高级软件工程师,身份与访问管理
Senior Software Engineer, Identity & Access Management
在DigitalOcean开启职业生涯中最出色的工作。与一支由顶尖人才组成的强大团队共同成长,他们不断追求构建最简单、可扩展的云服务。如果你拥有成长型思维,习惯于大胆思考,并且被真正行业颠覆者的快节奏环境所激励,你将在这里找到属于自己的位置。我们注重协作共赢——在学习中进步,在工作中享受乐趣,并为世界上的梦想家和建设者带来深远的影响。
我们正在寻找一名**高级软件工程师(IC3)**加入我们的**客户信任与工程**团队,负责身份与访问管理(IAM)。IAM是DigitalOcean信任体系的基础;我们的服务处理每一条请求的关键路径,以单位数毫秒的延迟授权每秒数十亿次交易。
在这个职位上,你不仅仅是维护现有系统——你将负责设计下一代身份平台。你将对我们的AI计划提供支持,构建无缝的SSO集成,为全球合作伙伴提供服务,并升级我们的策略引擎以支持复杂的代理工作流。如果你对分布式系统、以安全为先的工程以及超大规模的构建充满热情,这个团队适合你。
### 你将负责
- **设计可扩展架构:** 使用**Go**设计和开发高可用、低延迟的身份验证和授权服务,以应对全球区域的大规模负载波动。
- **推动下一代创新:** 为新兴的云原生AI/ML平台构建IAM基础,设计安全的令牌交换模式和代理AI工作流中的身份上下文注入。
- **现代化身份系统:** 主导OIDC和SAML集成的实施,为企业客户和战略全球合作伙伴提供无缝的联合单点登录(SSO)。
- **解决复杂授权问题:** 升级我们的**策略引擎**(使用Rego/OPA等行业标准),以支持高级的资源级权限、动态作用域和网络感知的访问条件。
- **演进身份模型:** 设计并扩展稳健的多租户数据模型,以管理复杂的层级结构(用户、团队、组织和资源边界),满足企业客户的需求。
- **实现运营卓越:** 对服务可靠性负责,从优化Kubernetes部署到将遗留数据管道迁移到现代事件驱动架构。
- **以安全为先:** 主动识别潜在的安全风险,确保系统始终符合最高安全标准。
查看英文原文
Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
We are seeking a **Senior Software Engineer (IC3)** to join our **Customer Trust & Engineering** team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency.
In this role, you won't just maintain existing systems—you will architect the next generation of our Identity platform. You will be instrumental in supporting our AI initiatives, building seamless SSO integrations for global partners, and evolving our policy engine to support complex, agentic workflows. If you are passionate about distributed systems, security-first engineering, and building at hyperscale, this is the team for you.
### What You’ll Do
- **Architect for Scale:** Design and develop high-availability, low-latency authentication and authorization services in **Go** that scale to handle massive load spikes across global regions.
- **Drive Next-Gen Innovation:** Build the IAM foundations for emerging cloud-native AI/ML platforms, designing secure token exchange patterns and identity context injection for agentic AI workflows.
- **Modernize Identity:** Lead the implementation of OIDC and SAML integrations, enabling seamless federated Single Sign-On (SSO) for enterprise customers and strategic global partners.
- **Solve Complex AuthZ:** Evolve our **Policy Engine** (using industry standards like Rego/OPA) to support advanced resource-level permissions, dynamic scoping, and network-aware access conditions.
- **Evolve Identity Models:** Design and scale robust, multi-tenant data models to manage complex hierarchical structures (users, teams, organizations, and resource boundaries) that map to enterprise customer needs.
- **Operational Excellence:** Take ownership of service reliability, from fine-tuning Kubernetes deployments to migrating legacy data pipelines to modern eventing architectures.
- **Security First:** Proactively identify and remediate complex security vulnerabilities, ensuring our auth flows are resilient against credential stuffing, session hijacking, and configuration theft.
- **Mentor & Lead:** Act as a technical lead for major workstreams, conducting deep code reviews and mentoring junior engineers in distributed systems best practices.
### What You’ll Add to DigitalOcean
- **Experience:** 5+ years of software engineering experience, with at least 2+ years focused on Identity (AuthN/AuthZ), Security Products, or high-scale Distributed Systems.
- **Language Expert:** Expert-level proficiency in **Go** and a strong understanding of **gRPC** microservices architecture.
- **Identity Specialist:** Deep knowledge of identity protocols ( **OIDC, OAuth2, SAML**) and access control models ( **RBAC, ABAC, PBAC**).
- **Distributed Systems Guru:** Proven ability to build systems that handle consensus, replication, and partitioning at cloud scale.
- **Cloud Native:** Working experience with container orchestration (Kubernetes **)**, SQL (MySQL), and Infrastructure as Code (Terraform).
- **Problem Solver:** A track record of "unwinding" complex legacy logic into clean, maintainable abstractions.
- **Communication:** Ability to communicate technical strategy to senior leadership and collaborate across teams (Inference, Billing, DOKS).
### Nice to Have
- Experience with **Open Policy Agent (OPA)** and Rego.
- Familiarity with Cloud-native deployment strategies (Canary/Blue-Green) via kubernetes.
### **Compensation Range:**
- $140,800 - $176,000
*This is a remote role
JR: 2026-7665
_#LI-Remote_
### **Why You’ll Like Working for DigitalOcean**
- **We innovate with purpose.** You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
- **We prioritize career development.** At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
- **We care about your well-being.** Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
- **We reward our employees.** The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
- **DigitalOcean is an equal-opportunity employer.** We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
**Application Limit:** You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.