Staff Software Engineer, SecureAI

United States Digital Space LLC

Toronto

On-site

CAD 160,000 - 220,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Equity in compensation
Bonus programs
RRSP with a match
Paid leave (PTO & parental)

Job summary

United States Digital Space LLC is seeking a Staff Software Engineer for its Secures AI team to build the industry's first Identity Security Fabric for the agentic era. You will design and maintain backend services, enforce least privilege for agents, and advance AI-native development with secure, scalable systems.

The role emphasizes collaboration with product, design, and leadership, ensuring secure access and auditable decisions across distributed systems in a rapidly evolving AI landscape.

Qualifications

  • Proven experience building scalable backend systems.
  • Experience integrating complex APIs with modern web technologies.
  • Strong knowledge of web authentication and authorization.

Responsibilities

  • Proactively shape the technical strategy of the Identity Security Fabric, partnering with leadership to prioritize work streams for securing AI Agents.
  • Build the Runtime Policy Decision Point (PDP) and implement request-time authorization at the Agent Gateway and resource connections.
  • Design and support from a policy engine like Cedar, schema validation, and policy evaluation.
  • Develop logic to validate delegated agent identities and forward the acting user's identity securely downstream.
  • Track MCP, OAuth token exchange, and agent identity specs; feed lessons back into specs and implementations.
  • Develop comprehensive audit logging to record outcomes and reason behind decisions.
  • Drive evolution in AI-native development practices and CI/CD, observability, and reliability.
  • Collaborate with Product/Design to align outcomes with customer needs; mentor peers to raise technical standards.

Skills

Backend architecture
Java
Web authentication
APIs integration
Distributed systems
AI-native development
Leadership

Education

Bachelor's or Master's in CS

Tools

Cedar policy engine
OAuth/OIDC/SAML

Job description

**Secure Every Identity, from AI to Human

**Identity is the key to unlocking the potential of AI. the company secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

About the company Secures AI Team

The the company for AI Agents Team is building the future of digital identity management. The way companies are using agents and allowing them access is undergoing a fundamental shift, enabling teams to move fast while staying secure.

Our North Star is clear: To get AI right, you have to get identity right. We are not just managing identities; we are building the industry's first Identity Security Fabric for the agentic era. As organizations rapidly deploy AI, these non-human entities are acting with access to critical tools, often bypassing traditional perimeters and creating a 'Shadow AI' crisis. Our mission is to move identity from a reactive gatekeeper to a unified control plane, transforming AI risk into business ROI.

We are tackling this by implementing a comprehensive four-pillar maturity model: Discover, Onboard, Protect, and Govern. We are driving innovation by defining the standards for Agentic Identity—including pioneer work with securing AI Agents and support for protocols like MCP. You will be helping us build the infrastructure that allows enterprises to scale AI safely, ensuring every access decision—whether made by a human or an automated agent is authenticated, authorized, and audited at scale.

We are a diverse team of engineers, product managers, and designers who are bringing the company’s expertise in identity to define the future of Agent Identity management, focusing on enablement while staying secure.

About the role

As a Staff Software Engineer on the the company Secures AI team, your mission is to build the industry's first Identity Security Fabric for the agentic era. You will be working on the designs and driving of our unified control plane features, ensuring that we operationalize our North Star: "To get AI right, you have to get identity right."

As a staff engineer, you will actively design, build, and maintain robust backend services. This role requires deep expertise in distributed systems and a commitment to AI-native engineering as our standard. You will rethink backend design, validation, and delivery through AI-augmented workflows, ensuring our platform provides secure, interoperable, and scalable access—enforcing the principle of least privilege for every agent action.

What you’ll be doing
  • Proactively shape the technical strategy of the Identity Security Fabric, partnering with leadership to prioritize the work streams for securing AI Agents.
  • Build the Runtime Policy Decision Point (PDP). Implement the request-time authorization engine at the Agent Gateway and at the agent to resource connection level to intercept and evaluate every agent request against per-agent, per-tool, and per-resource rules.
  • Design and support authoring from a policy engine like Cedar, schema validation, and evaluation—connecting the admin console's no-code UI builder output with direct API-published policies.
  • Develop the logic to validate which users a delegated agent is permitted to represent and securely forward the acting user's identity to downstream resources.
  • Track and shape MCP, OAuth token exchange, and agent identity specifications. Feed lessons learned from production back into the specs and their reference implementations.
  • Develop Comprehensive Audit Logging. Build secure logging mechanisms to record the outcome of every request (allow or deny) along with the specific rule or reason behind the decision.
  • Drive continual evolution in the adoption of AI-native development practices, helping the team rethink how we design, review, and ship software with AI as a core part of the workflow.
  • Proactively identify and prioritize tech debt; drive improvements in areas beyond feature work - CI/CD, observability, documentation, reliability, and support processes.
  • Partner with Product and Design to understand and own the desired customer outcome, not just the technical deliverable.
  • Actively invest in the growth of peer engineers, taking responsibility for raising the technical bar of the team as a whole.
What you’ll bring to the role
  • Operates well beyond basic AI tool usage - understands how to apply AI meaningfully across the full software development lifecycle, can evaluate and adopt new AI tooling with good judgment, and is able to establish practices and bring a team along.
  • Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies - including the ability to make and defend architectural decisions with lasting org-wide impact.
  • Solid understanding of web authentication and authorization fundamentals - how auth flows work, and best practices for securing sensitive user data.
  • Architectural expertise: Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies, including making decisions with lasting, org-wide impact.
  • Backend proficiency: Deep expertise in building reliable, secure, enterprise-grade software in Java or another type-safe language.
  • Prior experience leading a team of engineers through a meaningful shift in ways of working - whether around AI adoption, developer tooling, or engineering culture change is a strong plus.
Extra credit
  • Experience with identity, authorization, or IAM protocols (e.g., OAuth, OIDC, SAML)
  • Work with agent frameworks, AI-facing APIs, or developer toolchains in the LLM space
Education and Experience:

Bachelor’s or Master's degree in Computer Science or related field

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, the company offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit:https://rewards.the company.com/can.

The annual base salary range for this position for candidates located in Canada is between:

$160,000—$220,000 CAD

The the company Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Foster
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Frontend Engineer, SecureAI
Staff Frontend Engineer, SecureAI

United States Digital Space LLC • Toronto

On-site
CAD 160,000 - 220,000
Equity
Bonus
Health insurance
+6
Staff Software Engineer, SecureAI
Staff Software Engineer, SecureAI

AI Chopping Block, Inc. • Toronto

On-site
CAD 160,000 - 220,000
Equity (where applicable)
Bonus
Health/dental/vision insurance
+3
Staff Product Engineer, Agentic Identity & Governance, AI Platform
Staff Product Engineer, Agentic Identity & Governance, AI Platform

Lever, Inc. • Canada

Remote
CAD 312,000 - 369,000
Fully remote in Canada
High-autonomy Staff-level role
Mentorship and professional growth
+1
Director of Engineering, AI Takeoff Team
Director of Engineering, AI Takeoff Team

United States Digital Space LLC • Bellevue

On-site
CAD 224,000 - 308,000
Staff Fullstack Engineer, SecureAI
Staff Fullstack Engineer, SecureAI

Okta • Toronto

On-site
CAD 160,000 - 220,000
Equity (where applicable)
Bonus
Health, dental, and vision insurance
+3
Staff FullStack Engineer, Okta Secures AI
Staff FullStack Engineer, Okta Secures AI

Okta • Southwestern Ontario

On-site
CAD 160,000 - 220,000
Equity
Bonus
Health, dental, and vision insurance
+4
Staff Frontend Engineer, SecureAI
Staff Frontend Engineer, SecureAI

Okta • Toronto

On-site
CAD 160,000 - 220,000
Health insurance
Dental insurance
Vision insurance
+6
Staff Product Marketing Manager, Security
Staff Product Marketing Manager, Security

United States Digital Space LLC • Bellevue

Hybrid
CAD 128,000 - 176,000
Equity (where applicable)
Health, dental & vision insurance
PTO & parental leave
+1
Staff Software Engineer – AI & Platform
Staff Software Engineer – AI & Platform

Alygra • Quebec

On-site
CAD 120,000 - 180,000
Staff Software Engineer - AI Platform
Staff Software Engineer - AI Platform

CaptivateIQ • Toronto

On-site
CAD 181,289 - 242,106
Comprehensive Healthcare
Flexible Time Off
Annual Stipends
+3