Senior Developer, Fullstack
Job description
About the role
You will architect and implement the core identity and access management systems that define how users enter and move through our platform. You will design and maintain the authentication workflows that verify practitioner identity and the authorization rules that govern access to sensitive health data. You will own the end-to-end logic behind sign-up, login, single sign-on integrations, and OAuth token lifecycles. You will translate product and security requirements into resilient frontend and backend features that keep user data safe and experiences frictionless. You will partner with security stakeholders to ensure every layer of the identity stack adheres to strict compliance and threat models. You will mentor junior engineers by elevating code quality, clarity, and maintainability across the IAM suite. You will proactively identify scalability risks and performance bottlenecks in high-concurrency flows like login and session management. If you share our values outlined in our developer handbook, we would be excited to discuss how your expertise can strengthen our mission.
Key facts
What you'll do
Design and maintain the architecture of our identity and access management platform, including authentication, authorization, and user identity stores.
Implement and iterate on sign-up, login, and session management workflows to ensure secure and reliable practitioner access.
Integrate and manage single sign-on solutions with enterprise identity providers to support large health systems and clinics.
Develop and maintain OAuth flows and token handling mechanisms to enable secure delegated access for integrations and third-party applications.
Collaborate closely with security engineers and compliance officers to enforce data protection standards and regulatory requirements.
Partner with product managers to translate business requirements into technical specifications for identity-related features and user journeys.
Lead the implementation of resilient APIs and frontend components that deliver smooth authentication experiences across web and client applications.
Monitor system performance and reliability for identity services, identifying and resolving bottlenecks in high-traffic scenarios.
Mentor cross-functional engineers by elevating code quality, documentation, and best practices across the IAM engineering team.
Proactively investigate and resolve complex issues in login, SSO, and token validation workflows to reduce friction for practitioners and administrators.
Coordinate with clinical and analytics product teams to align identity infrastructure with broader platform capabilities and user needs.
Champion secure development practices by integrating security reviews and threat modeling into the delivery lifecycle for identity features.
Support the deployment and operation of IAM services in production, working closely with DevOps and site reliability teams.
Evaluate and recommend new identity technologies and standards to keep our platform current with industry best practices and emerging needs.
Requirements
You have a Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
You possess 8+ years of professional software development experience, with a strong focus on fullstack engineering.
You have 8+ years of experience building and maintaining authentication and authorization systems.
You are highly proficient in JavaScript or TypeScript, with substantial experience writing production-grade code for both frontend and backend.
You have deep expertise in modern frontend frameworks and a solid understanding of browser security models, including same-site cookies, CSP, and XSS/CSRF mitigation.
You have extensive experience with OAuth 2.0 and OpenID Connect, including implementing authorization code flows, token refresh, and secure storage of credentials.
You are experienced integrating with enterprise identity providers such as Okta, Azure AD, and similar SAML/OIDC platforms.
You have a strong understanding of security best practices, compliance frameworks, and the challenges of building systems that handle protected health information.
You are comfortable working in an agile environment, collaborating daily with product, design, security, and operations teams to deliver reliable solutions.
Nice to have
Experience contributing to open source projects related to identity, security, or authentication.
Familiarity with clinical workflows and terminology used in digital health platforms.
Experience with infrastructure as code and cloud provider services used to host identity platforms.
Practical notes
This is a full-time position based in Ottawa, Ontario.
The work location is primarily on-site, and the role is not eligible for remote or hybrid arrangements.
Applicants must be authorized to work in Canada without sponsorship at this time.
We encourage applicants who share our passion for improving care through technology to apply and align with our developer values.