Remote Jobs RockRemote Jobs Rock

Staff Software Engineer, Identity & Authorization

๐Ÿ”ฅ 18 hours ago
Oauth 2.0OIDCJWTMtls

๐Ÿ“œ Description

  • Design and operate central authorization interfaces with typed principals, actions, resources, and explainable deny reasons.
  • Evolve enterprise roles, groups, app access, and workspace policy for both simple and complex cases.
  • Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange and JWT.
  • Threat-model delegation and cross-tenant movement to ensure secure behavior.
  • Lead migrations with shadow evaluation and own the operational health of the systems you ship.
  • Collaborate with various teams to translate product requirements into shared platform primitives.

๐Ÿ› ๏ธ Requirements

  • Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability
  • Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item
  • Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling
  • Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement
  • Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate
  • Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

โœจ Benefits

  • ๐Ÿ’ฐ Competitive Salary & Equity
  • Dental
  • Vision and Life Insurance
  • ๐Ÿšผ Paid Parental
  • Medical
  • Caregiver Leave
  • ๐Ÿ Flexible Time Off (FTO) + Holidays
  • ๐Ÿš— Commuter
Full job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Team

Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly.

Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services.

Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls.

We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here.

About the Role

As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity.

The work is guided by a few simple questions:

  • Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf?

  • Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services?

  • Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions?

  • Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials?

  • Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?

What you'll do

  • Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations

  • Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible

  • Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS

  • Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default

  • Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship

  • Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives

  • Research and develop new innovative approaches to Authx in the Agentic world

Areas you might work in

  • Authorization policy: evolve Replit's central policy decision point and migrate fragmented authorization checks to its typed contract.

  • Agent delegation: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs.

  • Enterprise access control: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations.

  • Agent and service identity and reliability: operate the token and workload-identity systems that protect service-to-service traffic.

Required skills and experience

  • Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability

  • Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item

  • Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling

  • Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement

  • Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate

  • Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

If you're excited about this role but don't meet every requirement, we still encourage you to apply.

Full-Time Employee Benefits Include:

๐Ÿ’ฐ Competitive Salary & Equity

๐Ÿ’น 401(k) Program with a 4% match (US Only)

โš•๏ธ Health, Dental, Vision and Life Insurance

๐Ÿฉผ Short Term and Long Term Disability

๐Ÿšผ Paid Parental, Medical, Caregiver Leave

๐Ÿ Flexible Time Off (FTO) + Holidays

๐Ÿš— Commuter Benefits (In-Office & US Only)

๐Ÿ“ฑ Monthly Wellness Stipend

๐Ÿง‘โ€๐Ÿ’ป Autonomous Work Environment

๐Ÿ–ฅ In Office Set-Up Reimbursement (In-Office Only)

๐Ÿš€ Quarterly Team Gatherings

โ˜• In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Abnormalsecurity

Software Engineer II - Insider Risk

Abnormalsecurity๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Computer & Network Security
๐Ÿ”ฅ 16 hours ago

Build and enhance identity verification and fraud detection systems to protect organizations from insider threats and fraudulent employee identities.

Software DevelopmentFraud DetectionIdentity VerificationData Analysis
Aecom2

OLE Engineer

Aecom2๐Ÿ‘ฅ 10,000+ employees๐Ÿข Architecture And Engineering๐Ÿค B2B
๐Ÿ”ฅ 19 hours ago

The OLE Engineer will engage in design activities for international railway projects, focusing on technical reports, structural design, and interdisciplinary collaboration.

OLE DesignStructural DesignTechnical ReportingCAD Tools
Cloudflare

Software Engineer - Egress (Go/Rust)

Cloudflare๐Ÿ‘ฅ 10,000+ employees๐Ÿข Computer And Network Security๐Ÿค B2B
๐Ÿ”ฅ 20 hours ago

As a key technical contributor on the Egress team, you will enhance Cloudflare's network software infrastructure, ensuring robust connectivity for various products.

GoRustLinux NetworkingClickhouse
MongoDB

Software Engineer 3, AI Framework Integrations

MongoDB๐Ÿ‘ฅ 10,000+ employees๐Ÿข Software Development๐Ÿค B2B
๐Ÿ”ฅ 23 hours ago

As a Software Engineer focused on AI Framework Integrations, you'll build and ship MongoDB integrations across various AI frameworks, taking ownership of projects from design to release.

PythonTypeScriptAI FrameworksBackend Systems

Trusted by Remote Workers