Staff Software Engineer, Identity & Access Management

Robinhood
Menlo Park, CA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$230,000.0 - $270,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Architectural Patterns Cloud Computing Cyber Security Identity and Access Management Python (Programming Language) OAuth Public Key Infrastructure Role-Based Access Control Openid Connect Zero Trust Network Access
+5 more
Security Assertion Markup Language (SAML) Systems Architecture Large Language Models Backend Kubernetes

Job description

The Security Engineering team builds the identity and access control plane governing how employees, services, and agentic workloads access Robinhood’s critical infrastructure. We are a platform-building engineering team focused on creating secure, frictionless, and automated self-service access systems at scale.

As a Staff Software Engineer on this team, you will shape Robinhood’s foundational identity architecture, define technical strategy, and build Tier-0 access infrastructure used across the entire company! From solving complex authentication and authorization challenges to setting secure guardrails for emerging AI and agentic workflows, your technical leadership will directly impact every product team at Robinhood!, * Access Control Plane Architecture: Define and build the core technical architecture for managing employee, service, non-human, and agentic access across company-wide resources

  • Tier-0 Platform Engineering: Design, build, and operate highly available, resilient, and observable backend identity infrastructure using Go, Python, Rust, or comparable systems languages.
  • AuthN & AuthZ Solutions: Implement modern identity protocols and access frameworks (OAuth 2.0, OpenID Connect, RBAC, ABAC, and policy-based access controls).
  • AI & Agentic Access Governance: Develop secure access patterns, identity frameworks, governance, and observability guardrails for AI agents, LLM applications, and Model Context Protocol (MCP) systems.
  • Self-Service Developer Experience: Create automated, developer-friendly platforms that allow teams to request, approve, provision, and audit access without manual security operations friction.
  • Leadership: Set technical direction, author key architectural proposals, mentor engineers across the org, and partner closely with Infrastructure, Data, and Security teams.

Requirements

  • 8+ years of backend engineering or security platform engineering experience, with a focus on building systems at scale.
  • Platform-Builder Expertise: Demonstrated experience designing and building security platforms, access management control planes, or identity infrastructure from the ground up (rather than security operations or third-party tool administration).
  • Identity Domain Depth: Strong understanding of core identity primitives, least-privilege access, and protocols such as OAuth 2.0, OpenID Connect, SAML, or WebAuthn.
  • Modern Auth Models: Experience implementing role-based, policy-based, or attribute-based access control models across human and machine workloads.
  • AI / Non-Human Workload Exposure: Experience or strong foundational capability in defining security guardrails, access policies, or governance models for AI agents, LLMs, or non-human workloads.
  • Systems Architecture: Experience operating and maintaining high-availability, high-throughput Tier-0 infrastructure in cloud-native environments (AWS, Kubernetes).
  • Strategic Influence: Proven track record of technical ownership, cross-functional alignment without authority, and driving multi-team initiatives to completion., * Background in cryptography, PKI, and certificate lifecycle management.
  • Experience implementing zero-trust architectural models.
  • Prior experience building identity or authorization platforms within high-growth technology environments.

Benefits & conditions

Pulled from the full job description

  • Parental leave
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Disability insurance
  • Paid holidays, * Performance-driven compensation with multipliers for outsized impact, bonus programs, equity ownership, and 401(k) matching.
  • Best-in-class benefits to fuel your work, including 100% paid health insurance for employees with 90% coverage for dependents.
  • Lifestyle wallet - a highly flexible benefits spending account for wellness, learning, and more.
  • Employer-paid life & disability insurance, fertility benefits, and mental health benefits.
  • Time off to recharge including company holidays, paid time off, sick time, parental leave, and more!
  • Exceptional office experience with catered meals, events, and comfortable workspaces.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:38 min

Transitioning into backend engineering from web development

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all