Senior Backend Engineer (IAM)
Summary
Senior backend engineer to design, build, and operate identity & access management services (SSO, MFA, session management, federation) on a high-throughput distributed platform for a financial-services customer. Core stack is Go and gRPC with OAuth 2.0/OIDC, JWT, AWS, Kubernetes, and Terraform-based infrastructure.
We are hiring a Senior Backend Engineer (Identity & Access Management) for a project building a scalable distributed platform and delivering reliable backend solutions.
Our customer is an international organization operating in the financial and protection services domain. The company provides a diverse portfolio of customer-oriented solutions across multiple business areas and markets. With a strong focus on digital capabilities, operational excellence, and long-term development, the organization continuously invests in technology, process improvement, and service innovation to support evolving customer and business needs.
The project focuses on building and evolving a high-performance, scalable distributed platform designed to support complex business operations and rapid product growth. The system is developed in Go, with a strong emphasis on efficient concurrency models, reliability, and long-term maintainability.
Responsibilities:
Designing, developing, and operating high-throughput, low-latency identity services: Single Sign-On (SSO), Multi-Factor Authentication (MFA), session management, and federation.
Owning features end-to-end from design through production and support.
Implementing and scaling modern authentication and authorization protocols and token formats (OAuth 2.0, OpenID Connect, JWTs), including secure token issuance, rotation, and revocation strategies.
Writing clean, concurrent, and highly performant backend services primarily in Go.
Designing idiomatic, testable code and clear API contracts (gRPC/HTTP).
Using DevOps experience to deploy, manage, and automate identity infrastructure (CI/CD, monitoring, and incident response).
Serving as the subject matter expert on authentication and identity: owning internal security reviews, threating modeling for identity flows, and guiding other teams on secure integrations with the platform.
Integrating and maintaining solutions with custom and standard identity providers (e.g. Keycloak and AWS Cognito), and federation patterns.
Mentoring engineers, conducting design reviews, and contributing to the team's technical roadmap and security posture.
Must-haves:
Experience in backend engineering for 7+ years, including 5+ years with Go.
Experience working with IAM in production environments.
Strong production experience with Go and gRPC, building complex, distributed backend systems.
Deep expertise in authentication and authorization, including OAuth 2.0, OIDC, SSO, MFA, RBAC, JWT signing/verification/assertions, token security, session management, and cryptography.
Strong understanding of web security, federated identity, secure coding, and OWASP Top 10.
Hands-on experience with cloud platforms (AWS preferred), container orchestration (Kubernetes), and Infrastructure as Code (Terraform, Terragrunt and OpenTofu/Tofu).
Experience designing high-throughput, low-latency systems with a focus on security and correctness.
Strong communication skills and ability to explain security and architecture trade-offs to technical and non-technical stakeholders.
Level of English – from Upper-Intermediate and above.
Nice-to-haves:
Experience with SAML, SCIM, PKI, JWKs/JWKS endpoints, key management (KMS/HSM) and token introspection.
Working knowledge of identity platforms (commercial or open source), rate limiting, abuse mitigation, and adaptive authentication.
