Role: Policy-as-Code & Authorisation Engineer
Location: Northampton, UK
Days Onsite: 2 - 3 days a week
Role Overview
We are seeking an experienced Policy-as-Code & Authorisation Engineer to design, implement, and operate the policy decision capabilities that sit at the core of a modern authorization platform. The successful candidate will be responsible for developing scalable and maintainable authorization policies using Open Policy Agent (OPA) and Rego, enabling fine-grained access control through centralized, auditable, and high-performance policy decisions. This role combines expertise in authorization architecture, policy engineering, event-driven systems, and platform integration to deliver secure, explainable, and resilient access control solutions.
Key Responsibilities
-
Design, develop, test, and optimize Rego policies using advanced capabilities such as comprehensions, data references, defaults, partial evaluation, and policy modularization.
-
Implement and manage authorization models including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Relationship-Based Access Control (ReBAC).
-
Translate business, compliance, and security requirements into scalable and maintainable policy-as-code solutions.
-
Build, sign, distribute, version, and manage OPA policy bundles, ensuring secure deployment, rollback, and hot-reload capabilities.
-
Integrate OPA with enterprise platforms including Kafka, HTTP services, Vault, identity platforms, and other authorization ecosystem components.
-
Design and implement authorization decision evidence, ensuring decisions are traceable to specific policy versions, entitlement data, and access-control states.
-
Develop scope-based authorization models that return restriction identifiers for downstream enforcement rather than overexposing data.
-
Optimize policy decision performance, latency, and memory utilization for high-volume, real-time authorization workloads.
-
Build supporting Java/Spring Boot services, adapters, APIs, and integration components for policy evaluation platforms.
-
Develop and maintain automated testing frameworks, CI/CD pipelines, and operational dashboards for policy lifecycle management.
-
Collaborate with security, engineering, platform, and product teams to ensure consistent, enterprise-wide authorization standards.
Required Skills & Experience
-
Strong hands-on experience with Open Policy Agent (OPA) and Rego in production or enterprise-scale environments.
-
Deep understanding of authorization architectures, including Policy Decision Points (PDP), Policy Enforcement Points (PEP), Policy Information Points (PIP), and fail-closed security models.
-
Practical experience designing and implementing RBAC, ABAC, and ReBAC authorization frameworks.
-
Expertise in creating, testing, deploying, and governing policy lifecycles through Policy-as-Code methodologies.
-
Strong proficiency in Java and Spring Boot for integration development and supporting authorization services.
-
Experience developing automated policy testing, performance testing, and CI/CD quality-gate controls.
-
Hands-on experience with Apache Kafka, event-driven architectures, and authorization event processing.
-
Experience with Docker, GitLab CI/CD, and containerized application deployment.
-
Strong analytical and troubleshooting skills across complex access-control and identity ecosystems.
-
Proven commitment to Test-Driven Development (TDD) and engineering best practices.
-
Experience using AI-assisted engineering tools such as Claude Code, GitHub Copilot, or equivalent technologies while applying robust validation and governance controls.
Preferred Skills
-
Deep knowledge of OPA plugin architecture, bundle signing, and advanced policy distribution patterns.
-
Experience with policy caching, distributed authorization architectures, and high-performance decision optimization.
-
Familiarity with Envoy ext_authz, Spring Cloud Gateway, or API gateway authorization integrations.
-
Experience in Access Governance, Identity & Access Management (IAM), Entitlement Management, and Audit Controls.
-
Strong understanding of regulated environments such as Banking, Financial Services, Insurance, or Government sectors.
-
Knowledge of observability solutions including OpenTelemetry, Prometheus, Grafana, and distributed tracing frameworks.
Policy-as-Code & Authorisation Engineer in Northampton employer: Capgemini Europe
As a Microsoft Viva Architect in London, you will join a forward-thinking company that prioritises employee experience and innovation. With a strong commitment to professional development, our collaborative work culture fosters continuous learning and growth, while our focus on data-driven solutions ensures that your contributions have a meaningful impact. Enjoy the unique advantage of working in a vibrant city that is at the forefront of technology and business transformation.