Description
This position is listed on behalf of a partner company, who manages all applications and next steps.
Our partner is looking for a Staff Software Engineer, Identity & Access - AI Platform based in United States.
This is a high-autonomy staff-level engineering role focused on defining and building identity and access foundations for enterprise AI platforms.
You will own the technical direction for authentication, authorization, and on-behalf-of (OBO) delegation across agentic data and cloud environments.
The role sits at the intersection of identity infrastructure, enterprise security, and rapidly evolving agentic AI standards.
You will make architectural decisions in areas where industry conventions are still emerging, while remaining deeply hands-on in production engineering.
Success will depend on your ability to influence multiple engineering teams without formal authority and translate complex identity concepts for diverse audiences.
You will work closely with engineering, security, product, and enterprise stakeholders to deliver systems that can withstand rigorous customer security requirements.
The environment is globally distributed, startup-oriented, collaborative, and designed for engineers who take ownership from strategy through production delivery.
Accountabilities
Own the technical direction for authentication (AuthN), authorization (AuthZ), and OBO delegation across agentic data and cloud platforms.
Define which emerging identity and agent-authorization patterns to adopt, adapt, or deliberately avoid as standards evolve.
Design, implement, and productionize identity infrastructure, including OAuth 2.1 authorization services, token vaults, delegated tool-access flows, and cryptographic delegation models.
Build mechanisms that allow agents to act on behalf of humans or other agents with a verifiable and auditable chain of authority.
Ensure identity systems integrate effectively with enterprise identity providers such as Okta, Microsoft Entra, Ping, and similar platforms.
Partner with engineering, security, and product teams to validate identity and delegation architectures against real-world enterprise security requirements.
Represent the technical approach in customer security discussions, technical documentation, and relevant industry or standards conversations.
Drive initiatives through production delivery, measuring success through reliable, secure, customer-ready systems rather than architecture proposals alone.
Mentor engineers across multiple teams and raise organizational capability in identity, access management, and delegation without formal management authority.
Track initiative progress, surface systemic challenges, communicate risks, and develop contingency and mitigation plans.
Contribute to strategic engineering discussions with peers and leadership to help shape technical direction and the broader engineering environment.
Requirements
10+ years of software development and delivery experience, with deep hands-on expertise in authentication, authorization, identity, or related security infrastructure.
Production experience with OAuth 2.0/2.1, OIDC, token exchange, delegation patterns, or technologies such as RFC 8693 and OBO flows.
Practical experience operating authorization servers, token-management infrastructure, or comparable identity systems at scale.
Strong understanding of emerging agent identity and authorization patterns, including MCP authentication, A2A, and cross-application access or token-exchange approaches.
Experience designing identity systems that federate with enterprise identity providers rather than replacing them.
Background working with security-conscious or regulated enterprise environments where identity and access decisions are subject to customer security review.
Demonstrated ability to establish technical direction across multiple engineering teams or organizations as an individual contributor.
Strong experience influencing through technical proposals, RFCs, design documentation, code, and collaboration rather than organizational authority.
Excellent written and verbal communication skills, with the ability to explain sophisticated identity and delegation concepts to engineers, security professionals, customers, and other stakeholders.
Comfortable working independently within a globally distributed engineering organization and collaborating openly through tools such as GitHub.
Self-directed, accountable, pragmatic, and comfortable operating in a fast-growing environment where technical decisions may need to be made before industry standards fully converge.
Preferred experience includes building or operating OAuth 2.1/OIDC authorization infrastructure, working directly with agent-specific identity protocols, contributing to identity or OAuth standards efforts, or holding previous Staff/Principal-level IC responsibilities.
Benefits
U.S.
base salary range of $220,000–$260,000, with individual compensation determined by role, level, location, experience, skills, education, and training.
Remote work opportunity for candidates in the United States; the broader organization operates as a globally distributed team.
High-autonomy Staff-level individual contributor role with significant technical ownership and cross-functional influence.
Opportunity to work on emerging identity, authorization, and agentic AI infrastructure where technical standards are actively developing.
People-first culture centered on trust, transparency, communication, and kindness.
Access to modern AI tools and a budget intended to support their practical use.
Opportunities to mentor engineers and shape technical practices across multiple engineering organizations.
Collaborative environment with engineering, security, product, and customer-facing teams.
How Jobgether Works
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements.
Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company.
The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer.
This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR).
You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information.
These tools assist our recruitment team but do not replace human judgment.
Final hiring decisions are ultimately made by humans.
If you would like more information about how your data is processed, please contact us.