> Markdown version of [/jobs/ext/2733063-software-engineer](https://www.wearedevelopers.com/jobs/ext/2733063-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - **Company:** Baseten, Inc - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Python (Programming Language), Automation of Marketing, OAuth, OpenID, Single Sign-On, Backend, Build Management, Kubernetes, Hubspot - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/software-engineer-identity-and-authorization-baseten-9871796 ## About the Role * 4-5+ years of experience building production backend systems, including hands-on design and implementation of a product authorization system: per-resource or per-object permissions, relationship-based access control, a policy engine, or a fine-grained authorization system in the style of Zanzibar, OpenFGA, SpiceDB, or Cedar. * Demonstrated end-to-end ownership: you've taken a system from first design through implementation, production rollout, and iteration with users. * Experience developing and operating multi-tenant systems at scale, where authorization checks sit in the request path and latency and consistency matter. * Comfort working across the full stack, from product and application code to cloud and Kubernetes infrastructure. Preferred: * Experience with Python and Go. * Experience running an OpenFGA, SpiceDB, or similar deployment in production, beyond a proof of concept. * Working knowledge of OAuth, OIDC, and SCIM at the protocol level. ## Description The largest, most demanding enterprises run on Baseten, and they bring exacting requirements for how people, services, and agents access the platform. This is the founding role for our identity and authorization team within enterprise engineering. You'll own the identity and access layer of the Baseten platform: the authorization model, credential systems, and admin experiences that enterprise IT teams use to govern access for organizations like Harvey, HubSpot, and Notion. You'll design and build Baseten's fine-grained authorization system from the ground up to support the workflows customers depend on today while giving them cleaner, more precise ways to manage access as the platform grows. Authorization at Baseten requires low-latency permission checks at high request volume, consistent contracts and behaviors across the product suite, and strong security guarantees for mission-critical, highly regulated workloads. EXAMPLE INITIATIVES Recent and upcoming work in this area: * Fine-grained authorization for users, service accounts, and agentic workloads: per-resource permissions at the organization, team, and workload scope to support both common workflows and complex enterprise access policies * Programmatic authentication allowing high-compliance customers to connect service principles securely via short-lived, workload-based credentials * Agent credentials that grant an agent exactly the access it needs for the given task and nothing more * Enterprise identity lifecycle including single sign-on, SCIM provisioning, and per-organization session expiry policies * Admin controls for centralized visibility, auditability, and governance over credentials, roles, and access, * Lead identity and authorization projects from problem definition and technical design through implementation, launch, and iteration. * Design authorization and credential models that support critical user workflows today and can be safely extended as the platform evolves. * Partner with product, design, and customer-facing teams to turn enterprise security requirements into durable technical solutions. * Establish engineering practices for quality, security, observability, and operational ownership. * Provide technical leadership and mentorship as the team grows. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)