Principal Platform Engineer || Agentic AI || Identity and Access Management

๐Ÿข IFS ยท all IFS jobs
๐Ÿ“ United Kingdom
๐Ÿ“… Posted 2026-07-30 ยท via Himalayas
๐Ÿท IAM,Platform-Engineering,Authorization-Engineering,Authentication-Engineering,Enterprise-Software-Engineering,Agentic-AI-Platform-Engineer,Principal-Identity-And-Access-Management-Engineer,Identity-Platform-Engineer,Senior-Identity-And-Access-Management-Engineer,Agentic-AI-Platform-Engineering,Senior-Agentic-AI-Engineer,IAM-Platform-Engineer,AI-Agent-Platform-Engineer,Agentic-AI-Engineer,Platform-Engineer
Apply on original site โ†—

As Principal Platform Engineer - Identity & Access Management , you will be the technical authority on authorisation (AuthZ) and authentication (AuthN) across the Kairos and Nexus platforms. You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for the developers and end-users who rely on them.

This is one of two Principal Platform Engineers being hired into the Identity & Access Management domain, with a strong emphasis on unifying authorisation across IFS hosting environments. The authorisation problem is complex and high-stakes: it must work consistently across Nexus, F1, and LEC, it must scale to enterprise, multi-tenant workloads, and it is currently a blocker for NGA (Kairos) adoption. You will work directly with the team building this today (the Authorisation subdomain under Udayanga Silva) and own the technical outcome.

This is a hands-on engineering role with significant architectural scope. You will design and implement IAM patterns that are adopted as standards across IFS , and you will work closely with platform, product, and security teams to ensure identity and access are enablers, not bottlenecks.

- Architect and engineer the unified, enterprise-scale authorisation platform across Nexus, F1, and LEC, built on SpiceDB

- Design and implement fine-grained authorisation models: relationship-based access control (ReBAC / Zanzibar-inspired), alongside RBAC and ABAC where appropriate

- Model authorisation schemas, relationships, and permission checks that are correct, performant, and maintainable at scale

- Own the operation of the authorisation engine: SpiceDB on PostgreSQL, including the migration to cloud-native Postgres (CNPG) and blue-green deployment support

- Build the authorisation APIs and SDKs that product teams consume, making correct access control the path of least resistance

- Architect and engineer enterprise-scale AuthN solutions, and own the implementation, configuration, and operation of identity provider infrastructure, specifically Curity and/or Keycloak

- Implement and enforce OAuth 2.0, OpenID Connect (OIDC), and SAML patterns at scale, including token lifecycle management and claims-based authorisation

- Define IAM patterns, standards, and golden paths for product teams to implement securely and consistently

- Integrate identity and access services with the Internal Developer Platform (IDP) to enable self-service authentication and authorisation configuration

- Provide subject-matter expertise on identity and access security to product teams, architects, and security stakeholders

- Maintain platform identity and access service reliability, performance, and security posture

- Contribute to the broader platform engineering roadmap with an identity-and-access-first perspective

Authorisation (Must Have)

-
Architecting and engineering fine-grained authorisation systems at production scale , in distributed, multi-tenant environments

-
Hands-on production experience with a relationship-based / policy-based authorisation engine , ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent)

- Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each

- Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale

- Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent)

- Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions

Authentication (Must Have)

- Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale

- Hands-on production experience with Curity and/or Keycloak : config

โ† All remote jobs