Staff Software Engineer (Platform - Access & Authorization)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
As a Staff Software Engineer on the Access & Authorization team within the https://www.coinbase.com/careers/product-groups group, you’ll help shape the systems customers use to securely access Coinbase. This team builds and operates distributed services at the intersection of security, identity, developer infrastructure, and customer experience. You’ll design foundational authentication and authorization capabilities that balance strong security with a simple experience, creating leverage across every Coinbase product and partner integration.
What you’ll do:
-
Own end-to-end design, implementation, and operation of capabilities across authentication, OAuth, sessions, tokens, 2FA, account recovery, and edge authorization.
-
Build secure, low-latency Go and gRPC services used across Coinbase’s web, mobile, API, and partner experiences, with strong observability, failure testing, and measurable SLOs.
-
Lead technical designs for complex initiatives such as signed authorization tokens, passkeys, biometric recovery, device-aware authentication, and mobile OAuth.
-
Partner with product, security, fraud, and infrastructure teams to balance customer conversion, account protection, regulatory requirements, and engineering constraints.
-
Simplify integration patterns and build self-service tooling that enables product teams to adopt access and authorization capabilities safely at scale.
-
Mentor engineers and raise the technical bar through design reviews, pairing, code reviews, and on-call participation.
Requirements
-
8+ years of backend software engineering experience with strong proficiency in Go or a comparable systems-oriented language, including building and operating reliable, high-throughput distributed services in production.
-
Demonstrated experience designing secure APIs and reasoning about authentication, authorization, session management, trust boundaries, and token handling (OAuth 2.0, OpenID Connect, JWTs, PKCE, or related standards).
-
Proficiency with gRPC, Protocol Buffers, and data stores such as Redis or DynamoDB, with strong operational instincts using metrics, logs, traces, alerts, and SLOs to run critical services.
-
Track record of delivering complex, cross-functional projects from technical design through production rollout, with clear written and verbal communication
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Highest Paying Tech Companies for Developers
20 Essential Tools For Backend Development
Find a Developer Job: 12 Best Job Sites For Developers