Staff Software Engineer, Identity & Authorization

Replit
United States
Workplace: HybridFull timeUSD 250,000 - 375,000 annuallyFunction: Software EngineeringSkills: ["Tradeoff analysis","Clear communication"]

Design, build, and operate identity and authorization systems that protect critical Replit interactions, including Agent acting on behalf of users. Create central authorization with typed principals and explainable decisions, evolve enterprise roles and access policy, and build security token/workload identity using OAuth 2.0, JWT/OIDC, SPIFFE/SPIRE, and mTLS. Threat-model delegation risks, lead secure migrations, own SLOs/incident health, and partner across platform and security teams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Replit
Replit
4 hours ago

Staff Software Engineer, Identity & Authorization

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 40 minutes agoStatus: Live

Job Summary

Design, build, and operate identity and authorization systems that protect critical Replit interactions, including Agent acting on behalf of users. Create central authorization with typed principals and explainable decisions, evolve enterprise roles and access policy, and build security token/workload identity using OAuth 2.0, JWT/OIDC, SPIFFE/SPIRE, and mTLS. Threat-model delegation risks, lead secure migrations, own SLOs/incident health, and partner across platform and security teams.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Software Engineering
Seniority: Mid level

Key Responsibilities

  • •Design and operate central authorization interfaces with typed principals, actions, resources, decisions, and explainable deny reasons.
  • •Evolve enterprise roles, groups, app access, entitlements, and workspace policy, keeping common cases simple.
  • •Build and operate a Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS.
  • •Threat-model delegation risks and enforce secure, fail-closed behavior by default.
  • •Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans; own SLOs, incidents, and operational health.

Pay and Benefits

Salary: USD 250,000 - 375,000 annually
Equity and Bonus:Equity
Perks:Health Insurance401k

Key Requirements

  • •Experience shipping and operating security-sensitive backend or distributed systems in production with reliability, performance, incidents, and observability.
  • •Depth in authentication, authorization, or identity systems (e.g., OAuth 2.0/OIDC, JWT, mTLS, federation, RBAC/ReBAC/PBAC, or policy engines).
  • •Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling.
  • •Experience migrating security-sensitive systems without breaking callers (e.g., typed contracts, shadow evaluation, staged enforcement).
  • •Fluent in at least one production backend stack; systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate.
Experience:Security engineeringDistributed systems
Skills:Tradeoff analysisClear communication
Tech Stack:TypeScriptGoRustPostgresGRPC/ProtobufKubernetesEnvoyRestateOAuth 2.0JWTOIDCSPIFFESPIREMTLSSecurity Token ServiceIdentity FederationRBACReBACPBACZanzibar

Company Brief

Replit
Provides a browser-based integrated development environment (IDE) and collaborative coding platform that lets developers write, run, and deploy code instantly across many languages and frameworks.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn