- Deep understanding of Human and Machine Identity and Authentication protocols like OAuth 2.0, SCIM 2.0, SAML 2.0, Transaction tokens, FIDO2/WebAuthn and Passkeys, SPIFFE/SPIRE
- Experience with one or more policy-as-code or authorization frameworks (OPA/Rego, Cedar, Zanzibar/ReBAC)
- Proficiency in at least one systems or backend language: Python, Go, Rust
- Proficiency with security-relevant system design: session management, audit logging, rate limiting, secret storage
- Experience in Threat modeling for authentication and authorization systems
- Understanding of Zero trust architecture and least-privilege access patterns
- 10+ years of relevant professional experience combining SWE and security
- Engineer First: Approach problems with code and systems thinking
- Protocol Fluent: Hands-on experience implementing identity standards
- Collaborative: Work with direct team and cross-functional partners
- Strategic Thinker: Define clear technical requirements and assess commercial solutions
- Comfortable with Ambiguity: Gather data, navigate complex situations, and make sound technical decisions