> Markdown version of [/jobs/ext/2994872-software-engineer-5-ads-authorization-authz-platform-new](https://www.wearedevelopers.com/jobs/ext/2994872-software-engineer-5-ads-authorization-authz-platform-new). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer 5 - Ads Authorization (AuthZ) Platform New - **Company:** Netflix, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, Unit Testing, Software as a Service, Middleware, Identity and Access Management, Python (Programming Language), Node.Js, OAuth, OpenID, Role-Based Access Control, Software Engineering, Systems Integration, Management of Software Versions, Policy as Code, Caching, Backend, Kotlin, Free and Open-Source Software - **Published:** September 19, 2026 - **Apply:** https://www.gamesjobsdirect.com/job/netflix-game-studio/software-engineer-5-ads-authorization-authz-platform/359062 ## About the Role * 5-8+ years backend/software engineering experience shipping production systems. * Hands-on experience working on or building an authorization system - solid RBAC fundamentals, with real understanding of roles, permissions, role hierarchies, and resource-level vs. org-level scoping. * Solid conceptual grounding in authz fundamentals - able to reason through tradeoffs between RBAC, ABAC, and ReBAC (relationship-based / Zanzibar-style) approaches. * Some exposure to evaluating or integrating a policy engine/framework (Oso, OPA/Rego, Cerbos, OpenFGA, AuthZed/SpiceDB, AWS Cedar) - or having worked on an equivalent in-house. * Strong systems design skills: low-latency decision services, caching, consistency vs. performance tradeoffs. * Proficient in one backend stack (Java/Kotlin/Go/Node/Python). Nice-to-have * Experience with policy-as-code languages (Rego, Cedar, Polar) or Zanzibar-paper-inspired systems. * Has participated in a build-vs-buy or vendor RFP process before. * Familiarity with AuthN (OAuth/OIDC) and how the AuthN/AuthZ boundary is typically drawn. * Experience on large-scale multi-tenant SaaS platforms. * Experience building this external organizations in a b2b (not just internal access controls) * Open-source contributions to authz projects (OpenFGA, Cerbos, Casbin, etc.). ## Description * Co-drive the build vs. buy evaluation for centralized authorization - contribute to vendor bake-offs (Oso, Permit.io, Cerbos, OpenFGA, AuthZed, AWS Verified Permissions/Cedar) against an in-house option, weighing latency, flexibility, operational cost, and vendor lock-in. * Help design the policy model: roles vs. permissions vs. relations, org-level vs. resource-level roles, role hierarchies, resource ownership/sharing, multi-tenancy. * Partner on the decision engine architecture: low-latency authorization checks, caching, consistency tradeoffs, audit/versioning of policies. * Work with platform/security/IAM teams to integrate authz checks into services (sync and async enforcement points). * Build reference implementations, SDKs, and middleware so other engineering teams can adopt the centralized model instead of ad hoc checks. * Contribute to testing practices (policy unit tests, authorization test suites) and the migration plan from today's scattered checks to a single policy engine. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [DevOps at Netflix](https://www.wearedevelopers.com/videos/270-devops-at-netflix) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe) - [React Developer Salary [2023]](https://www.wearedevelopers.com/magazine/198-react-developer-salary-2023) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)