Software Engineer II - Identity & Access Management
DigitalOcean
- Location
- Bengaluru
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 3 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a Software Engineer II to join our Customer Trust & Engineering team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency.
In this role, you will contribute meaningfully to building and maintaining the systems that power DigitalOcean's identity platform. You will work within established technical frameworks, implement features against well-scoped designs, and grow your expertise in distributed systems and security engineering. If you are passionate about writing clean, reliable code and want to develop deep expertise in identity and access management, this is the team for you.
What You'll Do
• Build & Extend: Implement features and bug fixes across DigitalOcean's authentication and authorization services in golang, working within established architectural patterns and contributing to a high-reliability, low-latency platform.
• Contribute to Identity Systems: Work on OIDC and OAuth2 integrations, learning the protocols deeply and contributing to reliable, well-tested implementations.
• Modernize Identity: Lead the implementation of OIDC and SAML integrations, enabling seamless federated Single Sign-On (SSO) for enterprise customers and strategic global partners.
• Solve Complex AuthZ: Evolve our Policy Engine (using industry standards like Rego/OPA) to support advanced resource-level permissions, dynamic scoping, and network-aware access conditions.
• Learn & Grow: Partner with senior engineers to develop your understanding of distributed systems, identity protocols, and security engineering — building the skills to take on increasing ownership over time.
• Collaborate Cross-Functionally: Work with teammates across IAM, Billing, and Inference teams to understand how your work fits into the broader platform.
• Operational Excellence: Take ownership of service reliability, from fine-tuning Kubernetes deployments to migrating legacy data pipelines to modern eventing architectures.
• Security First: Proactively identify and remediate complex security vulnerabilities, ensuring our auth flows are resilient against credential stuffing, session hijacking, and configuration theft.
What You’ll Add to DigitalOcean
• Experience: 2–4 years of software engineering experience, with a strong foundation in building and shipping production services.
• Language Proficiency: Proficiency in Go or a strong background in another typed systems language with demonstrated ability to ramp quickly.
• Identity Familiarity: Working knowledge of at least one identity protocol (OIDC, OAuth2); familiarity with SAML or access control models (RBAC, ABAC) is a plus.
• Systems Thinking: