
Senior Software Engineer, Identity & Access Discovery
Keeper Security2 months ago
Remote, United StatesSenior
Responsibilities
- Design and develop the Python discovery engine running on customer-deployed gateways and Java/Kotlin cloud services that store and serve discovered data.
- Build systems that discover privileged accounts, service accounts, keys, machines, and related identity data across Active Directory, cloud IAM, databases, and endpoints.
- Solve identity correlation and reconciliation problems across multiple systems.
- Develop incremental rescanning and state-reconciliation capabilities that prevent duplicate or stale data.
- Build unit, integration, and automated test coverage plus diagnostic tooling, logging, and error reporting for field troubleshooting.
- Design safe, resilient discovery workflows for customer production networks that respect API limits and limit blast radius.
- Develop secure data-processing workflows that protect discovered data during collection, transmission, and storage within the zero-knowledge architecture.
- Collaborate with Product, QA, and other PAM engineers on design, testing, troubleshooting, and delivery.
- Use AI-assisted tools such as Claude, ChatGPT, GitHub Copilot, or similar platforms for development, debugging, research, and documentation.
Requirements
- 8+ years of professional software development experience focused on backend systems.
- Strong Python experience, with Python serving as the primary language for the Discovery engine.
- Working proficiency in Java or Kotlin and enough TypeScript/React experience to modify the administrative interface.
- Strong experience with distributed systems, APIs, and data-processing pipelines that operate reliably in environments the company does not control.
- Hands-on experience with Active Directory and/or LDAP.
- Working knowledge of at least one major cloud IAM model, including AWS IAM and Organizations, Microsoft Entra ID, or GCP IAM.
- Strong knowledge of secure software development, authentication, authorization, and encryption.
- Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Strong data-modeling skills, ideally including graph or relationship-oriented models.
- U.S. Person status, defined as a U.S. citizen or lawful permanent resident, due to involvement in GovCloud and FedRAMP environments.
- Experience with Privileged Access Management, identity security, cybersecurity products, identity discovery, account discovery, asset inventory, or similar infrastructure discovery systems is preferred.
- Experience with containerized or cloud-native applications and high-scale enterprise SaaS products is preferred.
Benefits
- 100% remote position, with a hybrid schedule available for candidates in the Chicago, Illinois or El Dorado Hills, California metro areas.
- Medical, dental, and vision insurance, including domestic partnerships.
- Employer-paid life insurance and supplemental life insurance for employees, spouses, and children.
- Voluntary short- and long-term disability insurance.
- Roth or traditional 401(k).
- Generous paid time off, including paid bereavement and jury duty.
- Above-market annual bonuses.
About Keeper Security
Keeper Security builds a cloud-based, zero-knowledge platform for password management, secrets management, privileged access management and secure remote connections for individuals and organizations. The privately held company, founded in 2011 and headquartered in Chicago, sells its KeeperPAM suite as subscription software, is published in 23 languages and sold in over 150 countries, and supports integrations with common identity providers and enterprise tech stacks.