Software Engineer, Backend (Security)

Base Power

Austin (TX)

On-site

USD 140,000 - 200,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Base is building a modern identity platform to securely authenticate and authorize access across its cloud apps, devices, and internal systems. We seek a hands-on software engineer to design and operate identity primitives, SSO/IdP, and workload identity with a governed PKI, advancing security while moving fast in a growing, in-person team.

You will partner with IT and security to define entitlements as code, implement MFA, RBAC, and short-lived credentials, and help shape Base's security

Qualifications

  • Experience designing or operating identity systems such as SSO/IdP, authn/authz, or workload identity.
  • Strong backend engineering experience in Go, Java, or similar.
  • Knowledge of OIDC, SAML, and SCIM and when to use each.
  • Comfort with cryptographic identity primitives like PKI and mTLS.

Responsibilities

  • Build and operate the workforce identity provider (SSO, SAML/OIDC, SCIM provisioning).
  • Design authentication policy and authorization primitives with least-privilege approach.
  • Federate cloud access using AWS IAM Identity Center and GCP Workforce Identity Federation.
  • Define and maintain entitlements-as-code in the GitOps monorepo.
  • Build workload identity infrastructure including private PKI and hardware-backed keys.

Skills

Go/Java backend
Identity systems
OIDC/SAML/SCIM
PKI/mTLS
Ownership & communication

Job description

About Base

Base is America’s next-generation power company. We’re rebuilding the foundation of modern civilization–electricity–by deploying a vast network of distributed batteries that is transforming today’s fragile, centralized grid into a resilient and abundant system. We are engineers, operators, and creatives solving some of the most complex, interdisciplinary challenges of our time.

About the Role

We are seeking Software Engineers to build the Identity Provider and Authorization platform that decides who — and what — can access Base's systems.

Base runs on a growing mix of internal apps, cloud infrastructure, and machines that all need to authenticate and authorize safely: employees signing into AWS and GCP, services talking to each other, and devices proving their own identity in the field. This role will own the platform layer that turns fragmented, ad hoc access into a single, auditable identity system.

You will design the core primitives for identity and access: workforce SSO, cloud federation, entitlements-as-code, and workload identity backed by a governed PKI. The ideal candidate is a hands‑on engineer who takes security‑critical systems seriously, moves fast without cutting corners on least privilege, and can turn a still‑forming scope into durable infrastructure other engineers build on.

What You'll Do
  • Build and operate Okta as Base's workforce identity provider — SSO, SAML/OIDC app integrations, SCIM provisioning, and joiner/mover/leaver lifecycle automation.

  • Design authentication policy (MFA, device assurance) and authorization primitives (RBAC, least‑privilege role catalog, break‑glass access) that other teams can safely build on.

  • Federate cloud access through AWS IAM Identity Center and GCP Workforce Identity Federation, replacing long‑lived IAM users and service‑account keys with short‑lived credentials.

  • Define and maintain entitlements-as-code: every role, group mapping, and access grant lives in the GitOps monorepo as a reviewable pull request.

  • Build workload and headless identity infrastructure — private CA/PKI, AWS Roles Anywhere, GCP WIF-X509, and hardware‑backed key custody (Secure Enclave, TPM, YubiKey).

  • Define Identity Assurance Level requirements, per NIST SP 800‑63‑3, for internal, partner, and service‑to‑service access.

  • Partner with IT, security, and application teams to keep identity, groups, and tokens as the shared foundation, while apps continue to own their own authorization business logic.

What You'll Bring
  • Strong backend engineering experience in Go, Java, or a similar systems language.

  • Experience designing or operating identity systems — SSO/IdP, authn/authz, entitlements, or workload identity.

  • Working knowledge of OIDC, SAML, and SCIM, and judgment about when to use each.

  • Comfort with cryptographic identity primitives — PKI, mTLS, or hardware‑backed keys.

  • High ownership, clear communication, and comfort making durable technical decisions in ambiguous, fast‑moving environments, including scope that's still being defined.

About the Team

The Identity Provider and Authorization team decides who — and what — can access Base's systems. We build and operate the workforce identity provider, federate access to cloud and internal infrastructure, define entitlements as code, and issue workload identity from a single governed PKI.

Our scope spans internal and partner access today, with customer‑facing (CIAM) and fine‑grained ABAC still being scoped, plus the service‑to‑service and headless identity that keeps Base's growing fleet of software and devices secure. Application teams own their own authorization business logic — we supply the identity, groups, and tokens they build on.

This is a rare opportunity to build the identity layer for one of the fastest‑scaling energy companies in the country, from close to zero.

Please note: Base is a startup, which means priorities shift and evolve quickly. Your role may expand or change based on the needs of the business at any given time, so the responsibilities listed may not be exhaustive.

Our Values
  • First Principles Thinking: Question assumptions. Principles > rules.

  • Operate at Base Pace: Focus on what matters, act quickly, and learn by doing.

  • Give & Get Feedback: Be direct, be humble, and maintain a growth mindset.

  • Everyone’s an Owner: Follow through on commitments and own results.

  • Strong Opinions, Loosely Held: Drive clarity and make calls with imperfect information.

  • Committed to the Mission: Rebuilding the grid is a big challenge. We work hard because we care deeply about the impact we’re creating. We work in‑person. It’s not a 9‑to‑5. We are all‑in.

  • Fun & Optimism Coexist with Grit: Collaboration and celebration coincide with the intensity of building real things.

Do the best work of your life at Base.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer, Backend (Security)
Software Engineer, Backend (Security)

Base Power Company • Austin (TX)

On-site
USD 120,000 - 180,000
Software Engineer, Backend (Security)
Software Engineer, Backend (Security)

Speedrun Talent Network • Austin (TX), Northern (KY)

Hybrid
USD 150,000 - 230,000
Senior Software Engineer, Backend
Senior Software Engineer, Backend

Base Power Company • Austin (TX)

On-site
USD 150,000 - 200,000
Senior Software Engineer, Backend
Senior Software Engineer, Backend

Base Power • Austin (TX)

On-site
USD 180,000 - 240,000
Software Engineer, Backend
Software Engineer, Backend

Base Power • Austin (TX)

On-site
USD 150,000 - 230,000
Senior Backend Engineer — Distributed Systems for the Grid
Senior Backend Engineer — Distributed Systems for the Grid

Base Power • Austin (TX)

On-site
USD 150,000 - 230,000
Software Engineer, Backend
Software Engineer, Backend

Base Power Company • Austin (TX)

On-site
USD 90,000 - 130,000
Head of IT & Security
Head of IT & Security

Security Executive Council • Austin (TX), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Software Engineer, Product
Senior Software Engineer, Product

Base Power Company • Austin (TX)

On-site
USD 140,000 - 200,000
Senior Software Engineer, Product
Senior Software Engineer, Product

Base Power • Austin (TX)

On-site
USD 140,000 - 190,000