> Markdown version of [/jobs/ext/565073-senior-software-developer](https://www.wearedevelopers.com/jobs/ext/565073-senior-software-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Developer - **Company:** Xylem Inc. - **Location:** Yellow Springs, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Lifecycle Management, Audit Trail, Software as a Service, Code Review, Continuous Integration, Identity and Access Management, OAuth, Open Source Technology, OpenID, Role-Based Access Control, Release Management, Azure Active Directory, Zero Trust Network Access, Reverse Proxy, Security Assertion Markup Language (SAML), Software Engineering, Systems Integration, Strategies of Testing, Policy as Code, Okta, ReactJS, Spring-boot, Technical Debt, AngularJS, Integration Tests, Front End Software Development, Api Gateway, Restful APIs, User Administration - **Published:** June 13, 2026 - **Apply:** https://dejobs.org/x/x/D78621864E2442ADB4C499B645BE9B87/job/ ## About the Role * 7+ years in software engineering with demonstrated experience in complex, multi-team platform environments * Strong hands-on proficiency with Java and Spring Boot in a production microservice context * Solid understanding of software development lifecycle practices including CI/CD, code review, testing strategy, and release management * Foundational understanding of security principles - authentication, authorization, token-based identity, and secure API design * Experience working with or integrating against an identity provider (Keycloak, Okta, Auth0, Entra ID, or similar) * Familiarity with OAuth 2.0 and OIDC concepts including authorization code flow, PKCE, and JWT structure * Ability to communicate technical decisions clearly to both engineering peers and non-technical stakeholders Strongly Preferred * Hands-on experience with Keycloak or a comparable open-source identity provider, including realm configuration, client scopes, protocol mappers, IdP federation, and the Admin REST API * Experience with a production authorization policy engine and a point of view on decoupling policy from application code * Experience designing IAM for multi-tenant SaaS, including JWT size constraints, token claim strategy, and downstream performance tradeoffs * Practical experience with API gateway security and policy enforcement at the edge * SAML 2.0 federation and enterprise SSO integration with providers such as Microsoft Entra ID or Okta * SOC2 Type II audit preparation and NIST 800-53 control mapping * Familiarity with NIST 800-207 Zero Trust Architecture principles Nice to Have * Experience with TOTP enforcement and MFA patterns for privileged access * Reverse proxy configuration for multi-domain identity routing * Frontend prototyping experience for operator tooling (Angular or React) * Experience writing authorization policy expressions against principal and resource attributes * Integration testing experience for auth flows * Prior work on developer-facing platforms, including writing integration guides and reviewing PRs for auth correctness ## Description As Senior Software Developer, you will be a key technical contributor on a production IAM platform serving multiple internal engineering teams and end-customer organizations worldwide. This role is about contributing to a transition, not inheriting a steady state. The platform is actively evolving toward a modern Policy-as-Code architecture, decoupling authorization logic from application code, thinning JWT payloads, and enforcing Zero Trust principles at the gateway layer. You will help shape the roadmap and build the technical foundation the team executes against. That said, you will be operating within a production enterprise identity platform at scale. What You'll Drive Architectural Evolution and Policy-as-Code Direction Contribute to the platform's evolution toward a thin-token, policy-as-code authorization model where JWTs carry identity context rather than encoded permissions and a dedicated policy engine becomes the authoritative evaluation layer. This is an active direction, not a completed migration. You will help scope the roadmap, sequence the work, and support consuming teams through the transition. Participate in an active dual-domain migration for the identity platform, including reverse proxy configuration, dynamic issuer handling, and ensuring downstream resource servers can validate tokens across both issuer values without regression. Authorization Model Development Work within and evolve a hybrid RBAC/ABAC authorization model built around a user, role, customer, and application authorization tuple, including platform-defined baseline roles, customer-scoped composite roles, and application-defined custom role patterns. Help identify and address security misconfigurations in how consuming teams integrate with the platform, ensuring authorization is evaluated against customer context, not flat role presence in a token. Developer Experience and Integration Enablement Contribute to Golden Path integration patterns for the engineering teams building on top of the platform, covering OAuth2/OIDC client registration, PKCE, identity provider hints, step-up authentication, redirect URI strategy, and token validation for Angular and React applications. Platform Operations Console Help drive an internal operations and governance UI from its current prototype state to production. The tool serves platform operators, security engineers, and compliance teams across modules including application management, role management, user management, customer hierarchy, MFA configuration, enterprise SSO federation, authorization policy authoring, and audit logs. The goal is reducing manual, ticket-based admin work. Security, Compliance and Risk Contribute to technical controls mapped to SOC2 CC6 and NIST 800-53 in alignment with Zero Trust principles. Support business-risk framing of architectural decisions and technical debt for leadership audiences, covering compliance exposure, audit risk, and real-time access control gaps. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Let developers develop again](https://www.wearedevelopers.com/videos/463-let-developers-develop-again) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)