We are looking for a Senior Java Backend Engineer with deep, hands-on experience designing, building, and operating authentication and authorization services. You'll work at the heart of…
About the role
We are looking for a Senior Java Backend Engineer with deep, hands-on experience designing, building, and operating authentication and authorization services. You'll work at the heart of our identity platform, shaping how millions of users securely access our products and help us push our IAM capabilities to the next level.
## What you'll do
- Design, build, and operate IAM capabilities on Keycloak and Java microservices
- Extend Keycloak through custom SPIs, providers, user federation, and themes to meet evolving business requirements
- Implement and maintain authentication and authorization flows using OAuth 2.0, OpenID Connect, SAML, MFA, and social or enterprise federation
- Drive security best practices, including secure token handling, session management, threat modeling, and supporting audits and compliance
- Own services in production, from design through deployment, observability, and incident response
- Collaborate with product, security, and platform teams to deliver reliable, scalable identity solutions
## What you bring
- Strong Java backend development experience, building and running microservices in production
- Proven, hands-on experience with Keycloak in real-world deployments, including customization via SPIs and providers
- Deep understanding of OAuth 2.0, OpenID Connect, JWT, and SAML
- Proven experience designing and operating distributed systems and microservices in production
- Solid database skills (e.g., PostgreSQL) and familiarity with caching relevant to Keycloak deployments (e.g., Infinispan/Redis)
- Experience with Docker, Kubernetes, CI/CD pipelines, and at least one major cloud platform (AWS or Azure)
- A security-first mindset and experience supporting audits and compliance requirements
Nice to have
- Experience with CIAM at scale: customer identity, identity resolution, or account deduplication
- WebAuthn/FIDO2/passkeys, Zero Trust architectures, or PKI
- Event-driven architectures (e.g., Kafka)
- Observability tooling such as Prometheus, Grafana, and OpenTelemetry
Öppen för alla
Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.


