Policy-as-Code & Authorisation Engineer in Northampton

Policy-as-Code & Authorisation Engineer in Northampton

Northampton Full-Time On-site
Capgemini Europe

Role: Policy-as-Code & Authorisation Engineer
Location: Northampton, UK
Days Onsite: 2 - 3 days a week

Role Overview

We are seeking an experienced Policy-as-Code & Authorisation Engineer to design, implement, and operate the policy decision capabilities that sit at the core of a modern authorization platform. The successful candidate will be responsible for developing scalable and maintainable authorization policies using Open Policy Agent (OPA) and Rego, enabling fine-grained access control through centralized, auditable, and high-performance policy decisions. This role combines expertise in authorization architecture, policy engineering, event-driven systems, and platform integration to deliver secure, explainable, and resilient access control solutions.

Key Responsibilities

  • Design, develop, test, and optimize Rego policies using advanced capabilities such as comprehensions, data references, defaults, partial evaluation, and policy modularization.

  • Implement and manage authorization models including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Relationship-Based Access Control (ReBAC).

  • Translate business, compliance, and security requirements into scalable and maintainable policy-as-code solutions.

  • Build, sign, distribute, version, and manage OPA policy bundles, ensuring secure deployment, rollback, and hot-reload capabilities.

  • Integrate OPA with enterprise platforms including Kafka, HTTP services, Vault, identity platforms, and other authorization ecosystem components.

  • Design and implement authorization decision evidence, ensuring decisions are traceable to specific policy versions, entitlement data, and access-control states.

  • Develop scope-based authorization models that return restriction identifiers for downstream enforcement rather than overexposing data.

  • Optimize policy decision performance, latency, and memory utilization for high-volume, real-time authorization workloads.

  • Build supporting Java/Spring Boot services, adapters, APIs, and integration components for policy evaluation platforms.

  • Develop and maintain automated testing frameworks, CI/CD pipelines, and operational dashboards for policy lifecycle management.

  • Collaborate with security, engineering, platform, and product teams to ensure consistent, enterprise-wide authorization standards.

Required Skills & Experience

  • Strong hands-on experience with Open Policy Agent (OPA) and Rego in production or enterprise-scale environments.

  • Deep understanding of authorization architectures, including Policy Decision Points (PDP), Policy Enforcement Points (PEP), Policy Information Points (PIP), and fail-closed security models.

  • Practical experience designing and implementing RBAC, ABAC, and ReBAC authorization frameworks.

  • Expertise in creating, testing, deploying, and governing policy lifecycles through Policy-as-Code methodologies.

  • Strong proficiency in Java and Spring Boot for integration development and supporting authorization services.

  • Experience developing automated policy testing, performance testing, and CI/CD quality-gate controls.

  • Hands-on experience with Apache Kafka, event-driven architectures, and authorization event processing.

  • Experience with Docker, GitLab CI/CD, and containerized application deployment.

  • Strong analytical and troubleshooting skills across complex access-control and identity ecosystems.

  • Proven commitment to Test-Driven Development (TDD) and engineering best practices.

  • Experience using AI-assisted engineering tools such as Claude Code, GitHub Copilot, or equivalent technologies while applying robust validation and governance controls.

Preferred Skills

  • Deep knowledge of OPA plugin architecture, bundle signing, and advanced policy distribution patterns.

  • Experience with policy caching, distributed authorization architectures, and high-performance decision optimization.

  • Familiarity with Envoy ext_authz, Spring Cloud Gateway, or API gateway authorization integrations.

  • Experience in Access Governance, Identity & Access Management (IAM), Entitlement Management, and Audit Controls.

  • Strong understanding of regulated environments such as Banking, Financial Services, Insurance, or Government sectors.

  • Knowledge of observability solutions including OpenTelemetry, Prometheus, Grafana, and distributed tracing frameworks.

Policy-as-Code & Authorisation Engineer in Northampton employer: Capgemini Europe

As a Microsoft Viva Architect in London, you will join a forward-thinking company that prioritises employee experience and innovation. With a strong commitment to professional development, our collaborative work culture fosters continuous learning and growth, while our focus on data-driven solutions ensures that your contributions have a meaningful impact. Enjoy the unique advantage of working in a vibrant city that is at the forefront of technology and business transformation.

Capgemini Europe

Contact Details:

Capgemini Europe Recruitment Team