Senior Principal Engineer

Ditto

España

Híbrido

EUR 120.000 - 180.000

Jornada completa

Hace 7 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Ditto is building an agentic identity platform and seeks a Senior Principal Engineer to own design and hands-on build of the platform’s hardest capabilities—verifiable agent identity, instance integrity, and continuous runtime trust—on a modern, standards-based foundation.

You’ll set the technical direction, mentor a scaling team, integrate with enterprise identity providers, and engage with standards communities to keep work current and interoperable across Europe.

Formación

  • 10+ years building distributed systems, platform, or security infra at principal level.
  • Deep identity and authorization expertise with OAuth 2.1 / OIDC and related flows.
  • Hands-on with cryptography, key lifecycle, and attestation concepts.
  • Ability to mentor and grow a high-performing team across Europe.
  • Fluent English, strong communication in technical and cross-team contexts.

Responsabilidades

  • Own the platform's technical direction and architecture in uncertain environments.
  • Integrate with enterprise identity providers and standards-based adapters.
  • Grow and mentor the team responsible for scaling the platform.
  • Engage standards and security communities to ensure interoperability.

Conocimientos

Identity & authorization
OAuth 2.1 / OIDC
LLMs for research
Mentoring
English fluency

Educación

Bachelor's or Master's in CS/related field

Herramientas

SPIFFE / SVID
PKI / mTLS
RASP / TEEs

Descripción del empleo

About Ditto

At Ditto, we're redefining digital trust. Our unified identity platform helps banks, financial institutions, governments and other regulated organisations verify identities, prevent fraud and deliver secure digital experiences through identity verification, authentication, passwordless access and mobile threat defence.

About Ditto

At Ditto, we're redefining digital trust. Our unified identity platform helps banks, financial institutions, governments and other regulated organisations verify identities, prevent fraud and deliver secure digital experiences through identity verification, authentication, passwordless access and mobile threat defence.

We're a global team with a startup mindset, led by CEO Gonzalo Alonso, on a mission to make digital trust simple, secure and accessible.

The Role

AI agents are beginning to act on behalf of people and businesses—making decisions, transacting, and connecting to other systems on their own. The identity tools most organisations rely on today were built for people or predictable machine identities, not autonomous agents.

Ditto is investing in an agentic identity platform to address this. We're hiring a Senior Principal Engineer to help design and build it—hands-on—drawing on Ditto's heritage in identity, device binding, runtime protection and continuous authentication, and using large language models as a genuine force-multiplier for the research and the delivery.

In one line: own the design and hands-on build of the platform's hardest capabilities—verifiable agent identity, instance integrity, and continuous runtime trust—on a modern, standards-based foundation, moving at real pace.

Where You'll Make an Impact
In This Role, You'll
  • Help set the technical direction and architecture for the platform, and make sound build/buy calls under uncertainty.
  • Integrate with existing enterprise identity providers and open standards rather than reinventing them, keeping external systems behind adapters so implementations can evolve as standards mature.
  • Grow and mentor the team that scales the platform—a genuine principal-level remit.
  • Engage the broader standards and security community to keep the work current, credible and interoperable.
What You'll Work With

A fast-moving standards landscape, spanning agent & workload identity, authentication, delegation, attestation, continuous trust, agent interop, provenance and EU regulation. You won't start from a blank page—several capabilities extend foundations Ditto has shipped for years in identity, device binding, runtime protection and continuous authentication.

  • Agent & workload identity: SPIFFE / SVID, workload identity, DID / VC, W3C agent identity work
  • AuthN & credentials: OAuth 2.1, OIDC, PKI, FIDO2 / WebAuthn, mTLS, sender-constrained tokens (DPoP)
  • Delegation & authorization: Token exchange (RFC 8693), on-behalf-of, CIBA, policy-based authorization
  • Attestation & integrity: Hardware attestation, TEEs (SEV-SNP, TDX, Nitro, Secure Enclave), RASP
  • Continuous trust: Shared Signals / CAEP, continuous & risk-based authentication
  • Agent interop: MCP, agent-to-agent protocols and the identity work around them
  • Provenance: Tamper-evident logs, software supply-chain attestation (SLSA / Sigstore)
  • Regulatory (EU): EU AI Act, eIDAS 2.0 / EUDI wallet, GDPR, DORA

You don't need every item on day one—but you should be fluent in identity and authorization fundamentals and able to reason from primary-source specs.

LLMs are core to how this role works, not a novelty: synthesizing fast-moving specs and vendor landscapes into build/buy decisions, driving threat models (OWASP NHI, Agentic Top 10) mapped to the property that defeats each attack, and accelerating delivery from spec to a working, demonstrable slice—always verified against primary sources, especially for crypto and security-critical logic.

Who You Are

You're someone who:

  • Builds evidence-first—shipping small, demonstrable increments and letting each one earn the next, rather than making big up-front bets.
  • Reasons clearly from primary-source specs in a fast-moving, still-forming standards landscape.
  • Uses LLMs deliberately and rigorously, and knows exactly where their output must be verified against primary sources.
  • Is comfortable owning ambiguity at principal level—architecting and shipping, and mentoring a team along the way.
Must-have
What We're Looking For
  • 10+ years building production distributed systems, platform, or security infrastructure, with principal-level technical ownership—architecting and shipping, not only advising.
  • Deep identity & authorization expertise: OAuth 2.1 / OIDC, token exchange and on-behalf-of flows, sender-constrained tokens, PKI, FIDO2 / WebAuthn, mTLS, and workload identity.
  • Applied cryptography in practice: credential formats, binding proofs, key lifecycle and rotation, and clear reasoning about what a construction does and does not prove.
  • Hands-on depth in at least one differentiating area: hardware attestation / TEEs, RASP, or continuous / risk-based authentication and shared signals.
  • Demonstrated fluency leveraging LLMs for rigorous technical research and for building, with the judgement to verify output against primary sources.
  • Fluent English, spoken and written; based in Europe (EU / EEA) and able to work across European time zones with a mostly-overlapping team.
Bonus Points
It Would Be Great If You Also Have
  • Fluent or native Spanish, spoken and written—valuable across our Spanish-speaking European and LATAM customers and partners.
  • Experience with agent ecosystems and protocols (MCP, agent-to-agent) and the identity work around them.
  • Decentralised identity (DID / VC) and eIDAS 2.0 / EUDI wallet models.
  • EU regulatory fluency—EU AI Act, DORA, GDPR—and experience building audit and traceability in from day one.
  • Participation in standards bodies (e.g. IETF, OWASP) or relevant open-source contribution.
Why Join Ditto

A rare mandate to help define and build a category-shaping platform on an open, still-forming standards landscape—with principal-level ownership of architecture and technical direction, and a path to build and lead the team. You'll build on foundations Ditto has shipped for years in identity, device binding, runtime protection and continuous authentication, rather than starting from scratch.

We value ownership, curiosity and collaboration, giving our people the freedom to make decisions, challenge ideas and grow their careers while helping build the future of digital trust.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Engineer — Mobile RASP
Security Engineer — Mobile RASP

Ditto • España

Presencial
EUR 70.000 - 110.000
Senior Principal Engineer, Identity Platform & AI Security
Senior Principal Engineer, Identity Platform & AI Security

Ditto • España

Híbrido
EUR 120.000 - 180.000
Senior Security Engineer – Identity & Access
Senior Security Engineer – Identity & Access

Dlocal • Madrid

Presencial
EUR 90.000 - 130.000
Flexible schedules
Fintech industry environment
Referral bonus program
+2
Product Manager (Non-Human Identity)
Product Manager (Non-Human Identity)

Omada • Alicante

Híbrido
EUR 60.000 - 90.000
Hybrid work Alicante
Customer exposure
Autonomy & leadership
+2
HR Lead
HR Lead

Didit (YC W26) • Barcelona

Presencial
EUR 70.000 - 110.000
In-office in Barcelona
YC-backed startup growth
Autonomy with sourcing & events budget
+1
Principal Security Engineer – Identity & Access
Principal Security Engineer – Identity & Access

Dlocal • Bellprat

Presencial
EUR 110.000 - 150.000
Flexible schedules
Fintech environment
Referral bonus
+2
Principal Security Engineer – Identity & Access
Principal Security Engineer – Identity & Access

dLocal • Madrid

Híbrido
EUR 120.000 - 180.000
Flexible schedules
Referral bonus program
Social budget
+1
Customer Success & Support
Customer Success & Support

Didit (YC W26) • Barcelona

Presencial
EUR 30.000 - 50.000
Competitive salary
High-impact role
Opportunity for growth
Software Engineer
Software Engineer

Taizen • Barcelona

Presencial
EUR 70.000 - 90.000
In-person in Barcelona (4 days/week)
Fullstack Developer (Non-Human Idenity)
Fullstack Developer (Non-Human Idenity)

Omada • Alicante

Presencial
EUR 45.000 - 65.000
Mentorship from experienced engineers.
Structured technical growth.
Modern cloud-native technology stack.
+2