IFS is seeking a Principal Platform Engineer for Identity and Access Management to serve as the technical authority on authorization and authentication across the Kairos and Nexus platforms. You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for developers and end-users. This is a hands-on engineering role with substantial architectural scope, intended to unify authorization across Nexus, F1, and LEC using SpiceDB and PostgreSQL, with cloud-native deployment patterns.
Key responsibilities include: - Design and implement fine-grained authorization models (ReBAC / Zanzibar-inspired, RBAC, ABAC where applicable) - Define authorization schemas, relationships, and permission checks at scale with performance and correctness in mind - Operate the authorization engine (SpiceDB on PostgreSQL), including migration to cloud-native Postgres and blue-green deployment support - Build IAM APIs and SDKs consumed by product teams to make access control the path of least resistance - Architect enterprise-scale authentication (AuthN) and manage identity-provider infrastructure (Curity and/or Keycloak), including OAuth 2.0, OIDC, and SAML patterns, token lifecycle management, and claims-based authorization - Define IAM patterns, standards, and golden paths for secure and consistent product adoption - Integrate IAM with the Internal Developer Platform to enable self-service authentication/authorization configuration - Provide subject-matter expertise on IAM security to product teams, architects, and
Track similar jobs
Get email alerts when new roles like this are posted.
Based on: Principal Platform Engineer - Identity and Access Management
See how this role matches your resume
Sign in to get an AI match score and personalized feed.
IFS is seeking a Principal Platform Engineer for Identity and Access Management to serve as the technical authority on authorization and authentication across the Kairos and Nexus platforms. You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for developers and end-users. This is a hands-on engineering role with substantial architectural scope, intended to unify authorization across Nexus, F1, and LEC using SpiceDB and PostgreSQL, with cloud-native deployment patterns.
Key responsibilities include: - Design and implement fine-grained authorization models (ReBAC / Zanzibar-inspired, RBAC, ABAC where applicable) - Define authorization schemas, relationships, and permission checks at scale with performance and correctness in mind - Operate the authorization engine (SpiceDB on PostgreSQL), including migration to cloud-native Postgres and blue-green deployment support - Build IAM APIs and SDKs consumed by product teams to make access control the path of least resistance - Architect enterprise-scale authentication (AuthN) and manage identity-provider infrastructure (Curity and/or Keycloak), including OAuth 2.0, OIDC, and SAML patterns, token lifecycle management, and claims-based authorization - Define IAM patterns, standards, and golden paths for secure and consistent product adoption - Integrate IAM with the Internal Developer Platform to enable self-service authentication/authorization configuration - Provide subject-matter expertise on IAM security to product teams, architects, and
Track similar jobs
Get email alerts when new roles like this are posted.
Based on: Principal Platform Engineer - Identity and Access Management
See how this role matches your resume
Sign in to get an AI match score and personalized feed.
© 2026 JobMatcher. All rights reserved.
© 2026 JobMatcher. All rights reserved.