Software Engineer, Identiy & Access

Lovable Lovable · Coding AI · Stockholm, Sweden · Engineering

Software Engineer focused on the identity and access management layer for an AI-powered software creation platform. This role involves designing and building authentication, authorization, and user management systems for both the platform itself and user-generated applications, ensuring security, scalability, and developer-friendliness.

What you'd actually do

  1. Design and build the Apps Platform's identity and access management system, covering both platform-level auth (Lovable users) and app-level auth (end users of Lovable-generated apps)
  2. Implement authentication flows: OAuth 2.0/OIDC, magic links, social login providers, MFA, and session management
  3. Build a robust authorization model: RBAC, row-level security, API key management, and fine-grained permissions
  4. Own multi-tenancy isolation — ensuring that user apps, data, and credentials are securely separated
  5. Manage secrets infrastructure: secure storage, rotation, and access control for database credentials, API keys, and service tokens

Skills

Required

  • Deep expertise in identity and access management: OAuth 2.0, OIDC, SAML, JWT, session management, and token lifecycle
  • Experience building or operating auth systems at scale — ideally in a multi-tenant SaaS or PaaS context
  • Strong security mindset
  • Experience with RBAC/ABAC models and row-level security in Postgres
  • Familiarity with identity providers and auth services (Auth0, Supabase Auth, Clerk, Firebase Auth, Keycloak, etc.)
  • Comfortable with TypeScript across backend services and API layers
  • Operational instincts

Nice to have

  • Experience with secrets management tools (Vault, AWS Secrets Manager, or similar)
  • Background in compliance-relevant auth work (SOC 2, GDPR, HIPAA)
  • Familiarity with Supabase Auth internals (GoTrue) or similar open-source auth servers
  • Experience designing auth for AI-generated or low-code applications
  • Familiarity with managed cloud services (AWS, GCP) and the tradeoffs of buy-vs-build for identity infrastructure

What the JD emphasized

  • Migrate identity services from the current bundled setup to a fully owned, composable identity layer without breaking user sessions
  • You've migrated auth systems or transitioned between identity providers in production without breaking user sessions