Security Software Engineer 5

Netflix Netflix · Big Tech · Poland · Remote · Engineering

Netflix is seeking a Security Software Engineer 5 in Poland to build and operate the access experience layer, focusing on authentication, authorization, and cryptographic software services. The role involves designing, implementing, and maintaining access tooling and integration services, including adoption of their next-generation access management platform, Turnstile. This position requires experience in building scalable, reliable services, developer-facing APIs, and familiarity with IAM concepts and protocols. The role is based in Poland and can be performed remotely.

What you'd actually do

  1. Ownership of system design, implementation, partner integration, rollout strategy, and maintenance of access tooling and integration services
  2. Adoption layer for Turnstile, Netflix's next-generation access management platform
  3. APIs, SDKs, and self-service workflows that enable internal teams to implement access securely and consistently
  4. Serve as an in-time-zone security anchor — a technical lead who brings a pragmatic, risk-aware lens to AXE's designs and implementations and partners directly with ACE Core and ARC on security architecture decisions.

Skills

Required

  • Ability to work collaboratively to solve problems, navigate ambiguity, make and communicate self-directed decisions, and weigh trade-offs
  • Experience building scalable, reliable, high-availability, and low-latency services
  • Proficiency in modern languages (Java preferred, or Kotlin, Go, Python)
  • Experience designing and building developer-facing APIs, SDKs, and integration patterns
  • Familiarity with access control and IAM concepts — identity, authentication, authorization, roles, groups, attributes, and resource models
  • Experience with GraphQL, gRPC, REST, or similar technologies
  • Effective written communication skills and a product-focused mindset

Nice to have

  • Experience designing complex access control models using industry standards like RBAC, ABAC, or ReBAC
  • Experience with continuous integration and continuous deployment in a cloud platform
  • Experience with NoSQL technologies such as Hive, Presto, Spark, or Cassandra
  • Experience with graph databases
  • Experience with React or another modern frontend framework for full‑stack work

What the JD emphasized

  • security-first approach