Senior Software Engineer ; Identity & Trust Infrastructure; Costa Rica
Listed on 2026-08-24
-
Software Development
Senior Software Engineer, Identity & Trust Infrastructure
We are looking for a Senior Software Engineer to build the identity and trust infrastructure that brings Sim Space's internet simulation platform to life for the humans and automated systems operating within it.
This role owns interconnected systems: a unified persona registration API that provisions fully realized digital identities across both in-range Active Directory environments and simulated internet services; a Range Domain Controller management service that configures AD domains, users, and group policy on top of deployed range infrastructure; and a PKI and certificate authority stack that ensures in-range clients trust the simulated internet at the TLS layer.
This is a security-infrastructure role with significant API design responsibility, the right candidate understands identity systems deeply, can build robust APIs that handle partial failure gracefully, and knows how to stand up and operate a home-grown certificate authority.
The team is responsible for:- A unified persona registration API: the single interface through which user emulation and scenario orchestration services provision fully realized range personas, creating AD accounts, configuring group memberships and privilege levels, and registering accounts across all configured simulated internet services in a single, idempotent operation
- A Range Domain Controller management service: the API layer that configures Active Directory domains, organizational units, users, and group policy on the DC infrastructure deployed by the range orchestration team, this team owns everything above the baseline VM configuration
- A PKI and certificate authority infrastructure: root CAs, intermediate CAs, certificate issuance pipelines, and the mechanisms by which in-range clients are configured to trust certificates issued for simulated internet domains
- The Grey Space user API: account lifecycle management across the heterogeneous set of simulated internet services, including web platforms, FTP servers, SSH services, and mail infrastructure.
- Design and build the unified persona registration API — the interface that accepts a persona definition and fans out to provision an account in real and simulated cloud services, configure group memberships and OUs, and create accounts on all relevant simulated internet services, handling partial failures idempotently and providing a consistent status model to callers
- Build and maintain the Range Domain Controller management service: the API layer that drives AD configuration, creating users, assigning group memberships, configuring OUs and domain policies, and managing subdomain configuration for simulated organizations
- Design and operate the PKI infrastructure: stand up a root CA and intermediate CA hierarchy, build certificate issuance pipelines that generate and sign certificates at domain provisioning time, and own the mechanism by which in-range clients on both Windows and Linux are configured to trust the platform CA chain
- Own the Grey Space user API: account creation, deletion, elevation, and demotion across the full service catalog, ensuring consistency between in-range AD identity and internet-facing service accounts for each persona
- Define and enforce the data model for range personas across all identity backends, AD schema, SSO federation, and per-service account state, and own the eventual consistency and reconciliation model when backends diverge
- Collaborate with the user emulation team to ensure the persona registration API meets their orchestration requirements and supports the full range of persona complexity their scenarios require
- Participate in design reviews and contribute to the broader platform architecture, particularly on topics of trust, authentication, and the security model for the internet simulation platform
- Strong bilingual proficiency in English and Spanish skills required across written, virtual, and in-person interactions
- Deep understanding of Active Directory: user and group provisioning, organizational unit design,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).