Search by job, company or skills

Staff Software Engineer

This job is no longer accepting applications

Job Description

This is a build role, not a security-review role. You will write production code, design backend services, and integrate with access-control systems across GCP, Kubernetes, and Kafka. The security background is required because the product you are building is security-critical - mistakes are access breaches or audit failures. Strong bias toward shipping working software over designing perfect systems. Your primary focus for the first six months is the Just-In-Time (JIT) Access Portal: an internal product that becomes the single entry point for elevated access across every system in the platform. After establishing that, you rotate into other engineering areas - contributing to the compliance evidence layer, CI/CD security hardening - expanding your footprint across the broader platform. What You Will Do

First Six Months - JIT Portal Build

  • Own the JIT portal from design through production. Inherit and extend the foundation already established by the existing Staff Engineer.
  • Extend portal coverage to Kafka ACLs via the Kafka admin client; SQL grants via GCP CloudSQL IAM; internal admin UI surfaces.
  • Design and ship the TTL-enforcement mechanism across all backend systems — the hardest engineering problem in this area, because different access-control systems have different revocation semantics.
  • Build the audit log pipeline: access events → Kafka → InfluxDB → Grafana. SOC2 access-control evidence view available to the GRC team on demand.
  • Integrate with the incident tool: emergency break-glass access automatically granted at incident-open and revoked at incident-close.

Next Six Months - Expanding Scope

  • Own the compliance evidence layer: map incidents to SOC2/ISO controls; auto-collect evidence artifacts at incident-close (ticket, post-mortem document, access logs, deployment manifest); generate audit dossiers on demand.
  • Connect the compliance layer to the access-portal audit log and the configuration-management audit log — one continuous evidence trail covering access, configuration change, and incident response.
  • Contribute to CI/CD security hardening: container image signing (Cosign), SBOM generation and storage, External Secrets Operator rollout, tfsec/Checkov in Terraform pipelines, CVE gating in the build pipeline.

Ongoing

  • Contribute to cross-team architecture reviews with a security and identity lens - flag credential handling issues, ACL gaps, and audit-log omissions.
  • Maintain the JIT portal as a production system - it is part of the platform team's on-call rotation.
  • Write and maintain design documents and runbooks for everything you build.

Requirements

What We Are Looking For

  • 8+ years of backend software engineering with a strong identity and access-management focus
  • Has built or substantially contributed to an identity or access platform - not just used IAM tools, but written the code behind access grants, revocations, and audit pipelines
  • Production experience with at least three of: GCP IAM, Kubernetes RBAC, Kafka ACLs, OAuth2/OIDC, SAML 2.0, Google Workspace admin APIs
  • Understanding of SOC2 control requirements from an engineer's perspective - specifically the access-control and change-management control families
  • Strong backend engineering in Java or Go - the portal backend is Java/Spring Boot to match the broader platform stack
  • Comfortable being the primary security engineering expertise in a team without a dedicated security function above you

Nice to Have

  • Experience with zero-trust access architectures or enterprise Privileged Access Management products - understanding their failure modes helps in building our own
  • Background with Cosign, Sigstore, or container image signing infrastructure
  • Familiarity with Erlang or willingness to integrate at an application-gateway layer - Mnesia does not have native ACLs, so enforcement happens at the gateway
  • Experience evaluating commercial JIT tools before deciding to build - familiarity with what Teleport, StrongDM, Britive, or CyberArk do well and where they fall short
  • Has worked in a compliance-adjacent engineering environment where audit evidence is a first-class deliverable

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 150656547

Similar Jobs

Bengaluru, India

Skills:

JavaScalaconcurrencyKafkaKotlinSqlAerospikeSystem DesignRest ApisNoSQL databasesGoCI CD automationperformance scalabilitymicroservices architectureobservability

Bengaluru, India

Skills:

data engineering PrometheusDatadogTerraformPythonJavaNode.jsCloud InfrastructureHelmKubernetesAI-powered developer toolsobservability practicesGoplatform engineeringCI CDGitHub ActionsLLM APIsOpenTelemetrybackend systemsdistributed tracingAI ML integrationSLO SLA-based alertingArgoCDstructured loggingagent-backed workflows

Bengaluru, India

Skills:

LoggingSLAKafkaGcpIncident ManagementAzureKubernetesAWSobservability metricstracingSREPagerDutyRootlyreliability engineeringSLOcontainer orchestration

Bengaluru, India

Skills:

JavaGcpDockerScalaAzureKubernetesAWSGo

Bengaluru, India

Skills:

react.js PostgreSQLPrometheusAWS CloudWatchGrafanaMicroservicesNosqlOctopusTerraformDockerAWSJavaCloudformationSoapRESTSpringbootMachine LearningKubernetesGenAI toolsAWS BedrockCI CDLlmGitHub ActionsNext.jsBIAN architectureClineRest API IntegrationOpenAPI SpecsAiCode CursorRoo

Beware of Scammers

We don’t charge money for job offers