About this role
Lead the design and engineering of a cloud-agnostic Identity and Authorization Platform that secures users, services, APIs, AI agents, and data across a multi-tenant SaaS platform.
Unlike traditional IAM roles, this position focuses heavily on authorization architecture.
Responsibilities
- Lead architecture and implementation of:
- Authentication
- Authorization
- Identity federation
- Fine-grained access control
- Own architecture for: RBAC
- ReBAC
- ABAC
- ACL
- Policy engines
- Relationship graphs
- Design authorization for: Web applications
- Mobile
- APIs
- Microservices
- AI Gateway
- Agent runtime
- MCP tools
- Knowledge Graph
- Vector stores
- Design authorization decision architecture: PEP ↓
- PDP ↓
- Policy Store ↓
- Relationship Store↓
- Decision
- Lead adoption of: OpenFGA / SpiceDB
- Cedar
- Open Policy Agent (OPA)
- Zanzibar concepts
- Work with platform teams on: API Gateway
- AI Gateway
- Kubernetes
- Service Mesh
- mTLS
Essential experience
- 10+ years engineering
- 5+ years security platform experience
- Demonstrable experience building authorization engines using: RBAC
- ReBAC
- ABAC
- ACL
- Experience designing authorization for: Multi-tenant SaaS
- Microservices
- APIs
- Experience with: OAuth2
- OpenID Connect
- JWT
- SAML
- Strong distributed systems experience
Nice to have
- Google Zanzibar
- OpenFGA
- SpiceDB
- OPA
- Cedar
- Envoy
- Istio
- SPIFFE/SPIRE
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.