SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Affirm is reinventing credit to make it more honest and friendly. This is a hands-on Staff engineering position within Information Security, focused on designing and shipping core Customer Identity and Access Management (CIAM) capabilities that protect customers and support growth.
You will build and operate backend services powering registration, login, authorization, and account lifecycle flows across B2C and B2B experiences. Working closely with partner engineering teams, you'll ensure identity features are delivered with strong security fundamentals, reliability, and operational rigor.
Key responsibilities include:
- Design, build, and operate core CIAM backend services supporting customer registration, authentication, authorization, account lifecycle, and profile management for B2C and B2B platforms
- Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code, ensuring correctness, scalability, and clean integration patterns
- Develop backend APIs and services in Python and Kotlin exposing identity capabilities to web, mobile, and partner applications
- Integrate CIAM platforms with internal systems including user data stores, messaging, fraud signals, and downstream customer platforms
- Own secure authentication and account flows end-to-end, including MFA, step-up authentication, device binding, consent, and adaptive authentication logic
- Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines, treating identity as a core platform service
- Monitor, debug, and optimize CIAM services for performance, resilience, and abuse detection in high-scale environments
Required qualifications:
- 7+ years designing, developing, and launching backend systems at scale using Python or Kotlin
- Extensive track record developing highly available distributed systems using AWS, MySQL, Spark, and Kubernetes
- Strong experience designing and implementing CIAM systems with deep hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM beyond basic configuration
- 5+ years professional backend software engineering experience
- Strong production experience in Python or similar backend language
- Experience designing APIs, automation frameworks, and distributed systems
- Hands-on experience building and maintaining CI/CD pipelines
- Experience with GitHub-based development workflows and Buildkite or similar build systems
- Cloud-native development experience, preferably AWS
- Hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C
- Solid understanding of backend and distributed systems fundamentals including API design, data modeling, latency, error handling, and observability
- Experience with Infrastructure as Code and automation tools such as Terraform
- Strong security fundamentals applied through engineering, including access control models, token handling, encryption, MFA, and privacy by design
- Clear communication skills and ability to work closely with product, frontend, mobile, and security teams
- Familiarity with AI-augmented development environments such as Cursor