Sr Backend Engineer, Identity & Access Management
Job description
About the role
You will own the systems every customer touches before they touch anything else, including SAML and OAuth2 single sign-on, SCIM user and team provisioning, login and session management, multi-factor authentication, and the API key and token infrastructure that authenticates every request to our platform. You will ensure that authentication is always correct because when it is wrong, customers cannot get in at all or the wrong person gets in, making security and availability core commitments to our customers and not optional extras. You will work alongside the team to make this stack reliable and enterprise-ready, applying deep backend judgment to safely change systems that are not allowed to be wrong. Your decisions will directly shape the identity and access management capabilities that our largest customers depend on every day. You will partner closely with product security and cross-functional teams to raise the bar for design, implementation, and operation of critical identity infrastructure. This role gives you ownership over the foundational controls that secure access to LaunchDarkly itself and to the platforms our customers build on top of it.
Key facts
What you'll do
Own LaunchDarkly's authentication surface end to end, covering single sign-on, SCIM provisioning, login and session flows, multi-factor authentication, and API key and token authentication.
Build the enterprise identity capabilities our largest customers require, such as additional identity-provider integrations, support for multiple IdPs per account, and MFA enforcement by default.
Make the stack operable by defining and tracking SLOs, implementing monitoring for certificate expiry and provisioning failures, creating actionable alerting, maintaining runbooks, and sustaining a healthy on-call rotation.
Partner with Product Security on threat modeling, audit logging, and compliance requirements, including SOC 2 and FedRAMP considerations for identity and access management.
Set the technical direction for identity at LaunchDarkly and influence engineering standards through design reviews, code quality, and mentorship of backend engineers.
Design and evolve backend services in Go, TypeScript, CockroachDB, Redis, AWS, and Terraform to meet scalability, reliability, and security targets.
Collaborate with product and security teams to translate identity requirements into robust technical specifications and implementation backstacks.
Lead incident responses for authentication and access issues, driving postmortems and preventative improvements to reduce future risk.
Contribute to architectural decisions that enable secure multi-tenant identity management across diverse customer environments and regulatory boundaries.
Champion best practices for secrets management, token lifecycle, and secure session handling across services and integrations.
Engage in code reviews and knowledge sharing to elevate the level of engineering rigor across the identity and access management domain.
Support the operation of CI/CD pipelines and infrastructure tooling that enable safe, auditable, and reversible changes to production identity systems.
Requirements
6+ years of professional software-engineering experience, with significant work on complex backend applications that underpin critical user workflows.
Experience building or operating production authentication and identity systems, including handling of login, sessions, tokens, and user lifecycle operations.
A track record on systems where correctness and availability are non-negotiable, demonstrated through habits such as backward-compatible change, staged rollouts, and safe cutovers.
Proficiency in at least one backend language such as Go, Rust, or Python, along with familiarity with cloud infrastructure on AWS or equivalent platforms, plus strong production ownership including on-call responsibilities.
Strong understanding of identity protocols including SAML, OAuth2, and SCIM, and experience integrating with external identity providers in enterprise contexts.
Solid experience with database systems like CockroachDB and Redis, and with infrastructure as code tools such as Terraform for managing cloud environments.
Comfort operating in distributed systems environments, including observability, logging, tracing, and structured alerting to maintain high reliability.
Commitment to compliance and security practices, including audit logging, threat modeling, and working toward standards such as SOC 2 and FedRAMP where applicable.
Nice to have
Protocol depth in SAML, OAuth2, and SCIM, including advanced scenarios like federation, delegation, and complex identity transformations.
Experience with multi-factor authentication mechanisms and enforcement workflows, including integration with hardware or software authenticators.
Background in roles that require strict security and availability postures, such as in financial services, healthcare, or regulated enterprise environments.
Familiarity with role-based access control models and how they intersect with identity providers and service-level permissions.
Experience contributing to open source projects or internal platform tooling that supports secure software delivery and operations.
Practical notes
Employment is full-time and remote within the United States.
The role requires availability to support on-call rotations and respond to production incidents outside standard business hours.
Candidates must be legally authorized to work in the United States without sponsorship for this position.