Senior Software Engineer II - Identity & Access Management
DigitalOcean
- Location
- Bengaluru
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 3 approvals (FY2023)
- Posted
- 3h ago
Skills
About this role
Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a Senior Software Engineer to join our Customer Trust & Engineering team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency.
In this role, you will set the technical direction for DigitalOcean's Identity platform not just for the IAM team, but across the engineering organization. You will define the architecture for our next-generation identity primitives, drive cross-org alignment on how identity intersects with AI workloads, billing, and access governance, and establish the engineering standards that the team builds against. If you are a seasoned engineer who wants to combine deep technical expertise with broad organizational impact, this is the role for you.
What You'll Do
• Define Platform Architecture: Set the technical direction for DigitalOcean's Identity platform; designing for hyperscale, multi-tenancy, and the evolving requirements of AI-native enterprise customers. Your architecture decisions will span multiple teams and multi-year roadmaps.
• Lead Agent Identity Strategy: Architect the IAM foundations for agentic AI workloads; including workload identity (SPIFFE/SPIRE-style), short-lived credential issuance, delegation chains, and identity context propagation across inference pipelines. This is greenfield, high-impact work.
• Drive Protocol Adoption: Own the technical strategy for identity protocol adoption across DigitalOcean; evaluating and standardizing on OIDC, SAML, SCIM, and emerging standards; driving federation architecture for strategic enterprise and global partners.
• Evolve the Policy Engine: Define the long-term architecture of our authorization layer; including compound RBAC/ABAC/PBAC models, hierarchical resource scoping, and network-aware access conditions; ensuring it scales to serve both platform-internal and customer-facing use cases.
• Shape Cross-Org Technical Decisions: Serve as a primary technical voice in cross-functional design reviews spanning IAM, Inference, Billing, and DOKS. Identify and resolve architectural conflicts before they become production incidents.
• Establish Engineering Standards: Define and socialize engineering best practices for the IAM domain; from credential lifecycle management to policy authoring patterns — that raise the floor for the entire team.
• Mentor Senior Engineers: Coach IC2 and IC3 engineers on system design, security engineering, and technical communication; serve as a multiplier for the team's overall capability.
• Translate Strategy to Leadership: Communicate identity platform strategy and investment rationale to senior leadership (VP, CISO, CPTO level), framing technical decisions in terms of security posture, customer trust, and business impact.
What You’ll Add to DigitalOcean
• Experience: 7+ years of software engineering experience, with 3+ years focused on Identity (AuthN/AuthZ), Security Products, or high-scale Distributed Systems at cloud or enterprise scale.
• Language Expert: Expert-level