An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Andersen is hiring a Senior Backend Engineer (Identity & Access Management) to design and operate high-throughput identity services, including SSO, MFA, session management, and token workflows, on a Go-based distributed platform.
You will own features end-to-end, implement OAuth 2.0, OpenID Connect, and JWTs, collaborate with AWS, Kubernetes, and Terraform, and mentor engineers while strengthening security posture and secure integrations.
Andersen is hiring a Senior Backend Engineer (Identity & Access Management) for a project building a scalable distributed platform and delivering reliable backend solutions. Our customer is an international organization operating in the financial and protection services domain. The company provides a diverse portfolio of customer-oriented solutions across multiple business areas and markets. With a strong focus on digital capabilities, operational excellence, and long-term development, the organization continuously invests in technology, process improvement, and service innovation to support evolving customer and business needs. The project focuses on building and evolving a high-performance, scalable distributed platform designed to support complex business operations and rapid product growth. The system is developed in Go, with a strong emphasis on efficient concurrency models, reliability, and long-term maintainability.
Designing, developing, and operating high-throughput, low-latency identity services: Single Sign-On (SSO), Multi-Factor Authentication (MFA), session management, and federation. Owning features end-to-end from design through production and support. Implementing and scaling modern authentication and authorization protocols and token formats (OAuth 2.0, OpenID Connect, JWTs), including secure token issuance, rotation, and revocation strategies. Writing clean, concurrent, and highly performant backend services primarily in Go. Designing idiomatic, testable code and clear API contracts (gRPC/HTTP). Using DevOps experience to deploy, manage, and automate identity infrastructure (CI/CD, monitoring, and incident response). Serving as the subject matter expert on authentication and identity: owning internal security reviews, threating modeling for identity flows, and guiding other teams on secure integrations with the platform. Integrating and maintaining solutions with custom and standard identity providers (e.g. Keycloak and AWS Cognito), and federation patterns. Mentoring engineers, conducting design reviews, and contributing to the team's technical roadmap and security posture.
Experience in backend engineering for 7+ years, including 5+ years with Go. Experience working with IAM in production environments. Strong production experience with Go and gRPC, building complex, distributed backend systems. Deep expertise in authentication and authorization, including OAuth 2.0, OIDC, SSO, MFA, RBAC, JWT, token security, session management, and cryptography. Strong understanding of web security, federated identity, secure coding, and OWASP Top 10. Hands-on experience with AWS, Kubernetes, and Terraform. Experience designing high-throughput, low-latency systems with a focus on security and correctness. Strong communication skills and ability to explain security and architecture trade-offs to technical and non-technical stakeholders. Level of English – from Upper-Intermediate and above.
Experience with SAML, SCIM, PKI, JWKs/JWKS endpoints, key management (KMS/HSM) and token introspection. Working knowledge of identity platforms (commercial or open source), rate limiting, abuse mitigation, and adaptive authentication.
Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc.. The opportunity to change the project and/or develop expertise in an interesting business domain.
You can work both fully remotely and from the office or can choose a hybrid variant.
Your personal data is protected in accordance with GDPR regulations.
Learn more: https://andersenlab.com/privacy-policy/plJoin us! https://people.andersenlab.com