Staff Software Engineer, Identity & Authorization

United States Digital Space LLC

United States

Remote

USD 100,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Ins.
Flexible Time Off (FTO)
Monthly Wellness Stipend
Autonomous Work Environment

Job summary

United States Digital Space LLC is seeking a Software Engineer to design, build, and operate the identity and authorization systems critical for user interactions. You will lead efforts in creating secure, efficient, and trustworthy systems for enterprise access control.

The role involves working in a collaborative team environment that values curiosity and thoughtful problem-solving. If you have experience with security-sensitive systems and a strong backend background, we encourage you to

Qualifications

  • Experience shipping and operating security-sensitive backend or distributed systems in production.
  • Depth in authentication, authorization, or identity systems like OAuth 2.0/OIDC, JWT, mTLS.
  • Fluent in at least one production backend stack.

Responsibilities

  • Design and operate central authorization interfaces.
  • Build and operate the company's Security Token Service.
  • Research and develop new innovative approaches to Authx.

Skills

Security-sensitive backend systems
OAuth 2.0
JWT
mTLS
TypeScript
Go
Rust
Postgres
gRPC/Protobuf
Kubernetes

Job description

About the Company

the company is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, the company is democratizing software development by removing traditional barriers to application creation.

About the Team

Product Platform builds and owns the shared foundations the rest of the company is built on, spanning the full stack so every other team can ship features safely and quickly.

Identity & Authorization

Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across the company's web product, Agent, enterprise controls, and internal services.

Our Focus

Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls.

Team Culture

We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here.

About the Role

As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on the company, including Agent acting on behalf of a user or holding their own identity.

Guiding Questions
  • Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf?
  • Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services?
  • Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions?
  • Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials?
  • Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?
What you'll do
  • Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations
  • Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible
  • Build and operate the company's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS
  • Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default
  • Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship
  • Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives
  • Research and develop new innovative approaches to Authx in the Agentic world
Areas you might work in
  • Authorization policy: evolve the company's central policy decision point and migrate fragmented authorization checks to its typed contract.
  • Agent delegation: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs.
  • Enterprise access control: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations.
  • Agent and service identity and reliability: operate the token and workload-identity systems that protect service-to-service traffic.
Required skills and experience
  • Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability
  • Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item
  • Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling
  • Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement
  • Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate
  • Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

If you're excited about this role but don't meet every requirement, we still encourage you to apply.

Full-Time Employee Benefits Include
  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver LeaveFlexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office & US Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)
Want to learn more about what we are up to
  • Self-driving Company
  • the company Agent at Scale
  • AI Adoption
  • Build Open-Source Apps
Interviewing + Culture at the company
  • Operating Principles
  • Reasons not to work at the company

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Identity & Authorization
Staff Software Engineer, Identity & Authorization

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
Health, Dental, Vision
Life Insurance
401(k) with employer match
+2
Forward Deployed Engineer
Forward Deployed Engineer

Baselayer • San Francisco (CA)

On-site
USD 160,000 - 230,000
Flexible PTO
In-person SF office four days a week
Health, dental, vision fully covered
+4
Staff Fullstack Engineer
Staff Fullstack Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 170,000
Staff Software Engineer, AI-Core (Federal)
Staff Software Engineer, AI-Core (Federal)

Segment (Twilio) • San Francisco (CA)

On-site
USD 194,000 - 267,000
Health, dental, and vision insurance
401(k)
Flexible spending account
+1
Senior Engineer, Agentic Identity Engineering San Francisco, California
Senior Engineer, Agentic Identity Engineering San Francisco, California

Baselayer • San Francisco (CA), Northern (KY)

Hybrid
USD 230,000 - 340,000
Flexible PTO
In-person SF office 4 days/week
Competitive compensation + equity
+5
Staff Software Engineer: Agent Identity and Authorization
Staff Software Engineer: Agent Identity and Authorization

delinea • United States

On-site
USD 180,000 - 240,000
Healthcare insurance
Retirement matching
Life insurance
+3
Senior Software Engineer, AI Agentic Experience (Auth0)
Senior Software Engineer, AI Agentic Experience (Auth0)

Okta • Bellevue (WA)

On-site
USD 140,000 - 190,000
Senior Identity Engineer
Senior Identity Engineer

Talanto • Boston (MA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Senior Software Development Engineer - Agent Identity & Core Primitives
Senior Software Development Engineer - Agent Identity & Core Primitives

delinea • United States

On-site
USD 180,000 - 240,000
Competitive salary
Meaningful bonus program
Healthcare insurance
+5
Manager, Engineering
Manager, Engineering

United States Digital Space LLC • United States

Hybrid
USD 150,000 - 210,000