Middle/Senior Backend Engineer

XsollaRussiaOn-siteFull-timeSenior, 5–8 yearsListed 3 days ago

Apply now

About this role

About the project

Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It is not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products, including Xsolla Wallet, Xsolla App, Web Shops, and partner integrations.

Tech Stack:

- Language: Go (idiomatic code, concurrency patterns, performance profiling)

- Databases: PostgreSQL (schema design, query optimization, migrations at scale), MySQL, Redis

- Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency

- Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ

- Infrastructure: Docker, Kubernetes, Nginx

- Identity Stack: Ory ecosystem (Hydra for OAuth2/OIDC, Kratos for identity management) with a custom Auth API orchestrator and plugin architecture

- Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn

- Web Security: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management

- Architecture: Microservices, High Availability design

Key Technical Challenges:

- Building Web2 & Web3 authentication flows (OTP, passkeys, biometrics, wallet-based login)

- Implementing custom auth methods without forking Ory

- SSO without third-party cookies

- Zero-downtime migration from legacy Xsolla Login with bidirectional identity sync

- Geo-distributed data residency via CockroachDB

- High availability and scaling for millions of concurrent users

- SDK development and integration with multiple Xsolla products

Responsibilities

- Develop and maintain backend services for the Xsolla ID platform using Go

- Design and implement OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token introspection, and refresh strategies

- Work with the Ory ecosystem (Hydra, Kratos) and extend the custom Auth API orchestrator and plugin architecture

- Apply web security fundamentals: cookie security, CSRF/XSS protection, secure token storage, TLS, secure session management

- Optimize database queries and ensure high performance under heavy loads (PostgreSQL, MySQL, Redis, CockroachDB)

- Build and maintain microservices architecture with focus on reliability and scalability

- Contribute to zero-downtime migration from legacy Xsolla Login with bidirectional identity sync

- Write clean, well-tested code with comprehensive unit and integration test coverage

- Collaborate with frontend engineers on SDK and widget integration

- Participate in code reviews and contribute to technical documentation

- Support production systems and troubleshoot issues across the authentication stack

QUALIFICATIONS

Required:

- 2+ years of commercial experience with Go

- Strong understanding of PostgreSQL and Redis (query optimization, indexing strategies)

- Working knowledge of OAuth 2.0 / OIDC auth flows (authorization code, client credentials) or strong motivation to learn

- Understanding of web security fundamentals : CSRF, XSS, cookie security, TLS

- Experience with Docker and docker-compose

- Proficiency with Git and collaborative development workflows

- Understanding of Nginx and web server configuration

- Solid experience writing unit tests and maintaining high code quality

- Good English reading skills (technical documentation)

Preferred:

- Understanding of microservices architecture and distributed systems trade-offs (consistency, availability, failure modes)

- Experience with REST API design and documentation ( Swagger/OpenAPI )

- Hands-on experience with CI/CD pipelines

- Familiarity with the Ory ecosystem (Hydra, Kratos, Keto) or similar identity management frameworks

- Knowledge of PKCE , client credentials, device flow, token introspection, and refresh-token strategies

- Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling)

- Experience with NATS , Kafka , or RabbitMQ for event-driven / message-streaming patterns

- Familiarity with Jira for project management

- Understanding of Kubernetes and container orchestration

- Familiarity with compliance requirements relevant to IAM: SOC 2 , ISO 27001 , GDPR data minimization, audit logging

- Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work