SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Software Engineer, Identity & Authorization

Replit - Foster City, CA, United States - In-office - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Replit is an agentic software creation platform that democratizes application development by enabling anyone to build using natural language. The Identity & Authorization team within Product Platform owns the shared security foundations that protect critical interactions across Replit's web product, Agent, enterprise controls, and internal services. In this Staff-level role, you will design, build, and operate identity and authorization systems that protect how people, agents, sandboxes, and services authenticate and prove their capabilities. Your work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls. Key responsibilities include: - Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations - Evolve enterprise roles, groups, app access, entitlements, and workspace policy to keep common cases simple while enabling advanced scenarios - Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS - Threat-model delegation and confused-deputy risks, ensuring secure, fail-closed behavior by default - Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans; own SLOs, incidents, and operational health - Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to translate product requirements into shared platform primitives - Research and develop innovative approaches to authorization in the agentic world Potential focus areas include authorization policy evolution, Agent delegation foundations, enterprise access control, and Agent/service identity reliability. The team values curiosity and clear thinking over pedigree, working in the open and bringing problems rather than just requests. The emphasis is on how you reason and build rather than your background. REQUIREMENTS: - Proven experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability - Depth in authentication, authorization, or identity systems (OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines) - Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling - Experience migrating security-sensitive systems without breaking callers (typed contracts, shadow evaluation, staged enforcement) - Fluency in at least one production backend stack; systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate - Ability to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

Similar roles