Staff Software Engineer (Platform - Access & Authorization)

Coinbase, Inc.
Topeka, KS, United States
10 days ago
Apply on www.kansasworks.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) User Authentication Code Review Data Stores Amazon DynamoDB Protocol Buffers OAuth Redis Openid Connect Session Management Software Engineering User-Centered Design
+2 more
Backend Grpc

Job description

As a Staff Software Engineer on the Access & Authorization team within the https://www.coinbase.com/careers/product-groups group, you’ll help shape the systems customers use to securely access Coinbase. This team builds and operates distributed services at the intersection of security, identity, developer infrastructure, and customer experience. You’ll design foundational authentication and authorization capabilities that balance strong security with a simple experience, creating leverage across every Coinbase product and partner integration.

What you’ll do:

  • Own end-to-end design, implementation, and operation of capabilities across authentication, OAuth, sessions, tokens, 2FA, account recovery, and edge authorization.

  • Build secure, low-latency Go and gRPC services used across Coinbase’s web, mobile, API, and partner experiences, with strong observability, failure testing, and measurable SLOs.

  • Lead technical designs for complex initiatives such as signed authorization tokens, passkeys, biometric recovery, device-aware authentication, and mobile OAuth.

  • Partner with product, security, fraud, and infrastructure teams to balance customer conversion, account protection, regulatory requirements, and engineering constraints.

  • Simplify integration patterns and build self-service tooling that enables product teams to adopt access and authorization capabilities safely at scale.

  • Mentor engineers and raise the technical bar through design reviews, pairing, code reviews, and on-call participation.

Requirements

  • 8+ years of backend software engineering experience with strong proficiency in Go or a comparable systems-oriented language, including building and operating reliable, high-throughput distributed services in production.

  • Demonstrated experience designing secure APIs and reasoning about authentication, authorization, session management, trust boundaries, and token handling (OAuth 2.0, OpenID Connect, JWTs, PKCE, or related standards).

  • Proficiency with gRPC, Protocol Buffers, and data stores such as Redis or DynamoDB, with strong operational instincts using metrics, logs, traces, alerts, and SLOs to run critical services.

  • Track record of delivering complex, cross-functional projects from technical design through production rollout, with clear written and verbal communication

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.kansasworks.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:18 min

Prioritizing communication and structural awareness over strict tool mastery

Liam Hurrel +1 · World Congress 2021

4:56 min

Establishing internal service communication with gRPC

Florian Bader Florian Bader · World Congress 2026 Europe

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:55 min

Demonstrating semantic routing thresholds with the Redis vector library

1:41 min

Designing internal developer platforms and product team responsibilities

Romano Roth Romano Roth · World Congress 2025

1:11 min

Evaluating architectural trade-offs between REST and gRPC

Sakshi Nasha Sakshi Nasha · Europe 2026 Virtual

Videos

See all

Related articles

See all