
Staff CIAM Security Engineer
Job description
About the role
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm is building the next generation of customer identity and authentication. This role is a hands-on engineering position inside Information Security, focused on designing and shipping core CIAM capabilities that protect customers and support growth. You will build and operate backend services that power registration, login, authorization, and account lifecycle flows across B2C and B2B experiences. You will work closely with partner engineering teams and ensure identity features are delivered with strong security fundamentals, reliability, and operational rigor.
What you'll do
Design, build, and operate core CIAM backend services that support customer registration, authentication, authorization, account lifecycle, and profile management for B2C and B2B platforms.
Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code, ensuring correctness, scalability, and clean integration patterns.
Develop backend APIs and services in Python and Kotlin that expose identity capabilities to web, mobile, and partner applications.
Integrate CIAM platforms with internal systems, including user data stores, messaging, fraud signals, and downstream customer platforms.
Own secure authentication and account flows end to end, including MFA, step-up authentication, device binding, consent, and adaptive authentication logic.
Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines, treating identity as a core platform service.
Monitor, debug, and optimize CIAM services for performance, resilience, and abuse detection in high-scale environments.
Collaborate closely with partner engineering teams to define and deliver identity features that meet security requirements and product goals.
Drive operational excellence by defining runbooks, observability strategies, and incident response processes for CIAM services.
Contribute to security design reviews and threat modeling sessions to ensure identity controls are robust and scalable.
Lead or participate in on-call rotations to respond to production incidents and ensure continuous availability of identity services.
Champion best practices in secure coding, testing, and documentation to enable other engineers to build safely with identity primitives.
Work with product managers and security stakeholders to translate business requirements into secure identity workflows and policies.
Continuously evaluate new identity technologies and patterns to future-proof the CIAM platform and support evolving use cases.
Requirements
You have 7+ years of experience designing, developing and launching backend systems at scale using languages like Python or Kotlin.
You have an extensive track record of developing highly available distributed systems using technologies like AWS, MySQL, Spark and Kubernetes.
You have strong verbal and written communication skills that support effective collaboration with our global engineering team.
You have experience delivering major features, system components or deprecating existing functionality in a system through the definition of a technical and execution plan. You write high quality code that is easily understood and used by others.
You have strong experience designing and implementing CIAM systems, with deep, hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM beyond basic configuration.
You have 5+ years of professional backend software engineering experience.
You have strong production experience in Python or a similar backend language.
You have experience designing APIs, automation frameworks, and distributed systems.
You have hands-on experience building and maintaining CI/CD pipelines.
You have experience with GitHub-based development workflows and Buildkite or similar build systems.
You have experience with cloud-native development, preferably AWS.
You have hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C using custom code, hooks, and APIs.
You have a solid understanding of backend and distributed systems fundamentals, including API design, data modeling, latency, error handling, and observability.
You have experience with Infrastructure as Code and automation tools such as Terraform, plus CI/CD pipelines for deploying backend services.
You have strong security fundamentals applied through engineering, including access control models, token handling, encryption, MFA, and privacy by design.
About the role
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm is building the next generation of customer identity and authentication. This role is a hands-on engineering position inside Information Security, focused on designing and shipping core CIAM capabilities that protect customers and support growth. You will build and operate backend services that power registration, login, authorization, and account lifecycle flows across B2C and B2B experiences. You will work closely with partner engineering teams and ensure identity features are delivered with strong security fundamentals, reliability, and operational rigor.
What you'll do
Design, build, and operate core CIAM backend services that support customer registration, authentication, authorization, account lifecycle, and profile management for B2C and B2B platforms.
Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code, ensuring correctness, scalability, and clean integration patterns.
Develop backend APIs and services in Python and Kotlin that expose identity capabilities to web, mobile, and partner applications.
Integrate CIAM platforms with internal systems, including user data stores, messaging, fraud signals, and downstream customer platforms.
Own secure authentication and account flows end to end, including MFA, step-up authentication, device binding, consent, and adaptive authentication logic.
Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines, treating identity as a core platform service.
Monitor, debug, and optimize CIAM services for performance, resilience, and abuse detection in high-scale environments.
Collaborate closely with partner engineering teams to define and deliver identity features that meet security requirements and product goals.
Drive operational excellence by defining runbooks, observability strategies, and incident response processes for CIAM services.
Contribute to security design reviews and threat modeling sessions to ensure identity controls are robust and scalable.
Lead or participate in on-call rotations to respond to production incidents and ensure continuous availability of identity services.
Champion best practices in secure coding, testing, and documentation to enable other engineers to build safely with identity primitives.
Work with product managers and security stakeholders to translate business requirements into secure identity workflows and policies.
Continuously evaluate new identity technologies and patterns to future-proof the CIAM platform and support evolving use cases.
Requirements
You have 7+ years of experience designing, developing and launching backend systems at scale using languages like Python or Kotlin.
You have an extensive track record of developing highly available distributed systems using technologies like AWS, MySQL, Spark and Kubernetes.
You have strong verbal and written communication skills that support effective collaboration with our global engineering team.
You have experience delivering major features, system components or deprecating existing functionality in a system through the definition of a technical and execution plan. You write high quality code that is easily understood and used by others.
You have strong experience designing and implementing CIAM systems, with deep, hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM beyond basic configuration.
You have 5+ years of professional backend software engineering experience.
You have strong production experience in Python or a similar backend language.
You have experience designing APIs, automation frameworks, and distributed systems.
You have hands-on experience building and maintaining CI/CD pipelines.
You have experience with GitHub-based development workflows and Buildkite or similar build systems.
You have experience with cloud-native development, preferably AWS.
You have hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C using custom code, hooks, and APIs.
You have a solid understanding of backend and distributed systems fundamentals, including API design, data modeling, latency, error handling, and observability.
You have experience with Infrastructure as Code and automation tools such as Terraform, plus CI/CD pipelines for deploying backend services.
You have strong security fundamentals applied through engineering, including access control models, token handling, encryption, MFA, and privacy by design.