CronJobs

security jobs

Software Engineer - Identity & Authorization

Baseten · San Francisco

hybridmid$240,000–$285,000Posted Sep 2, 2026PythonGoKubernetesOAuthOIDCSCIMOpenFGASpiceDB

Apply on the employer site

About this role

**ABOUT BASETEN** Baseten powers mission-critical inference for the world’s most dynamic AI companies (e.g., Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, Writer). By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we help frontier AI companies bring cutting-edge models into production. We’re growing quickly and recently raised our **$1.5B Series F** (led by Altimeter Capital, Conviction Partners, and Spark Capital). Join us to help build the platform engineers rely on to ship AI products. --- **THE ROLE** Enterprises running on Baseten have exacting requirements for how people, services, and agents access the platform. This is the founding role for our **Identity & Authorization** team within enterprise engineering. You’ll own the **identity and access layer** of the Baseten platform—covering the **authorization model**, **credential systems**, and **admin experiences** used by enterprise IT teams to govern access for organizations like Harvey, HubSpot, and Notion. You’ll design and build Baseten’s **fine-grained authorization system** from the ground up—supporting customer workflows today while enabling cleaner, more precise access management as the platform grows. Key focus areas include: - **Low-latency permission checks** at high request volume - **Consistent contracts/behaviors** across the product suite - **Strong security guarantees** for mission-critical, highly regulated workloads --- **EXAMPLE INITIATIVES** - Fine-grained authorization for **users, service accounts, and agentic workloads** (per-resource permissions across organization/team/workload scope) - **Programmatic authentication** for high-compliance customers using short-lived, workload-based credentials - **Agent credentials** granting only the access needed for the task - **Enterprise identity lifecycle**: SSO, SCIM provisioning, and per-organization session expiry policies - **Admin controls** for centralized visibility, auditability, and governance over credentials, roles, and access --- **RESPONSIBILITIES** - Lead identity and authorization projects from problem definition and technical design through implementation, launch, and iteration - Design authorization and credential models that support critical user workflows today and can be safely extended as the platform evolves - Partner with product, design, and customer-facing teams to turn enterprise security requirements into durable technical solutions - Establish engineering practices for **quality, security, observability, and operational ownership** - Provide technical leadership and mentorship as the team grows --- **REQUIREMENTS** - **4–5+ years** building production backend systems, including hands-on design/implementation of a product authorization system (e.g., per-resource/per-object permissions, relationship-based access control, policy engine, or fine-grained authorization like Zanzibar/OpenFGA/SpiceDB/Cedar) - Demonstrated end-to-end ownership (design → implementation → production rollout → iteration) - Experience building and operating **multi-tenant systems at scale**, where authorization checks are in the request path and latency/consistency matter - Comfort working across the full stack (product/application code through cloud and Kubernetes infrastructure) --- **NICE TO HAVE** - Experience with **Python** and **Go** - Production experience running **OpenFGA/SpiceDB** (or similar) beyond a proof of concept - Working knowledge of **OAuth,

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord