Lead Engineer II – Senior Engineer, Authentication and Authorization IRC302231

GlobalLogic

Bengaluru

On-site

INR 2,500,000 - 4,200,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible schedules
Work from home option
Paid time off
Learning & Development programs
Health and life insurance
Referral bonuses
Global centers and client facilities

Job summary

GlobalLogic, a Hitachi Group Company, seeks a Lead Engineer II – Senior Engineer to own the centralized authentication and authorization stack for our SaaS control plane. You will design token issuance, validate flows (OIDC/JWT), and enforce RBAC/ABAC across tenants.

Collaborate with product and platform teams for SSO integrations (SAML, SCIM), implement robust secret management in AWS, and drive security and scalability across services. India-based role with multiple center opportunities.

Qualifications

  • 5+ years building auth systems in production SaaS environments.
  • Strong Go or Python; ability to write performant, well-tested code.
  • Deep knowledge of OAuth 2.0, OIDC, JWT, and SAML with underlying workings.

Responsibilities

  • Design and operate the centralized authn/authz platform (token issuance and validation).
  • Build and maintain the authorization model with RBAC and ABAC.
  • Expose auth as a shared internal service with clean APIs and contracts.
  • Partner with product and platform teams to implement SSO integrations (SAML, SCIM).

Skills

Go
Python
OAuth 2.0
OIDC
JWT
SAML
Multi-tenant

Tools

AWS
AWS Secrets Manager
EKS

Job description

Lead Engineer II – Senior Engineer, Authentication and Authorization IRC302231

Function

Software Product Engineering

Experience

5-10 years

Location

India - Bangalore, Hyderabad, Pune

Skills

AWS, AWS Secrets Manager, JWT, OAuth 2.0, OpenID Connect (OIDC), Prompt Engineering AWS: EKS, Python, SAML

We’re building the identity and access layer that every service in our SaaS control plane depends on. You’ll own the common auth stack — making sure the right principals get the right access, consistently, across every tenant and product surface.

Requirements
  • 5+ years building auth systems in production SaaS environments.
  • Strong Go or Python (ideally both); comfortable writing performant, well-tested service code in either.
  • Deep knowledge of OAuth 2.0, OIDC, JWT, and SAML — not just using libraries but understanding what’s happening underneath.
  • Experience with authorization policy engines (OPA, Casbin, or equivalent) and modeling complex permission structures.
  • Familiarity with multi-tenant isolation patterns and the security implications of getting them wrong.
  • Comfort in an AWS/EKS environment with secrets management (AWS Secrets Manager, Vault).
  • Nice to have: SCIM provisioning, FIDO2/WebAuthn, zero-trust networking, SOC 2 audit experience, or prior work on a shared platform team serving internal consumers.
Job responsibilities
  • Design and operate the centralized authn/authz platform: token issuance and validation (OIDC/JWT), OAuth 2.0 flows, API key management, and service-to-service identity.
  • Build and maintain the authorization model: RBAC and ABAC policies, tenant isolation enforcement, and fine-grained permission evaluation (Open Policy Agent or similar).
  • Expose auth as a shared internal service consumed by the rest of the control plane — clean APIs, well-documented contracts, and minimal coupling.
  • Partner with product and platform teams to implement SSO integrations (SAML, SCIM) and onboard enterprise identity providers.
  • Harden the auth layer: token rotation, secret management, audit logging, and threat modeling against common identity attacks.
  • Drive adoption of consistent auth patterns across services, replacing one-off implementations.
What we offer
  • Exciting Projects: We focus on industries like High-Tech, communication, media, healthcare, retail and telecom. Our customer list is full of fantastic global brands and leaders who love what we build for them.
  • Collaborative Environment: You Can expand your skills by collaborating with a diverse team of highly talented people in an open, laidback environment — or even abroad in one of our global centers or client facilities!
  • Work-Life Balance: GlobalLogic prioritizes work-life balance, which is why we offer flexible work schedules, opportunities to work from home, and paid time off and holidays.
  • Professional Development: Our dedicated Learning & Development team regularly organizes Communication skills training(GL Vantage, Toast Master),Stress Management program, professional certifications, and technical and soft skill trainings.
  • Excellent Benefits: We provide our employees with competitive salaries, family medical insurance, Group Term Life Insurance, Group Personal Accident Insurance , NPS(National Pension Scheme ), Periodic health awareness program, extended maternity leave, annual performance bonuses, and referral bonuses.
  • Fun Perks: We want you to love where you work, which is why we host sports events, cultural activities, offer food on subsidies rates, Corporate parties. Our vibrant offices also include dedicated GL Zones, rooftop decks and GL Club where you can drink coffee or tea with your colleagues over a game of table and offer discounts for popular stores and restaurants!
About GlobalLogic

GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward-thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Engineer II – Senior Engineer, Authentication and Authorization IRC302231
Lead Engineer II – Senior Engineer, Authentication and Authorization IRC302231

GlobalLogic • India

On-site
INR 2,500,000 - 4,500,000
Competitive salaries
Family medical insurance
Group Term Life Insurance
+11
Principal Engineer Java Backend IRC298540
Principal Engineer Java Backend IRC298540

GlobalLogic • Bengaluru

On-site
INR 2,800,000 - 5,600,000
Flexible schedules
Work from home
Health insurance
+3
OKTA Admin IRC301685
OKTA Admin IRC301685

GlobalLogic • Dadri

On-site
INR 1,500,000 - 2,800,000
Competitive salaries
Family medical insurance
Group term life insurance
+2
Lead Security Engineer – Trilliant IRC300901
Lead Security Engineer – Trilliant IRC300901

GlobalLogic • Chennai District

On-site
INR 4,000,000 - 7,000,000
Flexible work schedules
Work from home
Paid time off
Senior Software Engineer, SaaS Control Plane IRC302106
Senior Software Engineer, SaaS Control Plane IRC302106

GlobalLogic • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Flexible work schedules
Work from home options
Paid time off
Backend Java Developer (Java, Cloud, Kubernetes) – Staff Engineer IRC302353
Backend Java Developer (Java, Cloud, Kubernetes) – Staff Engineer IRC302353

GlobalLogic • India

On-site
INR 1,200,000 - 1,800,000
Flexible work schedules
Work from home
Health insurance
+4
OKTA Admin IRC301685
OKTA Admin IRC301685

GlobalLogic • India

On-site
INR 1,200,000 - 1,800,000
Flexible work schedules
Work from home opportunities
Professional development programs
+1
Senior Java Developer IRC301136
Senior Java Developer IRC301136

GlobalLogic • Bengaluru

On-site
INR 1,800,000 - 4,000,000
Flexible work schedule
Work from home
Paid time off & holidays
+11
Java + React Developer IRC301398
Java + React Developer IRC301398

GlobalLogic • Dadri

On-site
INR 2,500,000 - 4,200,000
Flexible work schedules
Work from home
Competitive salaries
+1
Product Security Architect IRC286354
Product Security Architect IRC286354

GlobalLogic • Dadri

Hybrid
INR 3,500,000 - 7,500,000
Competitive salaries
Medical insurance
Life insurance
+2