Software Engineer - Identity and Authorization

Baseten

San Francisco, New York (CA, NY)

On-site

USD 180,000 - 240,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive compensation with equity
Comprehensive medical, dental, vision
Flexible PTO including Winter Break
Paid parental leave
Fertility and family-building stipend
401(k) employer match
Learning and networking opportunities

Job summary

Baseten in San Francisco is seeking a senior backend engineer to own the identity and authorization layer for enterprise customers. You will design and build a fine-grained authorization system, manage per-resource permissions, and ensure low-latency checks at high request volumes across the platform.

Collaborate with product, design, and customer teams to translate security requirements into durable technical solutions, establish engineering practices, and mentor growing teammates.

Qualifications

  • 4-5+ years building production backend systems with a fine-grained authorization system.
  • End-to-end ownership from design through production rollout and iteration.
  • Experience operating multi-tenant systems where latency and consistency matter.
  • Comfort working across the full stack from product and application code to cloud infrastructure and Kubernetes.

Responsibilities

  • Lead identity and authorization projects from problem definition and design through implementation, launch, and iteration.
  • Design authorization and credential models that support critical workflows today and can be safely extended as the platform grows.
  • Partner with product, design, and customer-facing teams to translate security requirements into durable solutions.
  • Establish engineering practices for quality, security, observability, and operational ownership.
  • Provide technical leadership and mentorship as the team grows.

Skills

Backend systems
Latency-sensitive design
Multi-tenant systems
Cloud & Kubernetes

Tools

OpenFGA
SpiceDB
Cedar

Job description

ABOUT BASETEN

Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting‑edge models into production. We're growing quickly and recently raised our $1.5B Series F, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to ship AI products.

THE ROLE

The largest, most demanding enterprises run on Baseten, and they bring exacting requirements for how people, services, and agents access the platform. This is the founding role for our identity and authorization team within enterprise engineering. You'll own the identity and access layer of the Baseten platform: the authorization model, credential systems, and admin experiences that enterprise IT teams use to govern access for organizations like Harvey, HubSpot, and Notion.

You’ll design and build Baseten’s fine‑grained authorization system from the ground up to support the workflows customers depend on today while giving them cleaner, more precise ways to manage access as the platform grows. Authorization at Baseten requires low‑latency permission checks at high request volume, consistent contracts and behaviors across the product suite, and strong security guarantees for mission‑critical, highly regulated workloads.

EXAMPLE INITIATIVES

Recent and upcoming work in this area:

  • Fine‑grained authorization for users, service accounts, and agentic workloads: per‑resource permissions at the organization, team, and workload scope to support both common workflows and complex enterprise access policies
  • Programmatic authentication allowing high‑compliance customers to connect service principles securely via short‑lived, workload‑based credentials
  • Agent credentials that grant an agent exactly the access it needs for the given task and nothing more
  • Enterprise identity lifecycle including single sign‑on, SCIM provisioning, and per‑organization session expiry policies
  • Admin controls for centralized visibility, auditability, and governance over credentials, roles, and access
RESPONSIBILITIES
  • Lead identity and authorization projects from problem definition and technical design through implementation, launch, and iteration.
  • Design authorization and credential models that support critical user workflows today and can be safely extended as the platform evolves.
  • Partner with product, design, and customer‑facing teams to turn enterprise security requirements into durable technical solutions.
  • Establish engineering practices for quality, security, observability, and operational ownership.
  • Provide technical leadership and mentorship as the team grows.
REQUIREMENTS
  • 4-5+ years of experience building production backend systems, including hands‑on design and implementation of a product authorization system: per‑resource or per‑object permissions, relationship‑based access control, a policy engine, or a fine‑grained authorization system in the style of Zanzibar, OpenFGA, SpiceDB, or Cedar.
  • Demonstrated end‑to‑end ownership: you've taken a system from first design through implementation, production rollout, and iteration with users.
  • Experience developing and operating multi‑tenant systems at scale, where authorization checks sit in the request path and latency and consistency matter.
  • Comfort working across the full stack, from product and application code to cloud and Kubernetes infrastructure.
Preferred:
  • Experience with Python and Go.
  • Experience running an OpenFGA, SpiceDB, or similar deployment in production, beyond a proof of concept.
  • Working knowledge of OAuth, OIDC, and SCIM at the protocol level.
BENEFITS
  • Competitive compensation, including meaningful equity
  • 100% coverage of medical, dental, and vision insurance for employee and dependents
  • Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)
  • Paid parental leave
  • Fertility and family‑building stipend through Carrot
  • Company‑facilitated 401(k)
  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer - Identity and Authorization
Software Engineer - Identity and Authorization

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 210,000 - 320,000
Competitive compensation
Equity
Medical, dental, vision insurance
+4
Software Engineer - Enterprise Platform
Software Engineer - Enterprise Platform

BaseTen • New York (NY), San Francisco (CA)

On-site
USD 150,000 - 230,000
Medical, dental, vision insurance for
Dependent coverage
Flexible PTO incl. Winter Break
+4
Head of IT
Head of IT

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 280,000
Equity
Medical dental vision coverage for 1
Flexible PTO including Winter Break
+3
Head of IT
Head of IT

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 280,000
Competitive compensation & equity
Full health insurance for employee & +
Flexible PTO including Winter Break
+4
Software Engineer - Enterprise Platform
Software Engineer - Enterprise Platform

The Consensus • New York (NY)

Hybrid
USD 130,000 - 160,000
100% coverage of medical, dental, and vision insurance
Flexible PTO policy
Paid parental leave
+2
Head of IT
Head of IT

Baseten • San Francisco (CA), Northern (KY)

On-site
USD 180,000 - 280,000
Competitive equity
Medical, dental, vision coverage for员工
GRC Manager
GRC Manager

Baseten • San Francisco (CA)

On-site
USD 150,000 - 190,000
Equity
Medical/Dental/Vision
Flexible PTO
+4
Security Engineer
Security Engineer

The Consensus • San Francisco (CA)

On-site
USD 120,000 - 150,000
100% medical, dental, and vision insurance
Flexible PTO policy
Paid parental leave
+2
GRC Manager
GRC Manager

The Consensus • New York (NY)

On-site
USD 130,000 - 180,000
Competitive compensation
Equity
Medical/Dental/Vision insurance
+1
GRC Manager
GRC Manager

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4