> Markdown version of [/jobs/ext/629392-software-engineer-identity-shield](https://www.wearedevelopers.com/jobs/ext/629392-software-engineer-identity-shield). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - Identity Shield - **Company:** Ally Financial Inc. - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Automation of Tests, Biometrics, Code Review, Data Structures, Relational Databases, Distributed Systems, Amazon DynamoDB, Fraud Prevention and Detection, Push Technology, Identity and Access Management, Python (Programming Language), Key Management, PostgreSQL, Node.Js, NoSQL, OAuth, PCI Data Security Standards, Scrum Methodology, Software Architecture, Redis, Openid Connect, Zero Trust Network Access, JSON Web Token, Runbook, Security Assertion Markup Language (SAML), Security Software, Session Management, Software Engineering, Software Technical Review, TypeScript, Cloud Platform System, Okta, Amazon ElastiCache, Grafana, Caching, AWS AppSync, Backend, Event Driven Architecture, Infrastructure Automation Frameworks, Information Technology, AWS Fargate, Graphql, Front End Software Development, Functional Programming, Cloudwatch, Api Gateway, Restful APIs, Terraform, Dynatrace, Serverless Computing, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b89b133a8ea2e09 ## About the Role Do you have experience in Zero Trust security?, Do you have a High school diploma or GED?, * 7+ years of relevant experience or equivalent combination of education and experience * High School Diploma or GED equivalent, * 7+ years of professional software development experience with strong fundamentals in data structures and algorithms * Strong experience with RESTful API design, GraphQL, and microservices architectures * Hands-on experience with AWS serverless technologies (Lambda, API Gateway, AppSync, ECS/Fargate) * Solid understanding of authentication and authorization concepts, patterns, and best practices * Experience working with both relational databases (PostgreSQL) and NoSQL databases (DynamoDB) in production environments * Strong grasp of security principles including encryption, token management, secret handling, and threat modeling * Passion for writing maintainable code, automated tests, and clear documentation * Collaborative mindset with excellent communication skills across technical and non-technical audiences * Self-motivated learner who stays curious about new technologies and approaches * BSc/BA in Computer Science, Engineering or a related field, or equivalent practical experience * Deep knowledge of identity protocols and standards (OAuth 2.0, OpenID Connect, SAML, JWT, PKCE, WebAuthn) * Experience building authentication or authorization systems from scratch or at scale * Familiarity with identity providers and platforms (Auth0, Okta, Cognito etc.) * Understanding of passwordless authentication patterns (passkeys, FIDO2, WebAuthn) * Experience with mobile authentication patterns (biometric authentication, device binding, push notifications) * Knowledge of zero-trust architecture principles and continuous verification patterns * Experience designing adaptive or risk-based authentication systems * Familiarity with session management patterns and token rotation strategies * Understanding of cryptographic concepts (signing, encryption, key management, certificate handling) * Experience with Infrastructure as Code tools like Terraform * Knowledge of observability tools and distributed tracing (Dynatrace, OpenTelemetry, CloudWatch, X-Ray) * Experience designing and deploying systems across multi-region architectures * Familiarity with caching strategies for authentication state (ElastiCache, Redis) * Understanding of compliance requirements (SOC2, PCI-DSS, GDPR, CCPA) * Experience with CI/CD pipelines and automated security testing (SAST, DAST, dependency scanning) * Background or interest in cybersecurity, fraud detection, or identity and access management domains * Knowledge of event-driven architectures and how authentication signals power fraud detection systems * Exposure to AI-assisted development tools and workflows ## Description As a backend engineer on this team, you'll tackle fascinating challenges implementing identity protocols at scale-building OAuth 2.0 and OpenID Connect flows, developing authorization engines that evaluate complex policies with millisecond latency, and serving authentication decisions that directly impact our ability to keep customers safe. You'll work with modern cloud technologies to build resilient, scalable platforms where performance and reliability are non-negotiable. This is your opportunity to contribute to Ally's authentication infrastructure, mastering security-first design principles, distributed systems, serverless architectures, and AI-assisted development workflows. This role offers the rare combination of high-impact work, cutting-edge technology, and meaningful outcomes. You'll collaborate across engineering, product, security, and data science teams to solve complex problems that matter. Whether you're developing authentication services that adapt to risk signals, implementing password-less flows using passkeys and biometrics, building integrations with enterprise identity providers, or designing event streams that carry authentication signals, your work will be visible and valued. On this team, we believe in relentless progress balanced with sustainable pace. We support each other, celebrate wins, learn from setbacks, and foster an environment where everyone can do their best work. Our #1 goal is team success, and our people are above all else., * Design and develop authentication and authorization services implementing modern identity protocols (OAuth 2.0, OpenID Connect, SAML, JWT) * Build scalable APIs for identity management, user registration, verification, and account recovery * Implement session management and token lifecycle systems across web and mobile platforms * Develop fine-grained authorization engines and policy evaluation services for access control * Build integrations with distributed identity providers, enterprise SSO platforms, and social login services * Implement passwordless authentication flows using passkeys, biometrics, and device attestation * Develop adaptive authentication logic that adjusts requirements based on risk signals and context * Instrument authentication events with rich contextual metadata that power fraud detection and analytics * Implement comprehensive observability using OpenTelemetry across identity services * Write clean, tested code in Node.js, TypeScript, and Python following engineering best practices and team standards * Collaborate with frontend engineers, security teams, and data scientists to deliver solutions that drive real outcomes * Participate in architectural decisions, technical design reviews, and code reviews * Build and maintain infrastructure-as-code for identity platform components using Terraform * Monitor, troubleshoot, and optimize platform performance, reliability, and security posture * Contribute to documentation, runbooks, and knowledge sharing across the team * Experiment with emerging technologies and propose innovations that enhance platform capabilities * Mentor team members and contribute to a culture of continuous learning and improvement * Work in an agile environment with sprint planning, story elaboration, and iterative delivery. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe)