Stand out for this role — generate a tailored resume and cover letter in about a minute.
Replit is seeking a Senior Backend Security Engineer to design, build, and operate identity and authorization systems protecting critical interactions across multi-tenant environments. You will lead the evolution of enterprise access controls, roles, and workspace policies using modern protocols like OAuth 2.0, JWT, and mTLS.
You will own the security health of shipped systems, collaborate with multiple teams, and drive secure migrations with shadow evaluation and telemetry.
• Design, build, and operate identity and authorization systems protecting critical Replit interactions
• Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations
• Evolve enterprise roles, groups, app access, entitlements, and workspace policies
• Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS
• Threat-model delegation, confused-deputy risks, and cross-tenant movement, establishing secure fail-closed defaults
• Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans
• Own SLOs, incidents, and operational health of shipped systems
• Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives
• Research and develop innovative approaches to Authx in the agentic world
• Evolve central policy decision points, agent delegation, enterprise access control, and service identity and reliability systems
Demonstrates expertise in designing and operating identity and authorization systems, with a strong focus on security-sensitive backend systems and multi-tenant security. Proficient in implementing OAuth 2.0, JWT, and mTLS, while effectively communicating tradeoffs across security and performance metrics.