, penetration testing coordination, and attack prevention.
- Experience with global infrastructure, edge deployment, geo-distributed token validation, cross-region consistency, horizontal scaling, caching, and latency optimization.
- Experience building developer-focused identity platforms with SDKs, webhooks, extensible APIs, custom grant flows, and protocol extensions.
- Knowledge of compliance requirements, audit trail design, data residency controls, privacy engineering, service mesh identity, workload identity bootstrapping, and container orchestration integration.
- Proven ability to lead technical initiatives and mentor teams in complex, regulated environments.
