Staff Software Engineer I - Internal Access Management

Confluent Confluent · Data AI · United States · Remote · Engineering

Staff Software Engineer to lead technical vision, architecture, and execution for Internal Access Management at Confluent, focusing on distributed systems, cloud security, authentication, and policy-driven authorization frameworks.

What you'd actually do

  1. Define and drive the long-term architecture and roadmap for Internal Access Management across Kubernetes and multi-cloud environments.
  2. Architect and implement least privilege, just-in-time access, and zero-trust models across Confluent services.
  3. Build and evolve scalable access-authorization workflows and lifecycle management systems using technologies such as OPA, cloud IAM policies, workload identity, and internal enforcement engines.
  4. Strengthen security boundaries through threat modeling, defense-in-depth practices, and comprehensive access-auditing capabilities.
  5. Partner with cross-functional teams—including Platform, Kafka, Observability, Developer Productivity, Release Engineering, and SRE—to drive adoption of secure identity and access patterns.

Skills

Required

  • 10+ years of engineering experience, with 4+ years in security, IAM, or distributed systems.
  • Deep expertise in Kubernetes, workload identity, cloud IAM (AWS, GCP, Azure), and zero-trust architectures.
  • Strong understanding of authentication technologies: IAM, OAuth2, OIDC, policy engines, and modern zero-trust principles.
  • Proven track record leading multi-team technical initiatives at a Staff or Senior Staff level.
  • Strong knowledge of distributed systems, cloud infrastructure, container orchestration, and service mesh.
  • Excellent communication and stakeholder-influence skills across engineering and security domains.

Nice to have

  • Experience leading cross-org security platform architecture initiatives.
  • Background in building developer-focused authentication and authorization platforms.

What the JD emphasized

  • least privilege
  • just-in-time access
  • zero-trust
  • OPA
  • cloud IAM policies
  • workload identity
  • Kubernetes
  • workload identity
  • cloud IAM
  • zero-trust architectures
  • IAM
  • OAuth2
  • OIDC
  • policy engines
  • zero-trust principles