> Markdown version of [/jobs/ext/2838071-principal-platform-engineers](https://www.wearedevelopers.com/jobs/ext/2838071-principal-platform-engineers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Platform Engineers - **Company:** IFS - **Location:** Staines-upon-Thames, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Active Directory, User Authentication, Distributed Systems, Identity and Access Management, Java Virtual Machine (JVM), Lightweight Directory Access Protocols (LDAP), PostgreSQL, OAuth, OpenID, Role-Based Access Control, Openid Connect, Security Assertion Markup Language (SAML), Secure Coding, Data Streaming, Backup and Restore, Policy as Code, Okta, Backend, Containerization, Kubernetes, Low Latency, Apache Kafka, Golang - **Published:** September 11, 2026 - **Apply:** https://www.careerjet.co.uk/job/gbe290bf02888c8f499796b2574baa481d/eaa ## About the Role * Architecting and engineering fine-grained authorisation systems at production scale, in distributed, multi-tenant environments * Hands-on production experience with a relationship-based / policy-based authorisation engine, ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent) * Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each * Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale * Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent) * Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions Authentication (Must Have) * Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale * Hands-on production experience with Curity and/or Keycloak: configuration, customisation, operations, and integration * Deep, practical knowledge of OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and token-based authentication patterns (JWT, opaque tokens, token introspection) * Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory) * Strong hands-on engineering capability across the NGA stack, or the ability to get there fast: * Backend: Go * Messaging / Streaming: Apache Kafka / RedPanda * Data: PostgreSQL * Comfortable operating in a cloud-native environment: Kubernetes (AKS), containers, GitOps, Infrastructure as Code * Event-driven and distributed systems architecture * Secure coding practices and security-by-design principles ## Description Authorisation is the single biggest blocker to our next-generation platform right now. Two Principal Platform Engineers are joining to unblock it. We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud. It is built on SpiceDB (relationship-based access control) on PostgreSQL, and it has to be correct, fast, and multi-tenant at enterprise scale. Alongside it, we run enterprise authentication on Curity, with Keycloak estates migrating onto it. You will architect and build that, own it in production, and set the identity patterns the rest of engineering follows. This is a hands-on engineering role. You will write Go. What we need to see Authorisation * Fine-grained authorisation systems you have built and run at production scale, in distributed multi-tenant environments * Hands-on production experience with a Zanzibar-style authorisation engine: SpiceDB, OpenFGA, Ory Keto or equivalent * Authorisation schemas and permission models you have designed, and the ability to reason about correctness, latency and consistency together * ReBAC, RBAC and ABAC, and a view on when each is the right answer * Policy-as-code exposure: OPA/Rego, Cedar or similar * Running the authorisation engine in production on PostgreSQL, with observability and traceability of the decisions it makes Authentication * Enterprise-scale authentication you have architected and operated, not integrated with * Hands-on production Curity and/or Keycloak: configuration, customisation, extensions, upgrades, operations * OAuth 2.0, OIDC, SAML 2.0 and token patterns at a level where you can explain why a given flow, what its failure modes are, and where PKCE belongs * Enterprise federation, SSO and directory integration, in a bring-your-own-identity model with per-tenant signing keys Operations and engineering * Identity infrastructure on Kubernetes (AKS): Helm, persistent volumes, blue/green cutovers, backup and restore, DR * An IdP under load: config import latency, JVM tuning, pod sizing, dedicated node pools, and a story about what fell over and how you found it * Go, PostgreSQL, Kafka/RedPanda, GitOps, IaC. Exact match not required, ability to get there fast is * You still write code. These are principal engineers who build, not IAM consultants who produce documents How we work We expect that AI tooling has changed how you work. We will ask what you delegate, what you still do yourself, and what you built to stop it breaking. Specifics, not a list of tools. We want strong opinions, held out loud. If you would not push back on your director in week two, this will not suit you. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Inside Bitpanda's Tech Stack: Scaling a European Fintech Leader - Markus Dorner](https://www.wearedevelopers.com/videos/1979-inside-bitpanda-s-tech-stack-scaling-a-european-fintech-leader-markus-dorner) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering)