Principal Platform Engineer - Identity and Access Management

Principal Platform Engineer - Identity and Access Management

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
IFS

At a Glance

  • Tasks: Lead the design and implementation of cutting-edge identity and access solutions.
  • Company: Join a forward-thinking tech company focused on security and innovation.
  • Benefits: Attractive salary, flexible working options, and opportunities for professional growth.
  • Other info: Dynamic team environment with significant career advancement potential.
  • Why this job: Be at the forefront of shaping secure access solutions that impact users globally.
  • Qualifications: Experience in authorisation systems and enterprise-scale authentication solutions required.

The predicted salary is between 63000 - 77000 £ per year.

As Principal Platform Engineer - Identity & Access Management, you will be the technical authority on authorisation (Auth Z) and authentication (Auth N) across the Kairos and Nexus platforms.

You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for the developers and end-users who rely on them.

This is one of two Principal Platform Engineers being hired into the Identity & Access Management domain, with a strong emphasis on unifying authorisation across IFS hosting environments.

The authorisation problem is complex and high-stakes: it must work consistently across Nexus, F1, and LEC, it must scale to enterprise, multi-tenant workloads, and it is currently a blocker for NGA (Kairos) adoption.

You will work directly with the team building this today (the Authorisation subdomain under Udayanga Silva) and own the technical outcome.

This is a hands‑on engineering role with significant architectural scope.

You will design and implement IAM patterns that are adopted as standards across IFS, and you will work closely with platform, product, and security teams to ensure identity and access are enablers, not bottlenecks.

  • Architect and engineer the unified, enterprise‑scale authorisation platform across Nexus, F1, and LEC, built on Spice DB
  • Design and implement fine‑grained authorisation models: relationship‑based access control (Re BAC / Zanzibar‑inspired), alongside RBAC and ABAC where appropriate
  • Model authorisation schemas, relationships, and permission checks that are correct, performant, and maintainable at scale
  • Own the operation of the authorisation engine: Spice DB on Postgre SQL, including the migration to cloud‑native Postgres (CNPG) and blue‑green deployment support
  • Build the authorisation APIs and SDKs that product teams consume, making correct access control the path of least resistance
  • Architect and engineer enterprise‑scale Auth N solutions, and own the implementation, configuration, and operation of identity provider infrastructure, specifically Curity and/or Keycloak
  • Implement and enforce OAuth 2.0, Open ID Connect (OIDC), and SAML patterns at scale, including token lifecycle management and claims‑based authorisation
  • Define IAM patterns, standards, and golden paths for product teams to implement securely and consistently
  • Integrate identity and access services with the Internal Developer Platform (IDP) to enable self‑service authentication and authorisation configuration
  • Provide subject‑matter expertise on identity and access security to product teams, architects, and security stakeholders
  • Maintain platform identity and access service reliability, performance, and security posture
  • Contribute to the broader platform engineering roadmap with an identity‑and‑access‑first perspective

Qualifications

  • Authorisation (Must Have)
  • Architecting and engineering fine‑grained authorisation systems at production scale, in distributed, multi‑tenant environments
  • Hands‑on production experience with a relationship‑based / policy‑based authorisation engine, ideally Spice DB (or comparable Zanzibar‑inspired systems such as Open FGA, Ory Keto, or equivalent)
  • Deep, practical knowledge of authorisation models: relationship‑based access control (Re BAC), role‑based (RBAC), and attribute‑based (ABAC), and knowing when to apply each
  • Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale
  • Familiarity with policy‑as‑code approaches and tooling (OPA / Rego, Cedar, or equivalent)
  • Understanding of the operational side: running the authorisation engine in production, backed by Postgre SQL, with observability and traceability of authorisation decisions
  • Authentication (Must Have)
  • Architecting and engineering enterprise‑scale Auth N solutions, demonstrated at production scale
  • Hands‑on production experience with Curity and/or Keycloak: configuration, customisation, operations, and integration
  • Deep, practical knowledge of OAuth 2.0, Open ID Connect (OIDC), SAML 2.0, and token‑based authentication patterns (JWT, opaque tokens, token introspection)
  • Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory)

Strong hands‑on engineering capability across the NGA stack, or the ability to get there fast:

  • Backend: Go
  • Messaging / Streaming: Apache Kafka / Red Panda
  • Data: Postgre SQL
  • Comfortable operating in a cloud‑native environment: Kubernetes (AKS), containers, Git Ops, Infrastructure as Code
  • Event‑driven and distributed systems architecture
  • Secure coding practices and security‑by‑design principles
  • Additional Experience
  • Experience architecting and engineering fine‑grained authorisation systems at production scale in distributed, multi‑tenant environments
  • Hands‑on production experience with relationship‑based/policy‑based authorisation engines, ideally Spice DB or comparable Zanzibar‑inspired systems (Open FGA, Ory Keto, etc.)
  • Deep practical knowledge of Re BAC, RBAC, and ABAC authorisation models
  • Experience designing authorisation schemas and permission models with a focus on correctness, latency, and consistency at scale
  • Familiarity with policy‑as‑code tooling such as OPA/Rego or Cedar
  • Experience running authorisation engines in production backed by Postgre SQL
  • Experience architecting and engineering enterprise‑scale Auth N solutions at production scale
  • Hands‑on production experience with Curity and/or Keycloak (configuration, customisation, operations, and integration)
  • Deep practical knowledge of OAuth 2.0, Open ID Connect (OIDC), SAML 2.0, and token‑based authentication patterns (JWT, opaque tokens, token introspection)
  • Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory)
  • Strong engineering capability in Go
  • Experience with Apache Kafka or Red Panda
  • Experience with Postgre SQL
  • Proficiency in cloud‑native environments: Kubernetes (AKS), containers, Git Ops, and Infrastructure as Code
  • Knowledge of event‑driven and distributed systems architecture
  • Adherence to secure coding practices and security‑by‑design principles
  • Demonstrable hands‑on experience designing, building and shipping production AI applications
  • #J-18808-Ljbffr

Principal Platform Engineer - Identity and Access Management employer: IFS

IFS is an exceptional employer that fosters a dynamic work culture where innovation thrives. With a focus on employee growth, we offer extensive opportunities for professional development and a competitive salary package, including flexible paid time off and comprehensive health insurance. Join us in a collaborative environment where your contributions directly impact enterprise customers and the future of AI solutions.

IFS

Contact Details:

IFS Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Platform Engineer - Identity and Access Management

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at IFS or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to IFS.

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like IFS.

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like IFS that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Principal Platform Engineer - Identity and Access Management

Authorisation (AuthZ)
Authentication (AuthN)
Enterprise-scale identity and access solutions
SpiceDB
PostgreSQL
OAuth 2.0
OpenID Connect (OIDC)

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at IFS.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at IFS and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at IFS

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If IFS uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.