Senior Engineer - Identity Platform
$135,000–$150,000 year
RemoteUnited States
Job Summary
Design, build, and refactor custom Keycloak SPIs in Java for authenticators, grant-type providers, and EMR SSO integrations. Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns, including JWT Bearer grants and Token Exchange. Drive the Keycloak major-version upgrade, shifting from external Infinispan caching to persistent user sessions while validating downstream integrations. Own the session lifecycle model across SSO, client, and offline sessions, designing per-client TTL policies that balance clinical workflow UX against security posture. Serve as the deep-diagnosis engineer for JVM tuning, Infinispan cluster behavior, and PostgreSQL session-store forensics on live authentication traffic. Design integrations with external identity systems, treating realm and client configuration as version-controlled, least-privilege, auditable code. Raise the bar on OAuth and OIDC fluency across the team and represent the platform technical position to application teams and leadership.
Required Qualifications
- 6+ years of professional software engineering with strong, production-grade Java
- significant focus on Identity and Access Management
- Expert Keycloak experience beyond the admin console
- hands-on SPI and extension development
- realm and client architecture for multi-tenant platforms
- running Keycloak (Quarkus) in production on Kubernetes
- Deep OAuth 2.0 and OIDC fluency
- authorization code plus PKCE
- client credentials
- Token Exchange (RFC 8693)
- JWT Bearer (RFC 7523)
- refresh rotation
- Working knowledge of SAML 2.0
- stateful SSO sessions versus stateless JWT validation
- online versus offline sessions
- idle and max semantics
- JWKS validation and key rotation
- judgment to choose per use case
- Hands-on distributed caching and state with Infinispan or comparable technology
- clustering
- persistence
- expiration
- failure modes of distributed session state
- Production operations skill
- JVM performance analysis (GC logs, heap and Metaspace sizing)
- correlating structured logs
- SQL-level investigation in PostgreSQL against live systems
- Security fundamentals and communication
- OWASP-aligned secure coding
- threat-model thinking around token theft and replay and brute-force protection
- MFA and adaptive auth
- the ability to write a design doc that survives review
- translate trade-offs for leadership
Desired Qualifications
- Healthcare integration experience
- EMR and EHR launch patterns
- SMART on FHIR
- other regulated-industry SSO work
- Identity brokering experience
- Keycloak brokering
- first-login flows
- federating with managed platforms such as Google Identity Platform
- Azure AD and Entra
- Okta
- Observability with Prometheus, Grafana, or ELK
- an eye for authentication anomalies such as login-failure trends
- session accumulation
- token-issuance spikes
- Cloud security certification (AWS Security Specialty or equivalent)
- a Master's degree in Computer Science or a related field
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.