# Staff Software Engineer, Identity & Authorization
**Company:** [Replit](https://scaleengineer.com/companies/replit)
Join Replit's Product Platform team as a Staff Software Engineer specializing in Identity & Authorization. You'll design and operate security-critical systems that enable authentication, authorization, and workload identity across Replit's agentic platform, serving millions of users globally. This role requires deep expertise in distributed systems security, OAuth 2.0/OIDC, policy engines, and multi-tenant architectures, with a focus on building horizontal platform primitives that unblock product teams.
**Role:** Staff Software Engineer
**Seniority:** Staff
**Locations:** Foster City, CA
**Salary:** 250000–375000 USD
[Apply](https://jobs.ashbyhq.com/replit/790afe73-238a-489c-875e-ac4e15780112)
Canonical: https://scaleengineer.com/jobs/replit/staff-software-engineer-identity-authorization
---
## Responsibilities

- Design Central Authorization Systems: Design and operate typed authorization interfaces supporting principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations. Establish robust authorization patterns that enable product teams to consistently express security policy across web, mobile, Agent, and internal service contexts without rebuilding controls.
- Architect Agentic Delegation: Build extensible delegation foundations where the user remains the subject while the Agent acts as the authenticated actor. Implement continuous validation mechanisms and dynamic permission envelopes that evolve as long-running work progresses, ensuring Agent can operate securely without broad or long-lived credentials.
- Operate Security Token Service and Workload Identity: Build and operate Replit's Security Token Service and workload identity infrastructure using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mutual TLS (mTLS). Ensure secure service-to-service communication while maintaining high reliability and observability across the distributed architecture.
- Conduct Threat Modeling and Security Architecture: Perform comprehensive threat modeling on delegation patterns, confused-deputy risks, and cross-tenant movement vectors. Design fail-closed security behavior as the default, ensuring multi-tenant isolation and least privilege principles are embedded throughout the system design.
- Execute Production Migrations with Minimal Disruption: Lead compatible migrations of security-sensitive systems using shadow evaluation, feature gates, telemetry collection, and rollback contingencies. Own SLOs, incident response, and operational health for shipped systems, ensuring zero-downtime transitions that maintain product stability.
- Cross-Functional Platform Collaboration: Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to translate product requirements into shared platform primitives. Drive consensus on authorization contracts and security policies that reduce engineering friction across Replit's product organization.
- Innovate Agentic Authorization Approaches: Research and develop novel approaches to authentication and authorization challenges unique to agentic software creation. Evaluate emerging identity patterns and policy frameworks that can address future product needs while maintaining security and performance.
- Evolve Enterprise Access Control: Develop and enhance enterprise roles, groups, workspace policy, and app-level access grants. Balance simplicity for straightforward use cases with expressiveness for complex organizational structures, enabling self-serve access control for enterprise administrators.

## Requirements

### education

- {"name":"Computer Science Foundation","description":"Bachelor's degree in Computer Science, Computer Engineering, or equivalent practical experience demonstrating systematic problem-solving and foundational CS knowledge. Equivalent industry experience building complex systems is valued equally."}
- {"name":"Security Fundamentals Knowledge","description":"Solid grasp of cryptographic primitives, public key infrastructure (PKI), token-based authentication, and secure communication protocols. Continuous learning about evolving security threats and defense mechanisms is essential."}

### technical

- {"name":"Production Backend Systems Experience","description":"Demonstrated expertise shipping and operating security-sensitive backend or distributed systems in production environments. Deep proficiency with reliability engineering, performance optimization, incident response, and observability tooling."}
- {"name":"Authentication and Authorization Depth","description":"Substantial hands-on experience with OAuth 2.0, OpenID Connect (OIDC), JSON Web Tokens (JWT), mutual TLS (mTLS), or identity federation systems. Familiarity with authorization models including RBAC, ReBAC, PBAC, Zanzibar-style frameworks, Macaroons, Biscuits, or Cedar policy languages. Prior experience with multiple approaches is advantageous but not required."}
- {"name":"Multi-Tenant Security Architecture","description":"Strong understanding of multi-tenant system design, tenant isolation patterns, least privilege enforcement, delegation mechanisms, privilege attenuation strategies, auditability requirements, and threat modeling methodologies specific to shared infrastructure."}
- {"name":"Security-Sensitive System Migration","description":"Proven experience migrating authentication or authorization systems without disrupting existing callers. Familiarity with migration strategies including typed contract negotiation, shadow evaluation patterns, and staged enforcement rollouts in production environments."}
- {"name":"Production Backend Stack Proficiency","description":"Fluent mastery of at least one modern production backend technology stack. Replit's core systems utilize TypeScript, Go, Rust, PostgreSQL, gRPC/Protocol Buffers, Kubernetes orchestration, Envoy proxy, and Restate stateful services. Strong foundation in at least one language with willingness to work across the polyglot stack."}
- {"name":"Distributed Systems Fundamentals","description":"Deep understanding of distributed systems concepts including consensus mechanisms, eventual consistency models, failure modes, network partitions, and their implications for security and reliability in identity and authorization services."}

### experience

- {"name":"Senior-Level System Design","description":"Minimum 8-10 years of software engineering experience with at least 5+ years specializing in backend systems, distributed infrastructure, or platform engineering. Track record of owning architectural decisions for complex, production-grade systems serving significant scale."}
- {"name":"Security Systems Specialization","description":"Minimum 3-5 years of focused experience in identity, authentication, authorization, or security infrastructure. Prior contributions to security-critical systems that handle sensitive operations and require rigorous reliability standards."}
- {"name":"Leadership and Communication","description":"Demonstrated ability to communicate complex tradeoffs across security, reliability, latency, product experience, delivery velocity, and long-term maintainability. Experience influencing architectural decisions and building consensus across teams on technical direction."}

## Skills

### required

- {"name":"OAuth 2.0 and OpenID Connect (OIDC)","description":"Advanced proficiency in OAuth 2.0 flows, token exchange mechanisms, and OpenID Connect protocols for federated identity. Understanding of token lifecycle management, scope-based access control, and integration with modern identity providers."}
- {"name":"JWT and Token Design","description":"Expert-level knowledge of JSON Web Token (JWT) structure, cryptographic signing, token claims design, revocation strategies, and refresh token patterns. Experience designing tokens that balance expressiveness with security constraints."}
- {"name":"Policy Engines and Authorization Frameworks","description":"Hands-on experience with policy-as-code engines, attribute-based access control (ABAC), or role-based access control (RBAC) systems. Familiarity with policy languages like Cedar, Rego, or similar frameworks for expressing complex authorization logic."}
- {"name":"Go or TypeScript Backend Development","description":"Production-level proficiency in Go, TypeScript, or both. Ability to build high-performance, concurrent services with strong error handling, clean architecture, and operational observability."}
- {"name":"PostgreSQL Database Design","description":"Advanced SQL and PostgreSQL expertise including schema design, query optimization, transaction management, and operational concerns for high-throughput identity systems. Understanding of permission storage and query patterns at scale."}
- {"name":"gRPC and Protocol Buffers","description":"Proficiency with gRPC framework and Protocol Buffers for defining typed service contracts. Experience building and maintaining contract-based APIs that enable backward compatibility and schema evolution."}
- {"name":"Kubernetes and Container Orchestration","description":"Strong operational experience deploying, scaling, and managing services on Kubernetes. Understanding of network policies, RBAC within Kubernetes, service mesh concepts, and observability integration."}
- {"name":"mTLS and Service Mesh","description":"Deep understanding of mutual TLS (mTLS) for encrypting service-to-service communication. Experience with service mesh technologies like Envoy for enforcing authentication policies, traffic management, and security controls."}
- {"name":"Threat Modeling and Security Design","description":"Systematic approach to threat identification, risk assessment, and mitigation design. Familiarity with threat modeling frameworks, OWASP principles, and secure-by-default architecture patterns specific to identity systems."}
- {"name":"Observability and Incident Response","description":"Expertise in structured logging, distributed tracing, metrics collection, and alerting for production systems. Experience on-call for security-sensitive services, incident investigation, and root cause analysis."}

### preferred

- {"name":"SPIFFE/SPIRE Workload Identity","description":"Experience with SPIFFE (Secure Production Identity Framework for Everyone) and SPIRE for managing cryptographic identities in production environments. Understanding of workload SVIDs and secure identity provisioning."}
- {"name":"ReBAC and Zanzibar-Style Authorization","description":"Familiarity with relationship-based access control (ReBAC) patterns popularized by Google's Zanzibar system. Understanding of efficient authorization checks at massive scale using relationship graphs."}
- {"name":"Macaroons and Capabilities-Based Security","description":"Knowledge of capability-based security models, Macaroon tokens, or Biscuit authorization tokens. Understanding of how capabilities enable privilege attenuation and delegation without central coordination."}
- {"name":"Rust Backend Development","description":"Production experience building high-performance services in Rust, particularly for security-sensitive or performance-critical components. Comfort with Rust's ownership model and type system for preventing certain classes of vulnerabilities."}
- {"name":"Restate Stateful Services","description":"Experience with Restate or similar frameworks for building durable, stateful services with built-in recovery semantics. Understanding of how durable execution enables long-running processes without state loss."}
- {"name":"Enterprise Directory Integration","description":"Experience integrating with enterprise identity providers, LDAP/Active Directory, or SSO systems. Understanding of enterprise access control requirements, compliance constraints, and group synchronization patterns."}
- {"name":"Multi-Tenant SaaS Architecture","description":"Prior experience designing and operating multi-tenant SaaS platforms with stringent isolation and security requirements. Understanding of data residency, compliance, and tenant-specific configurations."}
- {"name":"Agent or AI Systems","description":"Familiarity with agentic AI systems, orchestration frameworks, or autonomous systems. Understanding of long-running workflows and the unique identity and authorization challenges they present."}
- {"name":"Feature Flag and Configuration Management","description":"Experience implementing feature flags, shadow evaluation, or gradual rollout systems for managing breaking changes in production. Understanding of telemetry-driven decision making for staged rollouts."}

## Tech stack

### tools

- {"name":"Kubernetes","description":"Container orchestration platform for deploying, scaling, and managing identity services. Enables declarative infrastructure, automated failover, and resource management for high-availability systems."}
- {"name":"Envoy Proxy","description":"Layer 7 proxy and data plane for service mesh architecture. Used for enforcing mTLS, managing traffic policies, and implementing authentication requirements at the network layer."}
- {"name":"Docker","description":"Containerization platform for packaging services with dependencies, enabling consistent deployment across development, staging, and production environments."}
- {"name":"Git and GitHub","description":"Version control and collaboration platform. Essential for managing infrastructure-as-code, policy definitions, and coordinating changes across distributed engineering teams."}

### others

- {"name":"Restate Stateful Services","description":"Emerging framework for building durable, stateful backend services with built-in recovery semantics. Used for implementing long-running delegation flows and reliable work processing."}
- {"name":"Structured Logging and Tracing","description":"Distributed tracing and structured logging infrastructure for observability. Critical for debugging complex authorization flows and investigating security incidents."}
- {"name":"mTLS and TLS Termination","description":"Mutual TLS for encrypting and authenticating service-to-service communication. Foundational security technology for ensuring only authorized services can communicate."}
- {"name":"Policy-as-Code Engines","description":"Tools and frameworks for expressing authorization policies declaratively. Enables auditable, testable, and versionable security policies across product teams."}

### databases

- {"name":"PostgreSQL","description":"Primary relational database for identity and authorization data. Used for storing principals, permissions, policy rules, audit logs, and transactional consistency requirements of security-sensitive operations."}
- {"name":"Redis","description":"High-speed in-memory cache for token validation, permission caching, and real-time authorization decision optimization. Critical for achieving authorization latency SLOs."}

### languages

- {"name":"TypeScript","description":"Primary backend language used across Replit services for building scalable, type-safe backend systems with modern async/await patterns and strong tooling support."}
- {"name":"Go","description":"High-performance systems language used for latency-sensitive components, concurrent processing, and service-to-service communication with strong standard library support."}
- {"name":"Rust","description":"Systems programming language used for performance-critical security components, leveraging strong type system and memory safety guarantees to prevent entire classes of vulnerabilities."}
- {"name":"Protocol Buffers (Protobuf)","description":"IDL and serialization format for defining typed service contracts, enabling backward compatibility and language-agnostic service definitions across polyglot backend architecture."}

### frameworks

- {"name":"gRPC","description":"High-performance RPC framework built on HTTP/2 for service-to-service communication. Enables strongly-typed contracts and efficient binary serialization for identity and authorization APIs."}
- {"name":"OAuth 2.0 / OIDC","description":"Industry-standard protocols for delegated authorization and federated identity. Core protocols that Replit's identity systems build upon and extend for agentic use cases."}
- {"name":"JWT/OIDC","description":"Token-based authentication standards enabling stateless identity representation, especially important for distributed systems and cross-platform authorization."}
- {"name":"SPIFFE/SPIRE","description":"Production-grade framework for managing cryptographic workload identity at scale. Provides secure identity provisioning and mTLS orchestration for service mesh environments."}

## Benefits

### benefits

## Compensation

- **max:** 0
- **min:** 0
- **currency:** 
- **stockOptions:** false

## Interview process

### steps

## Full description
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

## About the Team

Product Platform builds and owns the shared foundations the rest of Replit is built on, spanning the full stack so every other team can ship features safely and quickly.

Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across Replit's web product, Agent, enterprise controls, and internal services.

Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls.

We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here.

## About the Role

As a **Software Engineer**, you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity.

The work is guided by a few simple questions:

* **Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf?**
* **Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services?**
* **Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions?**
* **Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials?**
* **Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?**

## What you'll do

* Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations
* Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible
* Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS
* Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default
* Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship
* Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives
* Research and develop new innovative approaches to Authx in the Agentic world

## Areas you might work in

* **Authorization policy**: evolve Replit's central policy decision point and migrate fragmented authorization checks to its typed contract.
* **Agent delegation**: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs.
* **Enterprise access control**: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations.
* **Agent and service identity and reliability**: operate the token and workload-identity systems that protect service-to-service traffic.

## Required skills and experience

* Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability
* Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item
* Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling
* Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement
* Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate
* Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

If you're excited about this role but don't meet every requirement, we still encourage you to apply.

**Full-Time Employee Benefits Include:**

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (_US Only_)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (_In-Office & US Only_)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (_In-Office Only_)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (_In-Office Only_)

**Want to learn more about what we are up to?**

* [Self-driving Company](https://replit.com/blog/self-driving-company)
* [Replit Agent at Scale](https://replit.com/blog/evaluating-and-improving-agent-at-scale)
* [AI Adoption](https://replit.com/blog/ai-adoption)
* [Build Open-Source Apps](https://replit.com/build/open-source-app-builder)

**Interviewing + Culture at Replit**

* [Operating Principles](https://blog.replit.com/operating-principles)
* [Reasons not to work at Replit](https://blog.replit.com/reasons-not-to-join-replit)

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
