SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 162,300 - 301,400 / annual
Veeam is seeking a Senior Engineer – Access Entitlements to design and scale systems that discover, normalize, and reason about access across customers' entire data estates. You will build connectors, pipelines, and graph models that transform millions of raw permission grants into an accurate, queryable picture of access across billions of files and identities, powering least-privilege analysis, access certification, and risk detection for enterprise customers.
Key Responsibilities:
• Entitlement Scanning: Build and extend connectors that enumerate identities (users, groups, service accounts, computers) and resource-level permissions (ACLs, role assignments, sharing links) across on-prem and SaaS data sources, handling per-connector quirks like SID resolution, inheritance breakage, and nested group membership.
• Scale & Concurrency: Design entitlement pipelines that safely parallelize across large tenants—correctly handling shared state, batching, and checkpointing so a scan of hundreds of thousands of principals and files can pause, resume, and recover without data loss or duplication.
• Data Modeling: Own the mapping from raw connector output to normalized entitlement records, and from those records into the identity graph—designing node/edge structures that represent principals, resources, and access grants (including sharing links and group-inherited access) in a way that supports fast traversal at scale.
• Multi-Store Architecture: Work across the full data path—Elasticsearch for search-driven access, Databricks/Delta for large-scale analytical joins, and a Neptune-backed graph for relationship queries—making deliberate tradeoffs about what gets synced where, and keeping those stores consistent as data volume grows.
• Entitlement-Activity Correlation: Build pipelines that join static entitlements against observed activity logs to answer "who can access this, and who actually does"—the core signal behind over-permission detection and access-risk scoring.
• Reliability & Correctness: Instrument and test for failure modes unique to entitlement data—partial scans, malformed ACLs, race conditions in concurrent principal writes, and inconsistent state between graph and source-of-truth stores.
Requirements:
• 6+ years of professional software engineering experience, with meaningful time spent on identity/access systems, security data pipelines, or large-scale distributed data processing.
• Strong Go, Java, or Python skills, with direct experience writing concurrent/parallel data pipelines (goroutines, worker pools, or equivalent) and reasoning about race conditions and shared state.
• Experience with graph databases or graph query languages (Gremlin, Cypher, or similar) and modeling relationship-heavy data.
• Familiarity with Elasticsearch/OpenSearch and at least one large-scale analytical store (Databricks, Snowflake, BigQuery, Redshift).
• Understanding of identity and access concepts—RBAC, ACLs, group membership.
Bonus Skills:
• Experience with Microsoft Graph API, SharePoint REST APIs, or Active Directory/LDAP-based identity systems.
• Familiarity with AWS Neptune, TinkerPop/Gremlin, or other graph-native databases at production scale.
• Background in DSPM, CIEM, IAM governance, or data security posture tooling.
• Experience designing multi-tenant systems with per-tenant data isolation across search, analytical, and graph stores.