Senior Software Engineer, Cloud Identity

Temporal Temporal · Enterprise · United States · Cloud Identity

Senior Software Engineer for Identity to design, build, and operate the identity and access systems behind Temporal Cloud, a multi-tenant SaaS platform. Responsibilities include authentication, authorization, integration with customer identity providers, and partnering with Security, Product, and infrastructure teams.

What you'd actually do

  1. Build and improve core parts of Temporal Cloud's identity platform — authentication (OAuth 2.0/OIDC, SAML), authorization (RBAC and policy-based access), and workload identity — so customers and workloads can authenticate securely
  2. Help keep the auth path fast and reliable to meet Temporal Cloud's SLOs through caching, token handling, and revocation strategies
  3. Integrate with enterprise identity providers (Okta, Entra ID, Google Workspace) and support user provisioning (SCIM), with attention to common identity threats such as token replay and privilege escalation
  4. Partner with Security, Product, and platform teams to ship secure-by-default patterns and contribute to IAM lifecycle and audit practices
  5. Write clear architecture and design docs, and contribute to the team's technical direction

Skills

Required

  • Go
  • production identity or auth systems
  • OAuth 2.0/OIDC
  • SAML
  • JWT
  • token/key rotation
  • RBAC
  • distributed systems
  • on-call responsibility
  • communication skills
  • collaboration

Nice to have

  • Python
  • Java
  • Rust
  • ABAC
  • OPA
  • Cedar
  • OpenFGA
  • workload identity
  • short-lived / federated credentials
  • SPIFFE/SPIRE
  • mTLS
  • WIF
  • SCIM provisioning
  • enterprise SSO integrations
  • identity OSS projects
  • Keycloak
  • Ory
  • Dex
  • OpenFGA
  • SPIRE
  • compliance frameworks
  • SOC 2
  • ISO 27001
  • HIPAA
  • IAM
  • Temporal
  • durable-execution engines
  • customer-facing API auth
  • scoped tokens
  • API keys
  • rotation

What the JD emphasized

  • production identity or auth systems
  • secure by default