SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Engineer, Agentic Identity

Baselayer - San Francisco, CA, United States - In-office - posted 2026-08-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Baselayer is rebuilding the identity infrastructure layer for American financial institutions. The company has built the most complete business graph in America, fusing public records, IRS data, sanctions lists, web signals, and fraud telemetry from 2,200+ financial institutions to resolve any business and its human stakeholders in milliseconds. With 98% match rates achieved in under two years (versus legacy credit bureaus at 60% over 50 years), Baselayer is trusted by over 20% of US financial institutions including FIS, Rho, and Socure. The company is now expanding beyond finance into gig platforms, marketplaces, AI companies, and commerce infrastructure. The core technical challenge involves real-time entity resolution at unprecedented scale—a graph AI problem layered with retrieval and fraud-modeling challenges. You will own a meaningful surface of the KYA (Know Your Agent) substrate—a cryptographic identity layer designed to replace self-assertion with third-party-issued credentials as AI agents increasingly act on behalf of people and businesses. This addresses a critical gap: today's identity models (self-asserted API keys, third-party cookies, pixel trackers) break when the actor is an agent. Your responsibilities include: - Building and maintaining the runtime issuer/mint: OAuth Token Exchange (RFC 8693), JWS credentials (RFC 7515/7519, SD-JWT-VC), and Merkle audit logs with real-time revocation - Owning the wire format and claim registry: JWT profiles, verification_level/verification_method enums, and regulatory crosswalks (eIDAS/NIST IAL/FATF CDD) - Implementing sub-millisecond JWS verification and Web Bot Auth signature checks (RFC 9421) at the HTTP edge for CDNs, merchants, and publisher paywalls - Building and maintaining Passport—the user's cloud-resident principal account with canonical handle, KYC/KYB records, authorized-operators list, audit feed, and authenticator binding - Developing operator integration: embedded KYB onboarding within OAuth 2.0 consent flows, per-operator opt-in, and webhook delivery via Svix - Working across a Python 3.13 monorepo (FastAPI, Cloud Tasks, Cloud Run, SQLModel/SQLAlchemy) and Go for performance-critical components You'll join a small, high-ownership team where the data moat is defensible, research problems are open, and infrastructure you build becomes load-bearing. There is minimal process between idea and shipping. The hardest problems ahead include graph embeddings, fraud propagation models across business networks, real-time traversal at sub-100ms latency, and expanding the identity layer beyond finance. Minimum requirements: shipped systems where cryptographic correctness was load-bearing (OAuth/OIDC IdP, token issuer, signing service, HSM-backed signer, passkey/WebAuthn); fluency in Python and Go; ability to read RFCs as primary sources and hold informed opinions on cryptographic details; deep understanding of identity vs. authorization distinctions; production experience with async Python on Postgres including migration safety and observability. What sets you apart: verifiable credentials/SSI/DID work (SD-JWT-VC, OID4VC, W3C VC stack); Certificate Transparency, Trillian, or append-only-log experience; KYC/KYB pipeline experience; edge/CDN engineering (Cloudflare Workers, Fastly Compute, Envoy, mTLS); familiarity with payment specs (AP2, x402, MPP, UCP, Mastercard VI) and how identity rides alongside mandate.

Similar roles