Описание:
Xsolla is a global commerce company that provides tools and services to help video game developers fund, distribute, market, and monetize their games. It operates as a merchant of record and helps game developers reach more players and grow their businesses.
Задачи:
- Own the technical strategy and architecture of the Xsolla ID IAM platform, covering authentication, authorization, and session management at scale Design and evolve OAuth 2.0 / OIDC flows, token lifecycles, and security primitives to meet product and compliance requirements
- Lead decisions on the Ory ecosystem, including API extensions, custom authentication methods, and the Auth API orchestrator and plugin architecture
- Own web security fundamentals across the platform, including cookie security, CSRF, XSS protection, secure token storage, TLS, and secure session management
- Drive the CockroachDB strategy for geo-distributed data residency, including multi-region deployments, clock skew handling, and survivability trade-offs
- Review complex security-critical code and ensure best practices
- Drive the zero-downtime migration from legacy Xsolla Login with bidirectional identity sync
- Identify systemic risks and performance bottlenecks, and lead initiatives to resolve them before they become incidents
- Make key decisions on system design, security architecture, and technology choices
- Contribute hands-on to critical security features
- Lead and mentor a team of up to 8 backend engineers
- Conduct regular 1:1s, performance reviews, and career development conversations
- Hire and onboard new team members with IAM/security expertise
- Foster a security-first culture focused on code quality
- Manage team workload and delivery commitments
- Own the team’s delivery predictability for the mission-critical platform
- Collaborate with Product to define the IAM roadmap and priorities
- Coordinate with dependent product teams, including Xsolla Pay, Wallet, App, and Backpack
- Report on security posture, platform reliability, and team progress
Требования:
- 5+ Years of commercial experience with Go, or 7+ years with other backend languages and Go proficiency
- Deep expertise in OAuth 2.0 / OIDC and IAM systems, including authorization code + PKCE, client credentials, device flow, token introspection, and refresh strategies
- Understanding of JWT, token refresh flows, and session management
- Knowledge of password hashing (bcrypt, Argon2) and secure storage
- Knowledge of web security fundamentals, including cookie security, CSRF, XSS, TLS, and secure session management
- Strong knowledge of MySQL/PostgreSQL, including schema design, query optimization, and migrations at scale, and Redis
- Experience with distributed systems and their trade-offs, including consistency, availability, and failure modes
- Experience with high-availability system design for 99.9%+ uptime requirements
- Understanding of security best practices and common vulnerabilities, including OWASP
- Experience with Docker, Kubernetes, and production deployments
- At least 2 years of experience leading engineering teams
- Track record of delivering mission-critical infrastructure
- Ability to lead multi-quarter technical initiatives across teams and influence architecture beyond the immediate team
- Experience with security-focused code review processes
- Strong written and verbal communication skills for RFCs and design documents
- Ability to balance security requirements with delivery timelines
- Будет плюсом: production experience with the Ory ecosystem, CockroachDB or other distributed SQL databases, NATS or Kafka, WebAuthn/FIDO2, Web3 authentication, SCIM, SAML, enterprise SSO (LDAP / Active Directory), fintech, payments, or gaming identity systems, IAM compliance requirements (SOC 2, ISO 27001, PCI DSS, GDPR data minimization, audit logging), open-source security or identity contributions, platform or infrastructure engineering, large-scale migrations involving millions of accounts, and practical up-to-date experience with AI tools such as Claude, Copilot, or Cursor
Условия:
- Unlimited flexible time off
- Private health insurance with dental coverage for the employee and family
- Personalized career roadmap with clear growth paths
- Professional development through training, security certifications, and conferences
- Annual corporate events and team gatherings
- Flexible working hours, 10:00–19:00
- Leadership development programs and executive coaching
- Competitive compensation reflecting leadership and security expertise
- Employment agreement; the entity or EOR is arranged according to the candidate’s location