Principal Platform Engineer || Agentic AI || Identity and Access Management
As Principal Platform Engineer - Identity & Access Management , you will be the technical authority on authorisation (AuthZ) and authentication (AuthN) across the Kairos and Nexus platforms. You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for the developers and end-users who rely on them.
This is one of two Principal Platform Engineers being hired into the Identity & Access Management domain, with a strong emphasis on unifying authorisation across IFS hosting environments. The authorisation problem is complex and high-stakes: it must work consistently across Nexus, F1, and LEC, it must scale to enterprise, multi-tenant workloads, and it is currently a blocker for NGA (Kairos) adoption. You will work directly with the team building this today (the Authorisation subdomain under Udayanga Silva) and own the technical outcome.
This is a hands-on engineering role with significant architectural scope. You will design and implement IAM patterns that are adopted as standards across IFS , and you will work closely with platform, product, and security teams to ensure identity and access are enablers, not bottlenecks.
- Architect and engineer the unified, enterprise-scale authorisation platform across Nexus, F1, and LEC, built on SpiceDB
- Design and implement fine-grained authorisation models: relationship-based access control (ReBAC / Zanzibar-inspired), alongside RBAC and ABAC where appropriate
- Model authorisation schemas, relationships, and permission checks that are correct, performant, and maintainable at scale
- Own the operation of the authorisation engine: SpiceDB on PostgreSQL, including the migration to cloud-native Postgres (CNPG) and blue-green deployment support
- Build the authorisation APIs and SDKs that product teams consume, making correct access control the path of least resistance
- Architect and engineer enterprise-scale AuthN solutions, and own the implementation, configuration, and operation of identity provider infrastructure, specifically Curity and/or Keycloak
- Implement and enforce OAuth 2.0, OpenID Connect (OIDC), and SAML patterns at scale, including token lifecycle management and claims-based authorisation
- Define IAM patterns, standards, and golden paths for product teams to implement securely and consistently
- Integrate identity and access services with the Internal Developer Platform (IDP) to enable self-service authentication and authorisation configuration
- Provide subject-matter expertise on identity and access security to product teams, architects, and security stakeholders
- Maintain platform identity and access service reliability, performance, and security posture
- Contribute to the broader platform engineering roadmap with an identity-and-access-first perspective
Authorisation (Must Have)
-
Architecting and engineering fine-grained authorisation systems at production scale , in distributed, multi-tenant environments
-
Hands-on production experience with a relationship-based / policy-based authorisation engine , ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent)
- Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each
- Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale
- Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent)
- Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions
Authentication (Must Have)
- Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale
- Hands-on production experience with Curity and/or Keycloak : config