Job Closed
This listing is no longer active.
The cloud ☁️ of choice for developers, startups, and growing digital businesses around the world.
Senior Software Engineer, Identity & Access Management
Location
Worldwide
Posted
94 days ago
Salary
$140.8K - $176K / year
Seniority
Senior
Job Description
Senior Software Engineer, Identity & Access Management
DigitalOcean
Role Description We are seeking a Senior Software Engineer (IC3) to join our Customer Trust & Engineering team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency. In this role, you won't just maintain existing systems—you will architect the next generation of our Identity platform. You will be instrumental in supporting our AI initiatives, building seamless SSO integrations for global partners, and evolving our policy engine to support complex, agentic workflows. If you are passionate about distributed systems, security-first engineering, and building at hyperscale, this is the team for you. What You’ll Do - Architect for Scale: Design and develop high-availability, low-latency authentication and authorization services in Go that scale to handle massive load spikes across global regions. - Drive Next-Gen Innovation: Build the IAM foundations for emerging cloud-native AI/ML platforms, designing secure token exchange patterns and identity context injection for agentic AI workflows. - Modernize Identity: Lead the implementation of OIDC and SAML integrations, enabling seamless federated Single Sign-On (SSO) for enterprise customers and strategic global partners. - Solve Complex AuthZ: Evolve our Policy Engine (using industry standards like Rego/OPA) to support advanced resource-level permissions, dynamic scoping, and network-aware access conditions. - Evolve Identity Models: Design and scale robust, multi-tenant data models to manage complex hierarchical structures (users, teams, organizations, and resource boundaries) that map to enterprise customer needs. - Operational Excellence: Take ownership of service reliability, from fine-tuning Kubernetes deployments to migrating legacy data pipelines to modern eventing architectures. - Security First: Proactively identify and remediate complex security vulnerabilities, ensuring our auth flows are resilient against credential stuffing, session hijacking, and configuration theft. - Mentor & Lead: Act as a technical lead for major workstreams, conducting deep code reviews and mentoring junior engineers in distributed systems best practices. Qualifications - 5+ years of software engineering experience, with at least 2+ years focused on Identity (AuthN/AuthZ), Security Products, or high-scale Distributed Systems. - Expert-level proficiency in Go and a strong understanding of gRPC microservices architecture. - Deep knowledge of identity protocols (OIDC, OAuth2, SAML) and access control models (RBAC, ABAC, PBAC). - Proven ability to build systems that handle consensus, replication, and partitioning at cloud scale. - Working experience with container orchestration (Kubernetes), SQL (MySQL), and Infrastructure as Code (Terraform). - A track record of "unwinding" complex legacy logic into clean, maintainable abstractions. - Ability to communicate technical strategy to senior leadership and collaborate across teams (Inference, Billing, DOKS). Nice to Have - Experience with Open Policy Agent (OPA) and Rego. - Familiarity with Cloud-native deployment strategies (Canary/Blue-Green) via Kubernetes. Compensation Range $140,800 - $176,000 *This is a remote role Benefits - Competitive array of benefits to support you, including Employee Assistance Program and Local Employee Meetups. - Flexible time off policy. - Reimbursement for relevant conferences, training, and education. - Access to LinkedIn Learning's 10,000+ courses to support continued growth and development. - Bonus eligibility based on company and individual performance. - Equity compensation for eligible employees, including equity grants upon hire and participation in the Employee Stock Purchase Program. Company Description DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service. You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.
Related Guides
Related Job Pages
More Full-stack Engineer Jobs
AI Staff Software Engineer
NateraWe are a global leader in cell-free DNA (cfDNA) testing, dedicated to oncology, women’s health, and organ health.
• Lead the technical design and delivery of AI-native accessioning automation services across paper and electronic requisition forms. • Build fast, ship independently. • Apply AI pragmatically using LLMs, vision models, OCR, and IDP frameworks. • Own the product outcome by partnering with Accessioning Operations, Product, and Engineering teams. • Integrate across systems and build into existing mature commerce and fulfillment systems. • Set the bar for engineering practices on a new team: AI-assisted development, strong test automation, CI/CD, and observability. • Evaluate new AI tools, models, and vendor solutions. • Mentor and multiply the technical quality of peers.
• Design, develop, and maintain production‑grade software systems with a focus on performance, reliability, and scalability • Optimize system behavior for real‑time, low‑latency environments, including edge and cloud components • Design, implement, and refine core system logic that improves platform performance, reliability, and scalability under real‑world conditions. • Profile, analyze, and optimize system performance across CPU, memory, I/O, and networking • Improve system observability through logging, monitoring, and diagnostics • Work on end‑to‑end development, from design and implementation to testing, deployment, and support • Collaborate with Deployment, ML, and Systems teams to validate and support improvements in production‑like and live environments. • Debug and resolve complex production issues involving distributed or real‑time systems • Write clean, maintainable, and well‑tested code following engineering best practices • Participate in code reviews and contribute to improving engineering standards and tooling • Support production systems post‑deployment and assist with performance tuning and issue resolution
• Design and implement robust authentication and authorization systems using industry-standard protocols such as OAuth 2.0, SAML, and JWT • Develop and maintain secure admin panels and dashboards that enable efficient system administration and user management • Architect microservices-based solutions for identity and access management, ensuring scalability and high availability • Conduct thorough security reviews and implement best practices to protect against vulnerabilities and threats • Collaborate with cross-functional teams across distributed locations to define requirements, establish technical standards, and drive implementation of authentication solutions • Partner with Product teams to understand customer needs and business objectives, translating them into technical solutions that balance security, usability, and scalability • Mentor junior and mid-level engineers, providing technical guidance and code reviews to ensure code quality and knowledge sharing • Analyze system performance, identify bottlenecks, and optimize authentication workflows for efficiency and reliability • Participate in on-call rotations and respond to security incidents with decisive action and technical expertise • Document system architecture, design decisions, and operational procedures to ensure organizational knowledge retention • Stay current with emerging security trends, authentication technologies, and industry compliance standards • Contribute to the evaluation and integration of third-party identity management tools and services
• Design and implement agentic workflows that materially reduce delivery time and cognitive load • Build reusable accelerators, templates, and shared services for engineers, product managers, designers, and analysts • Apply orchestration tools (LangChain, LangGraph, LangSmith, MCPs, n8n) with judgment—knowing where agents add leverage and where simpler solutions win • Define and evangelize AI-first development practices across teams • Leverage AI-enabled development environments (Cursor, Windsurf) and establish best practices for human + AI collaboration • Drive measurable step-changes in team velocity and consistency • Architect and Build LLM- and ML-powered solutions supporting digital journeys, call-center workflows, decisioning, and personalization • Develop end-to-end systems using Python, JavaScript/TypeScript (optionally Go) • Partner with Data Science to integrate generative AI with traditional ML (classification, regression) • Build AI-enabled interfaces using modern web stacks (React, Next.js, TypeScript) • Ensure scalability, reliability, security, and observability • Design modular, reusable AI systems that scale across clients and use cases • Build and operate production LLM systems, including RAG and agent-based architectures • Use Databricks for AI development (Spark, Delta Lake, MLflow) • Apply strong engineering discipline: Git workflows, code reviews, TDD, CI/CD • Mentor engineers and shape shared standards, patterns, and documentation




