> Markdown version of [/jobs/ext/1185555-identity-infrastructure-engineer](https://www.wearedevelopers.com/jobs/ext/1185555-identity-infrastructure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Infrastructure Engineer - **Company:** Verda - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, User Authentication, Cloud Computing, Configuration Management, Linux, Identity and Access Management, OAuth, Open Source Technology, OpenID, Public Key Infrastructure, Ansible, Saltstack, Snowflake, Infrastructure Automation Frameworks - **Published:** July 5, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=079f85840fe75ea5 ## About the Role * 5+ Years of Core Experience: Proven track record managing identity management (IDM/IAM) architectures and production secrets distribution networks at scale. * Configuration Management Expertise: Deep operational familiarity with SaltStack and Ansible for infrastructure orchestration. * High-Velocity Mindset: Comfort operating in a fluid, "move fast" environment where fast iterations and rapid deployment cycles are the norm. * Strong Communication: The ability to communicate seamlessly with both infrastructure engineers and security analysts, acting as a translator between policy and code., * Hands-on, production experience specifically deploying or migrating to Kanidm, OpenBao, or step-ca. * Deep familiarity with token design, troubleshooting, and edge cases in OIDC/OAuth setups. * A strong engineering point of view on modern open-source identity alternatives (e.g., Linux Foundation/OpenSSF ecosystems). ## Description In this role, you will become the absolute authority on how identities, credentials, certificates, and secrets are stored and distributed across our cloud infrastructure. You will also serve as the critical engineering liaison to our Security team-bridging the gap between strict security policies and highly automated, real-world infrastructure., * Own the Identity Layer: Champion and manage Kanidm as our central source of truth for authentication, account management, and authorization. * Secure Secrets & PKI: Take ownership of OpenBao for robust, decentralized secrets management and step-ca for automated internal certificate authority operations. * Automate Infrastructure Configuration: Use SaltStack and Ansible to ensure our identity and access management layers are 100% defined as code, removing manual steps and "snowflake" configurations. * Act as the Security Liaison: Partner directly with our Security team to translate compliance and threat-modeling requirements into production-ready engineering solutions. * Streamline Authentication: Architect and implement clean, secure OIDC and OAuth integrations across our expanding suite of internal tools and systems., * Cash + equity compensation along with various fringe benefits (e.g., healthcare, lunch, wellbeing, etc.). * Profitable operations with rapid, sustained growth. * 31 nationalities, with 6 different ones on the management team. * An opportunity to make a clear impact and work alongside world-class engineers, researchers, and partners across the global AI ecosystem. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems](https://www.wearedevelopers.com/videos/928-break-the-chain-decentralized-solutions-for-today-s-web2-0-privacy-problems) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)