SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kaseya is seeking a Staff Backend Engineer to design and operate core platform services powering Fleet, a comprehensive IT management and automation platform serving Managed Service Providers (MSPs) and internal IT organizations globally. The role focuses on high-reliability backend and platform engineering where correctness, security, scalability, and operational clarity are paramount.
Key responsibilities include building and operating platform services that underpin Fleet's architecture: API gateway, Kafka-based event routing (PSA webhooks and RMM alerts to Temporal workflow triggers), Zitadel integration for machine identity and capability grant management, and ClickHouse-backed immutable audit ledger infrastructure. You will implement the Secret Management and KMS abstraction layer supporting pluggable key encryption key (KEK) backends across AWS KMS, Azure Key Vault, GCP Cloud KMS, and bring-your-own-key (BYOK) options, with envelope encryption via AWS Encryption SDK and per-client cryptographic isolation.
The role includes building the capability grant enforcement pipeline, validating per-workflow, per-client, and per-operation grants issued by Zitadel on every inbound request. You will own the GitOps-based automation catalog deployment pipeline, versioning workflow definitions in Git and deploying to per-client Temporal namespaces via CI/CD. Additional responsibilities span operational tooling for MSP onboarding (Zitadel org provisioning, compliance tier configuration, per-client KMS setup) and contributing to the Safe Connector Layer—vendor API wrapper services for ConnectWise, NinjaOne, M365/CIPP, Datto, IT Glue, CrowdStrike, and Huntress that enforce scope, inject platform-managed credentials, and log every call.
Required qualifications include strong backend engineering in Go or Rust, experience building event-driven systems with Kafka and event sourcing patterns, familiarity with Temporal or similar durable workflow engines, and deep knowledge of identity and access management (OAuth 2.0, OIDC, token lifecycle, fine-grained authorization). You must understand encryption patterns including envelope encryption, key hierarchy design, and KMS integrations, and be comfortable operating in multi-tenant, regulated environments where correctness and audit evidence are non-negotiable. Strong observability instincts—structured logging, distributed tracing, metrics instrumentation—are essential.
Preferred qualifications include experience with Zitadel, Keycloak, or similar identity providers; ClickHouse or columnar/append-only store experience; and prior work in MSP tooling, PSA/RMM API integrations, or compliance-adjacent infrastructure (CMMC, HIPAA, SOC 2).