Software Engineer

Replit

Full TimeNot specifiedPosted 1 day ago

Let the right jobs find you

Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.

Overview

Position Type

Full Time

Experience

Not specified

Job Description

About the Role

As a Software Engineer, you will design, build, and operate the identity and authorization systems that protect critical interactions on Replit, including Agent acting on behalf of a user or holding their own identity.

The work is guided by a few simple questions:

  • Can every protected request prove which workload made it, which principal it represents, and who is acting on that principal's behalf?
  • Can product teams express policy once and trust the same decision across web, mobile, Agent, and internal services?
  • Can enterprise administrators control who can access each workspace, app, connector, and Agent capability without navigating a permission maze as well as having a legible ledger of decisions?
  • Can Agent act for a user across long-running and durable work without receiving broad or long-lived credentials?
  • Are identity and authorization fast, reliable, highly available, and observable enough for the product flows that depend on them?

What you'll do

  • Design and operate central authorization interfaces with typed principals, actions, resources, decisions, explainable deny reasons, privilege attenuation, delegations, and obligations
  • Evolve enterprise roles, groups, app access, entitlements, and workspace policy so common cases stay simple and advanced cases remain possible
  • Build and operate Replit's Security Token Service and workload identity using OAuth 2.0 token exchange, JWT/OIDC, SPIFFE/SPIRE, and mTLS
  • Threat-model delegation, confused-deputy risks, and cross-tenant movement, then make secure, fail-closed behavior the default
  • Lead compatible migrations with shadow evaluation, feature gates, telemetry, and rollback plans, and own the SLOs, incidents, and operational health of the systems you ship
  • Partner with Agent, Connectors, Enterprise, Security, and Infrastructure teams to turn product requirements into shared platform primitives
  • Research and develop new innovative approaches to Authx in the Agentic world

Required skills and experience

  • Experience shipping and operating security-sensitive backend or distributed systems in production, including reliability, performance, incidents, and observability
  • Depth in authentication, authorization, or identity systems, such as OAuth 2.0/OIDC, JWT, mTLS, Identity Federation, RBAC, ReBAC, PBAC, Zanzibar, Macaroons, Biscuits, Cedar, or policy engines. You do not need prior experience with every item
  • Strong understanding of multi-tenant security, least privilege, delegation, privilege attenuation, auditability, and threat modeling
  • Experience migrating security-sensitive systems without breaking callers. Approaches can include typed contracts, shadow evaluation, and staged enforcement
  • Fluent in at least one production backend stack. Our systems use TypeScript, Go, Rust, Postgres, gRPC/Protobuf, Kubernetes, Envoy, and Restate
  • Able to make and communicate tradeoffs across security, reliability, latency, product experience, delivery speed, and long-term maintainability

If you're excited about this role but don't meet every requirement, we still encourage you to apply.

Required Skills

Security Sensitive Backend SystemsAuthenticationAuthorizationIdentity SystemsMulti Tenant SecurityLeast PrivilegeDelegationPrivilege AttenuationAuditabilityThreat ModelingMigration SystemTypescriptGoRustPostgresql

About the Company

Replit

Foster City, United States

Share This Job