×
Register Here to Apply for Jobs or Post Jobs. X

Software Engineer, Identity & Authorization

Job in Fort Worth, Tarrant County, Texas, 76102, USA
Listing for: United States Digital Space LLC
Full Time position
Listed on 2026-09-17
Job specializations:
  • Software Development
    Backend Developer, DevOps, Software Engineer, Software Architect
Salary/Wage Range or Industry Benchmark: 100000 - 130000 USD Yearly USD 100000.00 130000.00 YEAR
Job Description & How to Apply Below
Position: Staff Software Engineer, Identity & Authorization

About the Company

the company is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, the company is democratizing software development by removing traditional barriers to application creation.

About the Team

Product Platform builds and owns the shared foundations the rest of the company is built on, spanning the full stack so every other team can ship features safely and quickly.

Identity & Authorization

Identity & Authorization defines how people, agents, sandboxes, and services prove who they are and what they can do. These systems protect critical product and service interactions across the company's web product, Agent, enterprise controls, and internal services.

Our Focus

Our work is high-leverage and horizontal: when identity and policy are clear, reliable, and easy to adopt, every other team can move faster without rebuilding security controls.

Team Culture

We are a small, collaborative team that values curiosity and clear thinking over pedigree, and we work in the open by bringing each other the problem rather than just the request. We care more about how you reason and build than the route you took to get here.

About the Role

As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on the company, including Agent acting on behalf of a user or holding their own identity.

Guiding Questions
  • Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf?
  • Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services?
  • Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions?
  • Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials?
  • Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?
What you'll do
  • Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations
  • Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible
  • Build and operate the company's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS
  • Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default
  • Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship
  • Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives
  • Research and develop new innovative approaches to Authx in the Agentic world
Areas you might work in
  • Authorization policy: evolve the company's central policy decision point and migrate fragmented authorization checks to its typed contract.
  • Agent delegation: extend the current delegation foundation so the user is the subject and Agent is the authenticated actor, with continuous validation and dynamic permission envelopes as work runs.
  • Enterprise access control: evolve roles, groups, workspace policy, and app-level grants for both simple collaboration and complex organizations.
  • Agent and service identity and reliability: operate the token and workload-identity systems that protect…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary