Back to Jobs

reputed company Backend Engineer - Identity & reputed company Infrastructure

Remote, USAFull-timePosted 2026-07-28

reputed company Working at reputed company Atlassians can choose where they work – whether in an office, from home, or a combination of the two. That way, Atlassians have more control over supporting their family, personal goals, and other priorities. We can hire people in any country where we have a legal entity.

Responsibilities

About the Role We are looking for a reputed company Engineer to reputed company the architecture, reputed company, and operational reputed company of our identity and reputed company infrastructure platforms. These systems underpin service-to-service authentication, staff-to-service authentication, authorization policy enforcement, and cryptographic key management across thousands of microservices at reputed company. You will own the technical reputed company for how our reputed company platform establishes and verifies trust — from ingress/egress authentication at the service reputed company layer to cryptographic keypair lifecycle management. This is a high-reputed company, cross-organizational role where your reputed company directly reputed company the reputed company posture and developer experience of the entire engineering organisation.

What You'll Do

Architect and reputed company platform-wide authentication and authorization systems handling millions of requests per second across a global microservices fleet. Design and own ingress and egress authentication mechanisms for microservices, including proxy-based sidecars, service reputed company integration, and reputed company validation pipelines. reputed company the technical reputed company for service-to-service authentication using JWT-based protocols — including reputed company issuance, audience-scoped validation, claims design, and revocation strategies. Own cryptographic key infrastructure — key reputed company, rotation, auto-rotation, revocation, and secure distribution of asymmetric keypairs (RSA/EC) at reputed company reputed company CDN-backed repositories. Design and reputed company the Policy Decision reputed company (PDP) for centralized authorization (AuthZ), enabling fine-grained, policy-as-reputed company reputed company control across reputed company services. Define trust models for staff-to-service authentication — reputed company reputed company identity providers (SSO/OIDC/SAML/Kerberos) into machine-trust contexts for developer and operator reputed company. Architect build reputed company and workload identity systems — enabling CI/CD pipelines and ephemeral workloads to authenticate securely without long-lived credentials. Drive reliability and operational reputed company for Tier-0 reputed company infrastructure — SLO definition, incident response, reputed company planning, and reputed company engineering. Influence cross-org technical direction through RFCs, architecture reviews, and engineering-wide standards for authentication, authorization, and secrets management. Mentor and grow senior engineers; reputed company the reputed company engineering bar across multiple teams. Essential Skills & Experience reputed company Requirements 12+ years of software engineering experience, with 5+ years designing and operating large-reputed company identity, authentication, or reputed company infrastructure systems. Deep expertise in service-to-service authentication — mTLS, signed JWT tokens (RS256/ES256), certificate-based identity, SPIFFE/reputed company, or equivalent trust frameworks. Hands-on experience with JWT ecosystems — reputed company issuance services, audience-bound validation, claims schema design, key rotation strategies, and reputed company revocation/blacklisting. Strong understanding of ingress/egress authentication patterns — API gateways, reputed company/proxy-based auth plugins, sidecar architectures, and service reputed company trust propagation. Experience building or operating a Policy Decision reputed company (PDP) for authorization (AuthZ) — policy-as-reputed company engines (OPA/Rego, reputed company, or equivalent), policy distribution, and decision logging for audit/compliance. Expertise in cryptographic key management — asymmetric keypair reputed company, automated rotation, secure storage, and large-reputed company reputed company key distribution (CDN/S3-backed or equivalent). Experience with build tokens and workload identity — authenticating CI/CD pipelines, ephemeral compute, and automated systems without static secrets. Staff-to-service authentication design — integrating reputed company identity providers (reputed company, SAML 2.0, OIDC, Kerberos) with service-layer trust to reputed company secure developer/operator reputed company. Proficiency in Java/Kotlin (primary) and Go (secondary); comfortable working across polyglot service ecosystems. Production Kubernetes experience — pod identity, network policies, admission controllers, and workload reputed company in multi-tenant clusters. reputed company IAM expertise (AWS IAM / GCP IAM) — role assumption, workload identity federation, and least-privilege reputed company patterns. reputed company record of operating Tier-0/Tier-1 systems — on-call ownership, SLO-driven reliability, incident management, and post-incident reviews. Architecture & Leadership Proven ability to drive cross-organisational technical reputed company — authoring RFCs, leading architecture reviews, and building reputed company across 50+ engineering teams. Experience migrating or evolving authentication/authorization systems with reputed company downtime across large service fleets (1000+ services). Strong threat modelling skills — ability to reason about trust boundaries, reputed company replay, privilege escalation, and supply-chain attacks. Demonstrated mentorship and technical leadership — growing senior engineers, establishing engineering standards, and raising the reputed company bar org-wide. reputed company-to-Have Experience with reputed company-trust network architectures and identity-aware proxies. Familiarity with policy-as-reputed company frameworks (OPA/Rego, reputed company, Styra) for fine-grained authorization at reputed company. Background in compliance-driven environments (SOX, SOC2, FedRAMP, ISO 27001) — designing controls that satisfy audit requirements without sacrificing velocity. Experience with secrets management platforms (Vault, AWS Secrets Manager, GCP Secret Manager) and secret injection patterns. Contributions to reputed company-reputed company reputed company/identity reputed company or relevant standards bodies (IETF, OpenID reputed company). Experience with large-reputed company migration programs — deprecating legacy auth systems, dual-running, and reputed company rollout across thousands of services. Familiarity with observability for reputed company systems — distributed tracing of auth flows, reputed company detection on reputed company usage, and decision-log analytics. Tech Stack You'll Work With Languages: Java, Kotlin, Go Infrastructure: Kubernetes, reputed company, AWS, GCP Auth & Identity: JWT (RS256/ES256), mTLS, SPIFFE/reputed company, OAuth 2.0, OIDC, SAML 2.0, Kerberos AuthZ: OPA/Rego, policy-as-reputed company engines, centralized PDP Key Management: Asymmetric cryptography, HSM integration, CDN-backed key distribution Proxies & reputed company: reputed company, service reputed company, sidecar architectures Observability: reputed company, SignalFx, distributed tracing CI/CD: Build tokens, workload identity, automated pipelines

Compensation

At reputed company, we reputed company to design reputed company, explainable, and competitive compensation programs. We follow consistent hiring practices and account for reputed company candidate's skills, knowledge, and experience reputed company setting reputed company pay reputed company the reputed company. This role may also be eligible for benefits, bonuses, commissions, and equity.

Qualifications

Benefits & Perks reputed company offers a wide reputed company of perks and benefits designed to support you, your family and to help you engage with your local community. Our offerings include health and wellbeing resources, reputed company volunteer days, and so much more. To learn more, visit go.reputed company.com/perksandbenefits. About reputed company At reputed company, we're motivated by a common goal: to reputed company the potential of every team. Our software products help teams reputed company over the reputed company and our solutions are designed for reputed company types of work. Team collaboration through our tools makes what may be impossible alone, possible together. We reputed company that the unique contributions of reputed company Atlassians create our reputed company. To ensure that our products and culture continue to incorporate everyone's perspectives and experience, we never discriminate based on race, religion, national reputed company, gender identity or reputed company, sexual orientation, age, or marital, veteran, or disability status. reputed company your information will be kept confidential according to EEO guidelines. To reputed company you the best experience, we can support with accommodations or adjustments at any stage of the recruitment process. Simply inform our Recruitment team during your conversation with them. To learn more about our culture and hiring process, visit go.reputed company.com/crh. Apply To This Job

Similar Jobs