> Markdown version of [/jobs/ext/1343951-software-engineer-identity-access-management](https://www.wearedevelopers.com/jobs/ext/1343951-software-engineer-identity-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer, Identity & Access Management - **Company:** Hadrian Automation - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $192,000.0 - $273,500.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing, Distributed Systems, Identity and Access Management, Python (Programming Language), Key Management, Network Architecture, OAuth, OpenID, Systems Development Life Cycle, Role-Based Access Control, Openid Connect, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Engineering, Policy as Code, Google Cloud, Cloud Platform System, Multi-Cloud, Kubernetes, Information Technology, Api Management - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7f71372f2057280d ## About the Role * 8-12+ years in software engineering, with 3+ years of focused experience in identity, authentication, or authorization systems at scale * Deep, hands-on expertise in modern auth protocols: OAuth 2.0, OpenID Connect (OIDC), SAML, and SCIM * Strong understanding of access control models - RBAC, ABAC, and ReBAC - and the ability to make sound architectural tradeoffs between them * Experience designing IAM systems across multi-cloud environments (AWS, GCP, Azure) * Security-first mindset: you understand threat modeling, risk assessment, and least-privilege principles, and you embed security throughout the SDLC * Proficiency in Go, Python, or similar; track record of writing high-quality, maintainable code * Ability to set technical direction independently, write clear design docs, and drive alignment across teams * Comfort working alongside a PM counterpart - you can divide technical and product ownership clearly and collaborate effectively * Bachelor's degree in Computer Science or related field, or equivalent experience What Will Set You Apart * Experience building IAM systems that serve external developer ecosystems - not just internal users * Experience building identity systems for non-human entities: service accounts, workload identity, machine certificates, Kubernetes service accounts * Familiarity with policy-as-code frameworks (OPA, Casbin, or similar) * Experience with zero-trust network architecture * Hands-on experience with secrets management platforms (Vault or equivalent) at scale * Prior experience in aerospace, defense, or manufacturing environments with ITAR or export control considerations * Experience working alongside a PM on a developer-facing platform product ## Description Hadrian's API Platform is how the outside world connects to our manufacturing systems. Every partner integration, every internal service, and every factory floor system that touches that platform depends on one thing being right: identity. Who is allowed in, what they can do, and how credentials are managed across a complex, multi-cloud, physically distributed environment. As Staff Software Engineer, Identity and Access Management, you will build the security foundation that the API Platform is built on. You will own authentication, authorization, and credential automation across cloud infrastructure, Kubernetes workloads, and factory floor systems - and you will work in close partnership with the API Platform PM to ensure that IAM capabilities are surfaced as first-class developer experiences, not bolted-on compliance requirements. This is not a supporting role. IAM is a product pillar here. You will own the technical layer end to end, set the direction for how it scales, and help define what secure-by-default looks like across everything Hadrian builds. What You'll Do * Design and implement scalable authentication and authorization systems covering both human operators and machine identities across cloud and factory floor environments - serving as the security foundation for the API Platform * Own Hadrian's authentication stack: SSO, MFA, OIDC/SAML integrations, and service-to-service auth across AWS, GCP, and future cloud environments * Build fine-grained access control systems (RBAC/ABAC/ReBAC) that scale across internal engineering teams, factory systems, and external API partners * Develop frameworks, APIs, and CLI tools that automate credential provisioning, rotation, and policy enforcement for both internal teams and external API consumers * Build identity and access models for machine-to-machine communication across factory floor systems, Kubernetes workloads, and cloud services * Partner with Security to ensure IAM systems meet compliance and audit requirements; troubleshoot complex identity and access issues across distributed systems * Work with the API Platform PM to define how IAM capabilities are surfaced as developer-friendly product experiences - for internal engineers and external partners alike * Build tooling, SDKs, and documentation that make it easy to integrate with IAM correctly and hard to do so incorrectly * Set IAM standards across the engineering org and act as the domain expert on access-sensitive architecture decisions, This is a founding role with a clear path upward. As Hadrian's API Platform scales and the IAM function grows in complexity - more factory locations, more partners, more systems - so does the scope of this role. The natural trajectory leads toward technical lead or architect of a broader Security and Identity platform org, with the potential to grow a team around you. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event)