Staff Software Engineer - Customer Identity & Access Management (CIAM)

fastly

United States

Hybrid

USD 211,000 - 254,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity
Discretionary bonus
Health, dental, vision
Life & disability
401(k) with match
Employee stock purchase
Paid time off
Holidays & wellness days
Hybrid/remote US

Job summary

Fastly is seeking a staff software engineer on the Customer Identity and Access Management team to build centralized identity services for our edge cloud platform. You will lead the design and delivery of authentication, authorization, and identity lifecycle capabilities as a technical anchor across workstreams.

You will mentor engineers, shape implementation plans with product and security partners, and participate in on-call rotations to ensure reliability.

Qualifications

  • Significant production experience designing and operating authentication and authorization systems.
  • Deep understanding of identity and access standards and technologies (OIDC, OAuth, SAML, SCIM, JWT, and SSO).
  • Experience with service-to-service authentication and secure communication patterns in distributed systems.
  • Strong software architecture and system design across scalability, performance, reliability, and security.
  • Demonstrated ability to provide technical leadership across multiple teams through architectural guidance and delivery of complex initiatives.
  • Strong written and verbal communication skills.

Responsibilities

  • Design and build secure, scalable identity services covering authentication, authorization, identity lifecycle, and related platform capabilities.
  • Lead complex technical initiatives from design through production, balancing long-term architecture with practical delivery milestones.
  • Act as technical lead for one or more core areas of the platform, guiding architecture, reviewing designs, and supporting sound technical decisions.
  • Partner with engineering, product, and security counterparts to shape implementation plans, prioritize investments, and surface risks early.
  • Translate ambiguous technical problems into incremental, high-quality solutions that hold a strong engineering bar.
  • Champion modern, standards-based identity patterns and mentor engineers through design reviews and collaborative problem solving.
  • Participate in on-call support rotation as needed to maintain reliability of identity services.

Skills

Authentication & authorization design
OIDC/OAuth/SAML/SCIM/JWT/SSO
Distributed systems security
Software architecture & system design
Technical leadership across teams
Communication skills
Keycloak experience

Tools

Go
Java
Ruby
Keycloak

Job description

Role overview

A staff software engineer role on a Customer Identity and Access Management team building centralized identity services for an edge cloud platform. The position involves leading the design and delivery of authentication, authorization, and identity lifecycle capabilities while serving as a technical anchor across multiple workstreams that empower customers with advanced access controls and a unified identity experience.

Responsibilities
  • Design and build secure, scalable identity services covering authentication, authorization, identity lifecycle, and related platform capabilities.
  • Lead complex technical initiatives from design through production, balancing long-term architecture with practical delivery milestones.
  • Act as technical lead for one or more core areas of the platform, guiding architecture, reviewing designs, and supporting sound technical decisions.
  • Partner with engineering, product, and security counterparts to shape implementation plans, prioritize investments, and surface risks early.
  • Translate ambiguous technical problems into incremental, high-quality solutions that hold a strong engineering bar.
  • Champion modern, standards-based identity patterns and mentor engineers through design reviews and collaborative problem solving.
  • Participate in on-call support rotation as needed to maintain reliability of identity services.
Requirements
  • Significant production experience designing and operating authentication and authorization systems, typically 7+ years of relevant work.
  • Deep understanding of identity and access standards and technologies such as OIDC, OAuth, SAML, SCIM, JWT, and SSO.
  • Experience with service-to-service authentication and secure communication patterns in distributed systems.
  • Strong background in software architecture and system design across scalability, performance, reliability, and security.
  • Demonstrated ability to provide technical leadership across multiple teams through architectural guidance and delivery of complex initiatives.
  • Strong written and verbal communication skills, with the ability to produce clear documentation and align diverse stakeholders.
Nice to have
  • Experience with Go, Java, or Ruby.
  • Hands-on experience with Keycloak.
  • Production experience implementing Role-based and Attribute-based Access Control systems.
  • Background designing secure identity systems with attention to authentication threats, authorization models, and operational resilience.
Benefits and work setup
  • Estimated salary range of $211,370 to $253,644, with eligibility for equity and discretionary bonus programs.
  • Comprehensive medical, dental, and vision coverage, plus life, disability, and accident insurance starting day one.
  • Family planning benefits, mental health support, an Employee Assistance Program, flexible vacation, and up to 18 days of accrued paid sick leave.
  • 401(k) with company match and an Employee Stock Purchase Program.
  • 11 paid local holidays and 12 paid company wellness days for the year.
  • Strong preference for hybrid work near a local office, with potential to consider qualified remote candidates within the US; quarterly travel may be required to align on technical direction.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Identity Engineer
Staff Identity Engineer

United States Digital Space LLC • Washington

On-site
USD 161,000 - 221,000
Equity
Health insurance
Dental & Vision insurance
+1
Cybersecurity Engineer
Cybersecurity Engineer

SSA Marine • Seattle (WA)

Hybrid
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+11
Staff Software Engineer, IAM
Staff Software Engineer, IAM

CoreWeave • Bellevue (WA)

On-site
USD 180,000 - 240,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Engineer, CIAM
Engineer, CIAM

Optimum Communications Inc. • Bethpage (NY)

Hybrid
USD 84,000 - 137,000
Engineer, CIAM
Engineer, CIAM

Optimum Communications Inc. • Plano (TX)

On-site
USD 84,000 - 137,000
Senior Cloud Security Developer with OAuth 2.0
Senior Cloud Security Developer with OAuth 2.0

Aether Biomedical • United States

Hybrid
USD 150,000 - 210,000
Vacation days (26)
Health and life insurance
MyBenefit platform
+5
Senior Software Engineer II
Senior Software Engineer II

LexisNexis Risk Solutions • Town of Texas (WI)

Hybrid
USD 95,000 - 159,000
Senior Identity & Access Architect
Senior Identity & Access Architect

OEC • United States

Hybrid
USD 140,000 - 190,000
IAM/PAM Architect
IAM/PAM Architect

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 130,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+3
Senior Identity & Access Architect- Remote within the US
Senior Identity & Access Architect- Remote within the US

Francisco Partners • United States

Hybrid
USD 140,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+7