Principal Platform Engineer - - Identity Platform (AuthN/AuthZ)

Ifs1

Staines-upon-Thames

Hybrid

GBP 90,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work opportunities

Job summary

Ifs1 is hiring Principal Platform Engineers to design and operate a unified, production-grade authorisation platform across cloud-native and legacy environments. You will architect systems using SpiceDB-style RBAC/ABAC, implement policy-as-code, and own authentication with Curity/Keycloak at scale.

The role demands hands-on Go development, strong knowledge of PostgreSQL, Kubernetes, and observability. You’ll work in a hybrid model with strong opinions and responsibility for reliability and

Qualifications

  • Fine-grained authorisation systems you have built and run at production scale, in distributed multi-tenant environments.
  • Hands-on production experience with SpiceDB or Zanzibar-inspired systems (OpenFGA, Ory Keto, or equivalent).
  • Authorisation schemas and permission models you have designed, with reasoning about correctness, latency and consistency.
  • ReBAC, RBAC, ABAC, and knowing when to apply each
  • Policy-as-code exposure: OPA/Rego, Cedar or similar
  • Operational experience running the authorisation engine in production on PostgreSQL with observability of decisions
  • Enterprise-scale authentication you have architected and operated (Curity and/or Keycloak)
  • OAuth 2.0, OIDC, SAML 2.0, and token patterns; federation, SSO, directory integration
  • Backend: Go; Data: PostgreSQL; Messaging: Kafka/RedPanda; GitOps; IaC
  • Kubernetes (AKS), containers, CI/CD, IaC tooling
  • Security-by-design principles in cloud-native environments

Responsibilities

  • Architect and build a unified authorisation model across multiple hosting environments.
  • Own it in production and set identity patterns for engineering teams.
  • Write Go and implement production-ready solutions.
  • Operate and observe authorisation decisions backed by PostgreSQL.

Skills

Fine-grained auth systems
SpiceDB
ReBAC
RBAC
ABAC
Policy-as-code
OPA/Rego
Cedar
Go
PostgreSQL
Kubernetes
Security by design

Tools

Curity
Keycloak
AKS
GitOps
PostgreSQL

Job description

The job

Authorisation is the single biggest blocker to our next-generation platform right now. Two Principal Platform Engineers are joining to unblock it.

We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud. It is built on SpiceDB (relationship-based access control) on PostgreSQL, and it has to be correct, fast, and multi-tenant at enterprise scale. Alongside it, we run enterprise authentication on Curity, with Keycloak estates migrating onto it.

You will architect and build that, own it in production, and set the identity patterns the rest of engineering follows. This is a hands-on engineering role. You will write Go.

What we need to see
Authorisation
  • Fine-grained authorisation systems you have built and run at production scale, in distributed multi-tenant environments
  • Hands-on production experience with a Zanzibar-style authorisation engine: SpiceDB, OpenFGA, Ory Keto or equivalent
  • Authorisation schemas and permission models you have designed, and the ability to reason about correctness, latency and consistency together
  • ReBAC, RBAC and ABAC, and a view on when each is the right answer
  • Policy-as-code exposure: OPA/Rego, Cedar or similar
  • Running the authorisation engine in production on PostgreSQL, with observability and traceability of the decisions it makes
Authentication
  • Enterprise-scale authentication you have architected and operated, not integrated with
  • Hands-on production Curity and/or Keycloak: configuration, customisation, extensions, upgrades, operations
  • OAuth 2.0, OIDC, SAML 2.0 and token patterns at a level where you can explain why a given flow, what its failure modes are, and where PKCE belongs
  • Enterprise federation, SSO and directory integration, in a bring-your-own-identity model with per-tenant signing keys
Operations and engineering
  • Identity infrastructure on Kubernetes (AKS): Helm, persistent volumes, blue/green cutovers, backup and restore, DR
  • An IdP under load: config import latency, JVM tuning, pod sizing, dedicated node pools, and a story about what fell over and how you found it
  • Go, PostgreSQL, Kafka/RedPanda, GitOps, IaC. Exact match not required, ability to get there fast is
  • You still write code. These are principal engineers who build, not IAM consultants who produce documents
How we work

We expect that AI tooling has changed how you work. We will ask what you delegate, what you still do yourself, and what you built to stop it breaking. Specifics, not a list of tools.

We want strong opinions, held out loud. If you would not push back on your director in week two, this will not suit you.

Authorisation (Must Have)
  • Architecting and engineering fine-grained authorisation systems at production scale , in distributed, multi-tenant environments
  • Hands-on production experience with a relationship-based / policy-based authorisation engine , ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent)
  • Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each
  • Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale
  • Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent)
  • Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions
Authentication (Must Have)
  • Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale
  • Hands-on production experience with Curity and/or Keycloak : configuration, customisation, operations, and integration
  • Deep, practical knowledge of OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and token-based authentication patterns (JWT, opaque tokens, token introspection)
  • Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory)
Strong hands-on engineering capability across the NGA stack, or the ability to get there fast: Backend: Go
  • Messaging / Streaming: Apache Kafka / RedPanda
  • Data: PostgreSQL
Comfortable operating in a cloud-native environment: Kubernetes (AKS), containers, GitOps, Infrastructure as Code
  • Event-driven and distributed systems architecture
  • Secure coding practices and security-by-design principles

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Platform Engineer || Identity Platform (AuthN/AuthZ) Staines-upon-Thames, England, United Kingdom Research and Development
Principal Platform Engineer || Identity Platform (AuthN/AuthZ) Staines-upon-Thames, England, United Kingdom Research and Development

IFS • United Kingdom

Remote
GBP 110,000 - 150,000
Principal Platform Engineer | Identity Platform (AuthN/AuthZ)
Principal Platform Engineer | Identity Platform (AuthN/AuthZ)

IFS • Staines-upon-Thames

Hybrid
GBP 120,000 - 160,000
Hybrid work opportunities
Principal Platform Engineer | Agentic AI | Identity and Access Management
Principal Platform Engineer | Agentic AI | Identity and Access Management

IFS • Staines-upon-Thames

Hybrid
GBP 120,000 - 180,000
Principal Platform Engineer || Agentic AI || Identity and Access Management
Principal Platform Engineer || Agentic AI || Identity and Access Management

IFS • Staines-upon-Thames

On-site
GBP 120,000 - 180,000
Senior Software Engineer, Identity
Senior Software Engineer, Identity

United States Digital Space LLC • Greater London

On-site
GBP 90,000 - 130,000
Senior Software Engineer, Identity London, UK Apply →
Senior Software Engineer, Identity London, UK Apply →

Scale AI, Inc. • Greater London

On-site
GBP 110,000 - 150,000
Senior Platform Engineer
Senior Platform Engineer

United States Digital Space LLC • City of Edinburgh

On-site
GBP 90,000 - 120,000
25 days holiday
Private Medical and Dental Insurance
Enhanced pension contributions
+2
Senior Software Engineer, Identity Software
Senior Software Engineer, Identity Software

Front Door Defense • Greater London

On-site
GBP 110,000 - 165,000
Senior Platform Engineer
Senior Platform Engineer

United States Digital Space LLC • West of England

On-site
GBP 90,000 - 130,000
25 days holiday
Enhanced Parental Leave: 6 months full
Private Medical and Dental Insurance
+6
Senior Platform Engineer
Senior Platform Engineer

United States Digital Space LLC • Manchester

On-site
GBP 85,000 - 110,000
25 days holiday
Enhanced Parental Leave
Cycle to Work
+6