远程工作雷达

资深软件工程师,身份与访问管理

Staff Software Engineer, Identity and Access Management

开发工程全球可投(据职位描述推断)
公司kong
薪资163,685 - 245,800 CAD
工作地点Toronto, Canada
地域资格全球可投(据职位描述推断)
时区要求无特别要求
用工类型FullTime
发布时间2026-04-15
数据来源Ashby
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

你准备好解锁智能了吗?

如果你不认为自己完全符合以下所有要求,但仍对这份工作感兴趣,请申请。没有人能完全满足所有条件——我们寻找的是在某些领域特别出色,并且在其他领域有兴趣和能力的候选人。

职位简介:
Kong 正在为开发者构建 API 管理的未来。我们是一家快速成长、资金充足的公司,拥有满意的客户和积极的员工。2019 年收购的 Insomnia 是一个全生命周期的 API 开发平台,已迅速成为 Kong 产品组合中不可或缺的一部分。
作为 Kong Konnect 团队的资深软件工程师,你将设计 Kong Identity 的多租户身份平台,支持复杂的组织层级、跨租户隔离以及企业级安全控制。

你将负责:

- 设计和实现高级令牌管理系统,包括刷新令牌轮换、证明占有令牌,以及具有实时撤销功能的自定义令牌内省。

- 领导 Kong Identity 可扩展声明引擎的开发,支持动态属性解析、上下文声明注入和令牌发放时的复杂业务逻辑评估。

- 构建全球身份基础设施,包括边缘优化、智能令牌缓存和跨区域复制策略,以实现全球范围内的亚毫秒级认证延迟。

- 设计复杂的速率限制、异常检测和欺诈预防系统,以防止凭证填充、令牌滥用和分布式攻击。

- 构建企业身份联合功能,包括 SAML 桥接模式、外部 IdP 链接和用于遗留系统集成的自定义协议适配器。

- 领导 Kong Identity 的开发者体验技术策略,包括 SDK、Webhook、审计日志和实时分析仪表板,以实现令牌生命周期的可视性。

- 构建先进的客户端管理系统,支持动态客户端注册、自动凭证轮换和程序化策略执行。

- 设计 Kong Identity 的插件架构,支持自定义授权流程、协议扩展和第三方集成,同时保持安全边界。

- 推动合规框架(SOC 2、FedRAMP、GDPR)的实施,包括全面的审计追踪、数据驻留控制和隐私保护的令牌设计。

- 领导 Kong Identity 的技术项目,包括身份验证和授权的集成解决方案

查看英文原文

Are you ready to unlock intelligence?

If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

About the Role:
Kong is building the future of API management for developers. We’re a fast-growing, well-funded company with happy customers and motivated employees. Insomnia, acquired in 2019, is a full-lifecycle API development platform that has quickly become an integral part of Kong’s product portfolio.
As a Staff Software Engineer on the Konnect team at Kong, you’ll architect Kong Identity's multi-tenant identity platform supporting complex organizational hierarchies, cross-tenant isolation, and enterprise-grade security controls.

What You'll Do:

- Design and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation capabilities.

- Lead development of Kong Identity's extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business logic evaluation at token issuance.

- Architect global identity infrastructure with edge optimization, intelligent token caching, and cross-region replication strategies for sub-millisecond authentication latency worldwide.

- Design sophisticated rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.

- Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy system integration.

- Lead technical strategy for Kong Identity's developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.

- Architect advanced client management systems supporting dynamic client registration, automated credential rotation, and programmatic policy enforcement.

- Design Kong Identity's plugin architecture enables custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.

- Drive implementation of compliance frameworks (SOC 2, FedRAMP, GDPR), including comprehensive audit trails, data residency controls, and privacy-preserving token designs.

- Lead technical initiatives for Kong Identity's integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.

- Mentor engineering teams on advanced identity concepts including zero-trust architectures, workload identity, and service mesh integration patterns.

What You'll Bring:

- 7+ years of experience building production identity platforms at leading identity providers or enterprise software companies, with proven track record of handling millions of authentication requests daily.

- Deep expertise in advanced OAuth 2.0 extensions (PKCE, mTLS, JWT bearer assertions, token exchange), OpenID Connect profiles, and emerging standards like OAuth 2.1 and GNAP.

- Proven experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise feature sets.

- Strong background in cryptographic protocols including advanced JWT patterns, key rotation strategies, Hardware Security Module (HSM) integration, and post-quantum cryptography considerations.

- Experience building identity platforms with sophisticated analytics, real-time monitoring, and security event detection capabilities at enterprise scale.

- Expertise in global identity infrastructure including edge deployment strategies, geo-distributed token validation, and cross-region data consistency patterns.

- Deep understanding of enterprise identity integration patterns including SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.

- Proven track record building developer-first identity platforms including comprehensive SDKs, webhook systems, and extensible API designs.

- Experience with identity platform security including threat modeling, penetration testing coordination, and implementation of advanced attack prevention mechanisms.

- Strong background in compliance and regulatory requirements for identity systems including audit trail design, data residency controls, and privacy engineering.

- Experience building identity platforms supporting complex organizational structures, delegated administration, and fine-grained permission models.

- Expertise in high-performance system design including horizontal scaling strategies, caching architectures, and latency optimization for identity operations.

- Knowledge of service mesh identity patterns, workload identity bootstrapping, and integration with container orchestration platforms.

- Experience with identity protocol extensions, custom grant flows, and building extensible identity platforms that support diverse use cases.

- Proven ability to lead technical initiatives in complex, regulated environments while balancing innovation with security and compliance requirements.

#LI-AW1

About Kong:

Kong Inc., the AI Connectivity Company, is building the connectivity layer of AI. Trusted by the Fortune 500® and AI-native startups alike, Kong’s unified API and AI platform enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI traffic — on any model, any cloud. For more information, visit www.konghq.com http://www.konghq.com.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

软件工程师

kongToronto, Canada118,000 - 140,000 CADFullTime2026-01-22
开发工程全球可投(据职位描述推断)

← 返回全部职位