SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Render is a modern cloud platform for developers building AI-native, full-stack applications. The company has raised $257M in funding (Series C in Feb 2026) and serves over 6 million developers worldwide.
You'll join the Expansion team as a Software Engineer focused on authentication, authorization, and access management. This is a full-stack role where you'll design and ship authentication and authorization systems for users, agents, and services—including SSO, RBAC, audit logging, scoped credentials, and SCIM provisioning.
Key responsibilities include:
- Design and ship authentication and authorization systems across Render's platform, including credential scoping, SSO, SCIM provisioning, and fine-grained permission models
- Evolve Render's authorization model toward clear permissions and scopes for applications, environments, projects, and other resources
- Own the security experience across the full stack—from user-facing interfaces through APIs, data models, and backend systems
- Build controls and audit trails that help customers define, enforce, and understand how people, services, and agents act within their systems
- Design shared auth APIs and primitives, then drive adoption across Product, Design, Security, and other teams
- Operate authentication and authorization systems in production, including observability, safe rollouts, incident response, and on-call responsibilities
You'll need 6+ years of experience shipping and operating production systems, with a track record of building customer-facing authentication or authorization features. You should understand how security choices shape product experience and be comfortable with API, data-model, caching, and migration tradeoffs. The role values systems thinking and the ability to balance security and product tradeoffs.
Nice-to-haves include hands-on experience with OAuth, OpenID Connect, SAML, SCIM, JWTs, multi-tenant authorization models (RBAC, ABAC, ReBAC), workload identity, secrets management, developer platform or cloud infrastructure experience, and familiarity with compliance frameworks like SOC 2 or ISO 27001.