> Markdown version of [/jobs/ext/2964749-senior-software-engineer-authentication-identity](https://www.wearedevelopers.com/jobs/ext/2964749-senior-software-engineer-authentication-identity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer (Authentication & Identity) - **Company:** @orchard Llc - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, User Authentication, Software Debugging, Dynamical Systems, Middleware, Identity and Access Management, Python (Programming Language), Key Management, OAuth, OpenID, Role-Based Access Control, Security Assertion Markup Language (SAML), Single Sign-On, Software Engineering, Vault (Revision Control System), Okta, Backend, SC Clearance, Information Technology, Api Design, Software Coding - **Published:** September 17, 2026 - **Apply:** https://www.jofdav.com/jobs/59753193-senior-software-engineer-authentication-identity ## About the Role Must be a US Citizen with the ability to obtain Secret Clearance required, A Solid Python Developer: You have deep experience building production-level backend services. * An Identity Specialist: You haven't just used OAuth2 or OIDC; you understand the mechanics under the hood. You've built RBAC/ABAC models from the ground up. * Tool Agnostic: You are familiar with the "Identity Stack" (Vault, KeyCloak, AWS IAM, Azure Key Vault) but prefer writing code to solve problems. * Clearance Ready: You are a U.S. Citizen. While an active clearance isn't required to start, you're excited by the opportunity to engage with classified systems and debug in high-security environments., 4+ years of backend engineering with a focus on Auth/Identity. * Expertise in Python and API design. * Deep knowledge of OAuth2, OIDC, SAML, and SSO. * Experience with multi-tenant application design and tenant isolation. * U.S. Citizenship (required for clearance eligibility)., * Experience building or integrating authorization frameworks or policy engines. (e.g., OPA, Cedar, Zanzibar-inspired systems) * Experience designing authorization for dynamic systems. (e.g., agent-based systems, workflow engines, or plugin architectures) * Experience implementing relationship-based or context-aware access control models. * Experience supporting on-prem or air-gapped deployments. * Experience with enterprise identity integrations in complex environments. * Experience working in high-assurance or regulated environments. * Familiarity with secrets management tools. (e.g., Vault) * Exposure to compliance frameworks. (SOC2, FedRAMP, etc.) * Advanced degree in Computer Science or related field. * Active security clearance Compensation: The compensation for this role is based on a number of factors, primarily your credentials, experience and demonstrated capabilities. The base salary is expected to be the in the range $145,000 - $155,000. ## Description This is a pure backend engineering role. You will be the resident expert on authentication and authorization systems within the product codebase. You will bridge the gap between internal product security and the platform environment it runs on, ensuring that when a platform engineer deploys our tool, it is "secure by design.", Integration: Engineering seamless handshakes with external systems like Active Directory, IAM, and SSO providers. * Python Mastery: Developing high-performance middleware and SDKs to enforce security across distributed and air-gapped environments.