SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
AlphaSense is a market intelligence platform trusted by over 6,000 enterprise customers, including a majority of the S&P 500. The company delivers AI-driven insights from public and private content including equity research, company filings, event transcripts, and expert calls. Founded in 2011 and headquartered in New York, AlphaSense has 2,000+ employees across offices in the US, UK, Finland, India, Singapore, Canada, and Ireland.
The User Management team owns the complete identity lifecycle at AlphaSense—from user creation and provisioning through identity management, authentication, and authorization. This is a platform engineering team, not a product team; you'll build identity and access infrastructure that other engineering teams depend on, rather than shipping user-facing features. The team is well-established, senior-level, and based in Helsinki, deliberately scaling toward a true platform model where authentication and authorization systems can be safely self-served across the company.
As a Senior Software Engineer, you'll take deep technical ownership of complex identity and access problems, working across all three pillars: user management, authentication, and authorization. You'll design systems built to scale with a constantly growing customer base and user population. Security is core to this role—you'll partner closely with security teams on secure-by-design systems in a SOC2 and GDPR-governed environment.
You'll design and evolve the authorization platform (RBAC/ABAC/ReBAC), build and operate authentication systems at scale, and manage the user provisioning and lifecycle infrastructure. You're expected to execute independently on complex technical problems while contributing to the team's broader roadmap.
Required experience: Java 2.x, Spring Boot 3.x, WebFlux, Maven; SQL, GraphQL, gRPC, REST; AWS/GCP, Kubernetes, Helm; identity protocols including RBAC/ABAC/ReBAC, OAuth 2.0, OIDC, JWT, SAML 2.0, enterprise SSO federation, and SCIM; event-driven architecture and automated testing practices.
Nice-to-have: Auth0, SpiceDB/Zanzibar-style authorization systems, Apollo Federation, OpenTelemetry, SOC2/GDPR operational experience.