CronJobs

backend jobs

Staff Software Engineer

Bamboohr17 · Utah | Remote

remotestaffPosted Sep 30, 2026OAuth 2.0OIDCSAMLRBACABACJWTOpenAPIOPA

Apply on the employer site

About this role

**Staff Software Engineer — Permissions (Remote)** *Please Note:* This is a remote position available in the state listed on this job. Employment with BambooHR is contingent on passing both a background and credit check. --- ## About the Role At BambooHR, we’re using AI to streamline workflows and reimagine the future of HR. As a **Staff Software Engineer, Permissions**, you’ll be the technical authority for BambooHR’s next-generation **permission service**—designing and building a system that securely controls what every **user, token, and agent** can do across the platform. You’ll own the architecture of a **greenfield permissions service**, define **AuthN/AuthZ patterns** for **180+ product domains**, and connect the **Token Titans** team with engineering organizations that depend on what you ship. --- ## Essential Job Duties You will: - **Drive architecture & delivery** of a new permission service—from first design doc to production (data model, policy evaluation engine, enforcement APIs, and token contract) - **Refine and define BambooHR AuthN/AuthZ standards** (authentication flows, token issuance, scoped authorization, and role/attribute-based access control) - **Design the API contract** for the permission service (access decision requests, policy definition, and decoupled enforcement) - **Drive token strategy** (JWT issuance, rotation, scoping, revocation; relationships between tokens and permissions for human + machine callers) - **Partner with product & platform teams** to translate domain access control needs into reusable permission primitives - **Lead architectural reviews** for features with AuthN/AuthZ implications - **Collaborate with Security & Compliance** to meet audit, least-privilege, and zero-trust requirements - **Set the technical bar** for the Token Titans team (mentor engineers, lead RFCs, ensure implementation quality matches architecture) --- ## What You Need to Get the Job Done - **10+ years** software engineering experience, including **3+ years** at Staff or Principal level - Deep expertise in **identity & access management**: - Authentication: **OAuth 2.0, OIDC, SAML** - Authorization: **RBAC, ABAC, ReBAC** - Token lifecycle: **JWTs, opaque tokens, refresh/rotation strategies** - Demonstrated experience **designing and building AuthN/AuthZ systems at scale** (owning architecture, not just integrating) - Strong instincts for **policy-as-code**, permission modeling, and expressing complex access rules as an evolvable data model - Experience designing/reviewing **OpenAPI**, event-driven architectures, and cross-service communication in service-oriented/microservice environments - Strong backend fundamentals; comfort working in a **PHP monolith** with modern architectural patterns - Proven ability to drive org-wide architectural decisions (RFCs, reviews, consensus across competing priorities) - Excellent communication skills (precise specs, presentations, explaining tradeoffs in identity/security) --- ## What Will Make Us REALLY Love You - Hands-on experience building a **permission service/authorization framework** from scratch (e.g., Zanzibar-style, OPA-based, or custom policy engine) - Familiarity with **Okta, Auth0**, or similar identity platforms (clear sense of build vs. buy) - Experience with fine-grained authorization (relationship-based access control, contextual policies, delegated permissions) - Background in **multi-tenant SaaS** (org hierarchy, role inheritance, tenant isolation)

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord