SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
AlphaSense is a market intelligence platform trusted by over 6,000 enterprise customers, including a majority of the S&P 500. The company delivers AI-driven insights from public and private content including equity research, company filings, event transcripts, and expert calls. Founded in 2011 and headquartered in NYC with 2,000+ employees globally, AlphaSense acquired Tegus in 2024 to expand its capabilities.
The User Management team owns the complete identity lifecycle at AlphaSense—user creation and provisioning, identity management, authentication, and authorization. This is a platform engineering team that builds identity and access infrastructure for internal product teams and serves as a security guardrail for the entire platform. The team is well-established and senior, based in Helsinki, and is now expanding into North America to provide follow-the-sun support and scale authentication/authorization systems for self-service adoption across the company.
As a Staff Engineer, you will design and operate identity, authentication, and authorization systems built to scale with a constantly growing customer base. You'll work across all three pillars equally—user management, authentication, and authorization—in a security-first environment governed by SOC2 and GDPR compliance. This role requires genuine seniority and self-sufficiency: you'll help shape the roadmap, not just execute it, working largely autonomously while collaborating closely with the Helsinki-based core team across timezones.
You bring strong backend experience with Java, Spring Boot, and cloud infrastructure (AWS/GCP, Kubernetes). You're deeply familiar with identity and security protocols: RBAC/ABAC/ReBAC, OAuth 2.0, OIDC, JWT, SAML 2.0, enterprise SSO federation, and SCIM. You have hands-on experience building and operating identity platforms at scale, ideally in a platform engineering context. You're genuinely interested in security, comfortable designing secure-by-design systems in partnership with security teams, and thrive in distributed, cross-timezone collaboration. Experience with Auth0, SpiceDB/Zanzibar-style systems, Apollo Federation, OpenTelemetry, or SOC2/GDPR environments is a plus.