Staff Software Engineer, Identity & Authorization
Remote • Foster City, CA • FullTime
Posted 2d ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Replit is seeking a Staff Software Engineer to join the Product Platform team, specifically focusing on Identity & Authorization. This role is crucial for building and operating the systems that protect critical interactions across Replit's platform, including how people, agents, sandboxes, and services prove their identity and permissions. The work is high-leverage, ensuring that clear, reliable, and easy-to-adopt identity and policy systems enable all other teams to move faster and more securely. The team values curiosity, clear thinking, and collaborative, open work, prioritizing reasoning and building skills.
Responsibilities
- Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations.
- Evolve enterprise roles, groups, app access, entitlements, and workspace policy.
- Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS.
- Threat-model delegation, confused-deputy risks, and cross-tenant movement, ensuring secure, fail-closed behavior is the default.
- Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans.
- Own the SLOs, incidents, and operational health of the systems shipped.
- Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to translate product requirements into shared platform primitives.
- Research and develop innovative approaches to authorization in the agentic world.
Requirements
- Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability.
- Depth in authentication, authorization, or identity systems (e.g., OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines).
- Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling.
- Experience migrating security-sensitive systems without breaking callers, using approaches like typed contracts, shadow evaluation, and staged enforcement.
- Fluent in at least one production backend stack (TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate are used).
- Ability to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability.
Benefits
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office & US Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)