Staff Software Engineer, Cloud Identity

Temporal Temporal · Enterprise · United States · Cloud

Staff Software Engineer for Identity to design, build, and operate the identity and access platform behind Temporal Cloud, a multi-tenant SaaS serving high-throughput workloads. This role owns systems for authentication, authorization, federation, and distribution of auth material, partnering with Security, Product, and platform teams to deliver secure-by-default capabilities.

What you'd actually do

  1. Design and build Temporal Cloud's identity platform end-to-end — authentication (OAuth 2.0/2.1, OIDC, SAML, token exchange), authorization (RBAC/ReBAC/policy engines), and workload identity federation — so customers and workloads authenticate without long-lived secrets
  2. Scale the auth hot path to meet Temporal Cloud's SLOs: in-memory auth bundles, JWKS caching, decision caching, and revocation strategies that keep latency low and eliminate single points of failure
  3. Integrate with enterprise IdPs (Okta, Entra ID, Google Workspace, SAML/OIDC), own SCIM 2.0 provisioning, and threat-model identity flows against token replay, confused deputy, scope escalation, and mix-mix-up attacks
  4. Partner with Security, Product, and platform teams to ship secure-by-default patterns, define IAM lifecycle and audit strategies, and shape the technical roadmap by tracking emerging standards (IETF OAuth WG, OpenID Foundation)
  5. Mentor engineers, maintain clear architecture docs, and engage directly with customers to understand requirements and unblock adoption

Skills

Required

  • Go
  • OAuth 2.0/2.1
  • OIDC
  • SAML
  • JWT/JOSE
  • JWKS rotation
  • SCIM
  • workload identity (SPIFFE/SPIRE, WIF, mTLS, or short-lived federated credentials)
  • RBAC
  • ABAC
  • ReBAC/Zanzibar
  • policy engines (OPA, Cedar, or OpenFGA)
  • distributed systems
  • on-call ownership

Nice to have

  • Python
  • Java
  • Kotlin
  • identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE)
  • standards bodies (IETF OAuth WG, OpenID Foundation)
  • compliance frameworks (FedRAMP, SOC 2, ISO 27001, HIPAA)
  • Temporal or other durable-execution engines
  • customer-facing API auth
  • well-structured APIs

What the JD emphasized

  • Deep hands-on experience building and operating production identity systems
  • Track record operating latency-sensitive distributed systems in production
  • on-call ownership