Jobgether
Staff Software Engineer, Identity & Access - AI Platform
- Compensation
- $220K–$260K / yr
- From job posting
- Location
- CA
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Staff
- Posted
- 29 September 2026 (yesterday)
Checked yesterdayApplications go to the employer, never to RoleSprint
About this role
Accountabilities • Own the technical direction for authentication (AuthN), authorization (AuthZ), and OBO delegation across agentic data and cloud platforms.
• Define which emerging identity and agent-authorization patterns to adopt, adapt, or deliberately avoid as standards evolve.
• Design, implement, and productionize identity infrastructure, including OAuth 2.1 authorization services, token vaults, delegated tool-access flows, and cryptographic delegation models.
• Build mechanisms that allow agents to act on behalf of humans or other agents with a verifiable and auditable chain of authority.
• Ensure identity systems integrate effectively with enterprise identity providers such as Okta, Microsoft Entra, Ping, and similar platforms.
• Partner with engineering, security, and product teams to validate identity and delegation architectures against real-world enterprise security requirements.
• Represent the technical approach in customer security discussions, technical documentation, and relevant industry or standards conversations.
• Drive initiatives through production delivery, measuring success through reliable, secure, customer-ready systems rather than architecture proposals alone.
• Mentor engineers across multiple teams and raise organizational capability in identity, access management, and delegation without formal management authority.
• Track initiative progress, surface systemic challenges, communicate risks, and develop contingency and mitigation plans.
• Contribute to strategic engineering discussions with peers and leadership to help shape technical direction and the broader engineering environment.
Requirements
• 10+ years of software development and delivery experience, with deep hands-on expertise in authentication, authorization, identity, or related security infrastructure.
• Production experience with OAuth 2.0/2.1, OIDC, token exchange, delegation patterns, or technologies such as RFC 8693 and OBO flows.
• Practical experience operating authorization servers, token-management infrastructure, or comparable identity systems at scale.
• Strong understanding of emerging agent identity and authorization patterns, including MCP authentication, A2A, and cross-application access or token-exchange approaches.
• Experience designing identity systems that federate with enterprise identity providers rather than replacing them.
• Background working with security-conscious or regulated enterprise environments where identity and access decisions are subject to customer security review.
• Demonstrated ability to establish technical direction across multiple engineering teams or organizations as an individual contributor.
• Strong experience influencing through technical proposals, RFCs, design documentation, code, and collaboration rather than organizational authority.
• Excellent written and verbal communication skills, with the ability to explain sophisticated identity and delegation concepts to engineers, security professionals, customers, and other stakeholders.
• Comfortable working independently within a globally distributed engineering organization and collaborating openly through tools such as GitHub.
• Self-directed, accountable, pragmatic, and comfortable operating in a fast-growing environment where technical decisions may need to be made before industry standards fully converge.
• Preferred experience includes building or operating OAuth 2.1/OIDC authorization infrastructure, working directly with agent-specific identity protocols, contributing to identity or OAuth standards efforts, or holding previous Staff/Principal-level IC responsibilities.
Benefits
• U.S. base salary range of $220,000–$260,000 , with individual compensation determined by role, level, location, experience, skills, education, and training.
• Remote work opportunity for candidates in the Canada; the broader organization operates as a globally distributed team.
• High-autonomy Staff-level individual contributor role with significant technical ownership and cross-functional influence.
• Opportunity to work on emerging identity, authorization, and agentic AI infrastructure where technical standards are actively developing.
• People-first culture centered on trust, transparency, communication, and kindness.
• Access to modern AI tools and a budget intended to support their practical use.
• Opportunities to mentor engineers and shape technical practices across multiple engineering organizations.
• Collaborative environment with engineering, security, product, and customer-facing teams.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- CA
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 29 September 2026, last checked yesterday. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.