Staff Software Engineer I - Internal Access Management

Confluent, Inc
Jackson, MS, United States
3 months ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$225,100.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Systems Engineering User Authentication Microsoft Azure Cloud Computing Cloud Computing Security Distributed Systems Identity and Access Management OAuth OpenID Zero Trust Network Access Google Cloud
+5 more
Istio Multi-Cloud Kubernetes Apache Kafka Confluent

Job description

We are seeking a Staff Software Engineer to lead the technical vision, architecture, and execution for Internal Access Management at Confluent. This role is central to our trusted compute environment and requires deep expertise in distributed systems, cloud security, authentication, and policy-driven authorization frameworks.

As the domain owner, you will define how Confluent enforces least privilege, manages workload identity, governs access boundaries, and ensures secure, auditable authorization across all engineering systems. You will partner with Security, Product, and Engineering to establish a cohesive end-to-end access posture.

What You Will Do:

  • Define and drive the long-term architecture and roadmap for Internal Access Management across Kubernetes and multi-cloud environments.
  • Architect and implement least privilege , just-in-time access , and zero-trust models across Confluent services.
  • Build and evolve scalable access-authorization workflows and lifecycle management systems using technologies such as OPA , cloud IAM policies , workload identity , and internal enforcement engines.
  • Strengthen security boundaries through threat modeling, defense-in-depth practices, and comprehensive access-auditing capabilities.
  • Partner with cross-functional teams-including Platform, Kafka, Observability, Developer Productivity, Release Engineering, and SRE-to drive adoption of secure identity and access patterns.
  • Mentor senior engineers, elevate engineering standards, and influence architectural decisions across the organization.
  • Communicate complex technical decisions clearly and align stakeholders across engineering and security.

Requirements

  • 10+ years of engineering experience, with 4+ years in security, IAM, or distributed systems.
  • Deep expertise in Kubernetes , workload identity , cloud IAM (AWS, GCP, Azure), and zero-trust architectures .
  • Strong understanding of authentication technologies: IAM , OAuth2 , OIDC , policy engines , and modern zero-trust principles.
  • Proven track record leading multi-team technical initiatives at a Staff or Senior Staff level.
  • Strong knowledge of distributed systems, cloud infrastructure, container orchestration, and service mesh.
  • Excellent communication and stakeholder-influence skills across engineering and security domains.

What Gives You an Edge:

  • Experience leading cross-org security platform architecture initiatives.
  • Background in building developer-focused authentication and authorization platforms.

Ready to build what’s next? Let’s get in motion.

Benefits & conditions

At Confluent, we are committed to providing competitive pay and benefits that are in line with industry standards. We analyze and carefully consider several factors when determining compensation, including work history, education, professional experience, and location. The actual pay may vary depending on your skills, qualifications, experience, and work location. In addition, Confluent offers a wide range of employee benefits. To learn more about our benefits click here (https://confluentbenefits.com) .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all