Senior Engineer, Agentic Identity
Baselayer · San Francisco, California
About this role
**Senior Engineer, Agentic Identity** **About Baselayer** Baselayer is rebuilding the identity layer that determines whether businesses are real, who’s behind them, and whether they’re a risk—using modern infrastructure instead of systems from the 1980s. We fuse public records, IRS data, sanctions lists, web signals, and fraud telemetry from 2,200+ financial institutions into a single graph that resolves business entities and the humans behind them in milliseconds. We’ve achieved 98% match rates in under two years (legacy credit bureaus took ~50 years for ~60%). Trusted by 20%+ of financial institutions in the U.S. (including FIS, Rho, Socure), the graph is becoming foundational infrastructure for anyone who needs to verify businesses—gig platforms, marketplaces, AI companies, and commerce infrastructure at scale. **About the Team** You’ll join a small team tackling real-time entity resolution at scale: fusing multiple data sources into a business identity graph and resolving entities in milliseconds. The work spans graph AI, retrieval, and fraud modeling. The hardest problems are still ahead: graph embeddings, fraud propagation across the business network, real-time traversal at sub-100ms latency, and expanding beyond finance into any platform that needs to trust a business. **About the Role (KYA: Know Your Agent)** As AI agents act on behalf of people and businesses, identity verification can’t rely on self-asserted signals (API keys, cookies, pixels). Baselayer is building **KYA**, a cryptographic identity substrate that replaces self-assertion with third-party-issued credentials verifiable by any counterparty. You’ll own a meaningful surface of the substrate—such as **issuer mint**, **edge verification**, **Passport**, or a **Merkle audit log**—and ship it to production. **What You’ll Do** - Build and maintain the runtime issuer/mint: OAuth Token Exchange (RFC 8693), JWS credentials (RFC 7515/7519, SD-JWT-VC), and a Merkle audit log with real-time revocation. - Own and evolve the wire format and claim registry: JWT profile, `verification_level`/`verification_method` enums, and eIDAS/NIST IAL/FATF CDD crosswalk. - Implement sub-millisecond JWS verification and Web Bot Auth signature checks (RFC 9421) at the HTTP edge. - Build and maintain **Passport**: canonical handle, KYC/KYB record, authorized-operators list, audit feed, and authenticator binding. - Develop operator integration: embedded KYB onboarding inside first OAuth 2.0 consent, per-operator opt-in, and webhook delivery via Svix. - Work across a Python 3.13 monorepo (FastAPI, Cloud Tasks, Cloud Run, SQLModel/SQLAlchemy) and Go for performance-critical components. **Minimum Requirements** - Shipped systems where cryptographic correctness was load-bearing (e.g., OAuth/OIDC IdP, token issuer, signing service, HSM-backed signer, passkey/WebAuthn flow, or similar). - Fluent in **Python and Go**, or strong in one with a proven track record of learning the other quickly. - Reads RFCs as primary sources; strong opinions on JWK thumbprint canonicalization, pairwise-sub derivation, and Signature-Input header serialization. - Deep understanding of identity vs authorization, mandate vs claim, snapshot vs live state. - Production experience with async Python on Postgres, including migration safety and observability. **What Sets You Apart** - Verifiable credentials / SSI / DID work (especially SD-JWT-VC, OID4VC, or W3C VC stack). - Certificate Transparency / Trillian / append-onl
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.