SlipstreamJobsFresh Startup & VC-Backed Jobs

Software Engineer - Identity and Authorization

Baseten - San Francisco, CA, USA - In-office - posted 2026-09-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Baseten powers mission-critical inference for leading AI companies including Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, and Writer. This is a founding role for the identity and authorization team within enterprise engineering, reporting into the broader platform infrastructure organization. You will own the identity and access layer of the Baseten platform, including the authorization model, credential systems, and admin experiences that enterprise IT teams use to govern access for organizations like Harvey, HubSpot, and Notion. You'll design and build Baseten's fine-grained authorization system from the ground up to support current customer workflows while enabling cleaner, more precise access management as the platform scales. Key responsibilities include: - Leading identity and authorization projects from problem definition and technical design through implementation, launch, and iteration - Designing authorization and credential models that support critical workflows today and can be safely extended as the platform evolves - Partnering with product, design, and customer-facing teams to translate enterprise security requirements into durable technical solutions - Establishing engineering practices for quality, security, observability, and operational ownership - Providing technical leadership and mentorship as the team grows Example initiatives include fine-grained authorization for users, service accounts, and agentic workloads; programmatic authentication with short-lived, workload-based credentials; agent credentials with least-privilege access; enterprise identity lifecycle management including SSO and SCIM provisioning; and centralized admin controls for visibility and auditability. Authorization at Baseten requires low-latency permission checks at high request volume, consistent contracts across the product suite, and strong security guarantees for mission-critical, highly regulated workloads. Required qualifications: 4-5+ years building production backend systems with hands-on design and implementation of product authorization systems (per-resource permissions, relationship-based access control, policy engines, or fine-grained systems like Zanzibar, OpenFGA, SpiceDB, or Cedar). Demonstrated end-to-end ownership from design through production rollout and iteration. Experience developing and operating multi-tenant systems at scale where authorization checks sit in the request path. Comfort working across the full stack from application code to cloud and Kubernetes infrastructure. Preferred: Python and Go experience; production deployment experience with OpenFGA, SpiceDB, or similar; working knowledge of OAuth, OIDC, and SCIM protocols.

Similar roles