2 days ago
Paris, FranceStaff+
Responsibilities
- Design and build shared authentication and authorization platform services across three hosting environments.
- Develop and operate APIs, integrations, infrastructure code, automation, deployment tooling, and Go-based services.
- Automate provisioning, configuration, deployment, upgrades, rollback, backup, recovery, and operational workflows through version-controlled pipelines.
- Create documented self-service identity capabilities that reduce manual intervention for product engineering teams.
- Operate containerized application services on Kubernetes in production.
- Implement and maintain authentication flows, permission checks, access-control models, tenant isolation, and identity-provider integrations.
- Own platform capabilities in production, including observability, performance testing, safe rollouts, failure diagnosis, and prevention of recurring incidents.
- Provide technical leadership through design decisions, code reviews, engineering standards, and architectural guidance.
Requirements
- Substantial hands-on experience building and operating platforms or shared infrastructure for software engineering teams.
- Strong coding and scripting skills applied to infrastructure, automation, deployment tooling, or integrations, with experience maintaining code and automated tests.
- Experience automating provisioning, configuration, deployment, and operational tasks through repeatable version-controlled workflows.
- Production experience with Kubernetes and containers in software delivery environments.
- Practical experience with a major public cloud platform, Infrastructure as Code, CI/CD, and GitOps.
- Experience building reusable platform capabilities or self-service workflows for engineering teams.
- Sound understanding of APIs, networking, data stores, and distributed systems, with production troubleshooting experience.
- Practical experience implementing authentication and access control in applications, APIs, or shared platform services.
- Working knowledge of OAuth 2.0, OpenID Connect, token-based authentication, secure validation, permission models, least privilege, and tenant isolation.
- Ability to translate security requirements into working software, automated tests, and maintainable platform capabilities.
- Evidence of technical leadership through design decisions, code reviews, engineering standards, and support for other engineers.
- Experience with Curity, Keycloak, SpiceDB, enterprise federation, SAML, policy-as-code, or distributed multi-tenant identity systems is advantageous.
- Experience with Go, PostgreSQL, and Kafka or RedPanda is advantageous.
- Application or backend service development experience is beneficial but not required.
- Candidates should have demonstrable hands-on experience designing, building, and shipping production AI applications; AI-tool usage alone is insufficient.
Benefits
- Flexible and hybrid work opportunities are available to support diverse needs and lifestyles.
- The role provides substantial technical ownership and impact across the engineering organization.
- The position offers the opportunity to work on production AI systems, cloud-native technologies, and enterprise software at global scale.
Tech Stack
About IFS
IFS builds IFS Cloud, an enterprise suite covering ERP, EAM, FSM, SCM, and project/service management for manufacturers and asset‑intensive organizations. Its business model centers on software subscriptions and services for cloud and hybrid deployments, plus industry-specific modules and consulting. Founded in 1983 and headquartered in Linköping, Sweden, the company is privately held under EQT ownership and operates globally across industrial and service-focused markets.
