Java developer- IAM
Summary
Senior Java backend engineer building and operating the company's identity platform: extending Keycloak with custom SPIs, implementing OAuth 2.0/OIDC/SAML/MFA auth flows, and owning Java microservices in production with Docker, Kubernetes, CI/CD, and AWS or Azure.
## What you'll do
- Design, build, and operate IAM capabilities on Keycloak and Java microservices
- Extend Keycloak through custom SPIs, providers, user federation, and themes to meet evolving business requirements
- Implement and maintain authentication and authorization flows using OAuth 2.0, OpenID Connect, SAML, MFA, and social or enterprise federation
- Drive security best practices, including secure token handling, session management, threat modeling, and supporting audits and compliance
- Own services in production, from design through deployment, observability, and incident response
- Collaborate with product, security, and platform teams to deliver reliable, scalable identity solutions
## What you bring
- Strong Java backend development experience, building and running microservices in production
- Proven, hands-on experience with Keycloak in real-world deployments, including customization via SPIs and providers
- Deep understanding of OAuth 2.0, OpenID Connect, JWT, and SAML
- Proven experience designing and operating distributed systems and microservices in production
- Solid database skills (e.g., PostgreSQL) and familiarity with caching relevant to Keycloak deployments (e.g., Infinispan/Redis)
- Experience with Docker, Kubernetes, CI/CD pipelines, and at least one major cloud platform (AWS or Azure)
- A security-first mindset and experience supporting audits and compliance requirements
Nice to have
- Experience with CIAM at scale: customer identity, identity resolution, or account deduplication
- WebAuthn/FIDO2/passkeys, Zero Trust architectures, or PKI
- Event-driven architectures (e.g., Kafka)
- Observability tooling such as Prometheus, Grafana, and OpenTelemetry