> Markdown version of [/jobs/ext/2518616-staff-software-engineer-identity-access-management](https://www.wearedevelopers.com/jobs/ext/2518616-staff-software-engineer-identity-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Software Engineer, Identity & Access Management - **Company:** Robinhood - **Location:** Menlo Park, CA, United States - **Experience:** Expert - **Salary:** $230,000.0 - $270,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Architectural Patterns, Cloud Computing, Cyber Security, Identity and Access Management, Python (Programming Language), OAuth, Public Key Infrastructure, Role-Based Access Control, Openid Connect, Zero Trust Network Access, Security Assertion Markup Language (SAML), Systems Architecture, Large Language Models, Backend, Kubernetes - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0cfce4fb9d38fc21 ## About the Role * 8+ years of backend engineering or security platform engineering experience, with a focus on building systems at scale. * Platform-Builder Expertise: Demonstrated experience designing and building security platforms, access management control planes, or identity infrastructure from the ground up (rather than security operations or third-party tool administration). * Identity Domain Depth: Strong understanding of core identity primitives, least-privilege access, and protocols such as OAuth 2.0, OpenID Connect, SAML, or WebAuthn. * Modern Auth Models: Experience implementing role-based, policy-based, or attribute-based access control models across human and machine workloads. * AI / Non-Human Workload Exposure: Experience or strong foundational capability in defining security guardrails, access policies, or governance models for AI agents, LLMs, or non-human workloads. * Systems Architecture: Experience operating and maintaining high-availability, high-throughput Tier-0 infrastructure in cloud-native environments (AWS, Kubernetes). * Strategic Influence: Proven track record of technical ownership, cross-functional alignment without authority, and driving multi-team initiatives to completion., * Background in cryptography, PKI, and certificate lifecycle management. * Experience implementing zero-trust architectural models. * Prior experience building identity or authorization platforms within high-growth technology environments. ## Description The Security Engineering team builds the identity and access control plane governing how employees, services, and agentic workloads access Robinhood's critical infrastructure. We are a platform-building engineering team focused on creating secure, frictionless, and automated self-service access systems at scale. As a Staff Software Engineer on this team, you will shape Robinhood's foundational identity architecture, define technical strategy, and build Tier-0 access infrastructure used across the entire company! From solving complex authentication and authorization challenges to setting secure guardrails for emerging AI and agentic workflows, your technical leadership will directly impact every product team at Robinhood!, * Access Control Plane Architecture: Define and build the core technical architecture for managing employee, service, non-human, and agentic access across company-wide resources * Tier-0 Platform Engineering: Design, build, and operate highly available, resilient, and observable backend identity infrastructure using Go, Python, Rust, or comparable systems languages. * AuthN & AuthZ Solutions: Implement modern identity protocols and access frameworks (OAuth 2.0, OpenID Connect, RBAC, ABAC, and policy-based access controls). * AI & Agentic Access Governance: Develop secure access patterns, identity frameworks, governance, and observability guardrails for AI agents, LLM applications, and Model Context Protocol (MCP) systems. * Self-Service Developer Experience: Create automated, developer-friendly platforms that allow teams to request, approve, provision, and audit access without manual security operations friction. * Leadership: Set technical direction, author key architectural proposals, mentor engineers across the org, and partner closely with Infrastructure, Data, and Security teams. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)