At a Glance
- Tasks: Build and operate cutting-edge identity infrastructure for a next-gen platform.
- Company: Join IFS, a billion-dollar tech company transforming enterprise software.
- Benefits: Flexible work options, competitive salary, and opportunities for professional growth.
- Other info: Be part of a diverse team committed to innovation and sustainability.
- Why this job: Make a real impact by solving complex authorisation challenges in a dynamic environment.
- Qualifications: Experience with fine-grained authorisation systems and enterprise-scale authentication solutions.
The predicted salary is between 63000 - 77000 £ per year.
At IFS, we're building the next generation of AI-native enterprise software, transforming how some of the world's largest organisations manage assets, operations and critical services.
This role is about building and operating identity infrastructure, not administering it or governing it. It is not a fit if your identity experience is:
- Managing Entra ID, Okta or AWS IAM as a consumer of a platform someone else operates
- Identity governance and administration: SailPoint, Saviynt, joiner-mover-leaver, access certification campaigns, provisioning workflows
- Security governance, IAM audit, policy authoring or architecture-only work
- Kubernetes RBAC and cloud IAM policies as part of a DevOps or SRE role
It is a fit if you have personally run an identity provider in production. Installed it, configured it, extended it, upgraded it, sized it, cut over between versions, restored it, and been on call when authentication broke at three in the morning. If you have done that with Curity, we want to talk to you today.
This is a hands-on role and we expect you to still be writing code. We also expect that AI tooling has changed how you work. We'll ask what you delegate, what you still do yourself, and what you built to stop it breaking. Specifics, not a list of tools... so if you can evidence the correct experience for our role, please read on.
IFS is a billion-dollar revenue company with 7000+ employees on all continents. We deliver award-winning enterprise software solutions through the use of embedded digital innovation and a single cloud-based platform to help businesses be their best when it really matters–at the Moment of Service™.
At IFS, we're flexible, we're innovative, and we're focused not only on how we can engage with our customers, but on how we can make a real change and have a worldwide impact. We help solve some of society's greatest challenges, fostering a better future through our agility, collaboration, and trust.
We celebrate diversity and accept that there are so many different perspectives in this world. As a truly international company serving people from around the globe, we realise that our success is tantamount to the respect we have for those different points of view.
By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world.
We're looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs. If you want to change the status quo, we'll help you make your moment. Join Team Purple. Join IFS.
The job: Authorisation is the single biggest blocker to our next-generation platform right now. Two Principal Platform Engineers are joining to unblock it. We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud. It is built on SpiceDB (relationship-based access control) on PostgreSQL, and it has to be correct, fast, and multi-tenant at enterprise scale. Alongside it, we run enterprise authentication on Curity, with Keycloak estates migrating onto it.
You will architect and build that, own it in production, and set the identity patterns the rest of engineering follows. This is a hands-on engineering role. You will write Go.
What we need to see:
- Fine-grained authorisation systems you have built and run at production scale, in distributed multi-tenant environments
- Hands-on production experience with a Zanzibar-style authorisation engine: SpiceDB, OpenFGA, Ory Keto or equivalent
- Authorisation schemas and permission models you have designed, and the ability to reason about correctness, latency and consistency together
- ReBAC, RBAC and ABAC, and a view on when each is the right answer
- Policy-as-code exposure: OPA/Rego, Cedar or similar
- Running the authorisation engine in production on PostgreSQL, with observability and traceability of the decisions it makes
- Enterprise-scale authentication you have architected and operated, not integrated with
- Hands-on production Curity and/or Keycloak: configuration, customisation, extensions, upgrades, operations
- OAuth 2.0, OIDC, SAML 2.0 and token patterns at a level where you can explain why a given flow, what its failure modes are, and where PKCE belongs
- Enterprise federation, SSO and directory integration, in a bring-your-own-identity model with per-tenant signing keys
- Identity infrastructure on Kubernetes (AKS): Helm, persistent volumes, blue/green cutovers, backup and restore, DR
- An IdP under load: config import latency, JVM tuning, pod sizing, dedicated node pools, and a story about what fell over and how you found it
- Go, PostgreSQL, Kafka/RedPanda, GitOps, IaC. Exact match not required, ability to get there fast is
- You still write code. These are principal engineers who build, not IAM consultants who produce documents
How we work: We expect that AI tooling has changed how you work. We will ask what you delegate, what you still do yourself, and what you built to stop it breaking. Specifics, not a list of tools. We want strong opinions, held out loud. If you would not push back on your director in week two, this will not suit you.
Qualifications:
- Architecting and engineering fine-grained authorisation systems at production scale, in distributed, multi-tenant environments
- Hands-on production experience with a relationship-based / policy-based authorisation engine, ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent)
- Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each
- Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale
- Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent)
- Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions
- Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale
- Hands-on production experience with Curity and/or Keycloak: configuration, customisation, operations, and integration
- Deep, practical knowledge of OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and token-based authentication patterns (JWT, opaque tokens, token introspection)
- Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory)
- Strong hands-on engineering capability across the NGA stack, or the ability to get there fast: Backend: Go Messaging / Streaming: Apache Kafka / RedPanda Data: PostgreSQL
- Comfortable operating in a cloud-native environment: Kubernetes (AKS), containers, GitOps, Infrastructure as Code
- Event-driven and distributed systems architecture
- Secure coding practices and security-by-design principles
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
Principal Platform Engineer || Identity Platform (AuthN/AuthZ) employer: IFS
As a leading employer in the tech industry, we pride ourselves on fostering a collaborative and inclusive workplace where innovation thrives. Our hybrid work model supports diverse lifestyles, while our commitment to engineering excellence and responsible AI practices ensures that you will be part of meaningful projects that drive customer value. With ample opportunities for professional growth and mentorship within our Enterprise Asset Management team, you'll be empowered to develop your skills and make a significant impact in the world of software engineering.
StudySmarter Expert Advice🤫
We think this is how you could land Principal Platform Engineer || Identity Platform (AuthN/AuthZ)
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at IFS or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to IFS.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like IFS.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like IFS that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Principal Platform Engineer || Identity Platform (AuthN/AuthZ)
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at IFS.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at IFS and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at IFS
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If IFS uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.