> Markdown version of [/jobs/ext/2702798-software-engineer-2-iam](https://www.wearedevelopers.com/jobs/ext/2702798-software-engineer-2-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer 2, IAM - **Company:** Drata Inc - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $174,500.0 - $236,100.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Audit Trail, User Authentication, Human Resources Information System (HRIS), Identity and Access Management, Node.Js, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Session Management, TypeScript, Okta, Api Design, Api Management - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-software-engineer-2-iam-drata-com-8098664 ## About the Role * 7+ years building production software, with meaningful time spent on authentication, authorization, or identity infrastructure. * 3+ years experience in a NodeJS / TypeScript codebase with a deep understanding of Typescript. * Working knowledge of the identity protocols this team operates against: OAuth 2.0 / OIDC, SAML 2.0, SCIM 2.0. You don't need to have shipped all three - fluent enough to design against them. * Experience designing or operating access control systems - at minimum RBAC, ideally with exposure to attribute-based or relationship-based authorization. * Working knowledge of surfacing observability & security information from complex systems. * Experience designing and collaborating on API design and architecture * Strong fundamentals in session management, token lifecycle, MFA, and the security tradeoffs that come with each. * Production experience operating on a major cloud (AWS preferred; we use it heavily). * Security-first instinct: you think about misuse before you ship, and you can defend a design decision against a threat model. * Comfortable in collaborative architecture work - contributing to designs you don't fully own while owning execution on the pieces you do., * Experience integrating with or building on top of identity platforms: Okta, Microsoft Entra ID, Auth0, Ping, WorkOS. * Experience with authorization engines (OpenFGA, Cedar, OPA) or with designing a custom policy model. * Experience operating SCIM, SSO, or identity sync at enterprise scale (multi-IdP, multi-domain customers). * Familiarity with durable workflow engines (e.g., Temporal). * Experience with HRIS API integrations * Compliance context: SOC 2, ISO 27001, NIST, FedRAMP - Drata is a compliance product, so a working understanding helps. * Experience building auth for AI agents, MCP servers, or other emerging agentic-system contexts - scoped credentials, delegation, HITL approvals. * Bug bounty, appsec, or red-team experience on identity surfaces. ## Description Drata's Identity & Access Management team owns the identity, authentication, and access control infrastructure that every customer uses to access the platform - and that every internal platform service relies on for trust boundaries. * Authentication - SSO (SAML 2.0, OIDC), session/token management, MFA. We're focused on authentication for enterprise customers - large user populations, sophisticated identity setups, and the uptime and observability that scale demands. * Authorization - the access control model that determines what users, services, and agents can do across the platform - from role-based access to fine-grained authorization for enterprise customers, internal services, and AI-driven actions. * Provisioning & lifecycle - SCIM 2.0 provisioning for enterprise customers like Okta, Microsoft Entra ID, and others. Group-to-role mapping, conflict resolution, and the long tail of behaviors enterprise identity setups demand. * Identity sync infrastructure - keeping Drata's view of the customer's workforce accurate via against Okta, M365, Google, and beyond. Efficiency across provider support, customers with small to enterprise user populations and to surface what's happening clearly when something goes wrong. * Auth for platform services and AI - providing the trust primitives other Drata services build on, and supporting authentication and human-in-the-loop authorization patterns for AI features and agentic workflows. What you'll do: * Design and operate Drata's authentication surface: SSO integrations (SAML, OIDC), session and token handling, MFA, and flexible enterprise identity configurations. * Contribute to Drata's authorization architecture - collaborating on direction, owning meaningful pieces of execution, and bringing your perspective on the tradeoffs (RBAC vs. ABAC vs. etc., policy engines, audit and observability of access decisions). * Build and harden SCIM provisioning at enterprise scale: group sync, role mapping, deactivation, conflict resolution, and the long tail of IdP-specific behavior. * Build and operate identity sync workflows - full and delta syncs across major identity providers - with the observability, retry semantics, and parity guarantees enterprise sync demands. * Build authentication and authorization for AI features and agentic flows: scoped credentials for AI agents, human-in-the-loop approval workflows, and the audit trail needed to defend AI-driven actions in a compliance product. * Provide the auth primitives other platform services depend on, and represent IAM in cross-team architecture discussions. * Threat-model identity surfaces, partner with security on hardening, and own the response when identity is implicated in an incident. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [How One Developer Built the Back Office for 10 Million Companies](https://www.wearedevelopers.com/videos/100082-how-one-developer-built-the-back-office-for-10-million-companies) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)