← Back to jobs
Temporaltechnologies
Temporaltechnologies

Staff Software Engineer, Cloud Identity

engineeringfull-timeUnited States - Remote Opportunity
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

About Us

Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster. We are on a mission to be the reliable foundation of every developer’s toolbox, and are building the team that will make that happen.

Our values guide us —they are present in how we show up, make decisions, and work together to make an impact. We’re curious, driven, collaborative, genuine and humble.

Temporal is growing and we are looking for those who share our values, challenge 'standard' thinking, and want to influence our future. If you have a passion for improving the developer experience, building world-class open-source software and communities, and want to be a part of our amazing team, we'd love to hear from you!

Summary

Temporal is hiring a Staff Software Engineer for Identity to design, build, and operate the identity and access platform behind Temporal Cloud — a multi-tenant SaaS serving high-throughput workloads. You'll own the systems that authenticate humans and workloads, authorize fine-grained access to namespaces and APIs, federate with customer IdPs, and distribute auth material to clients and workers at scale. This role partners closely with Security, Product, and platform teams to deliver "secure by default" capabilities without compromising developer or operator experience.

What You'll Do

  • Design and build Temporal Cloud's identity platform end-to-end — authentication (OAuth 2.0/2.1, OIDC, SAML, token exchange), authorization (RBAC/ReBAC/policy engines), and workload identity federation — so customers and workloads authenticate without long-lived secrets
  • Scale the auth hot path to meet Temporal Cloud's SLOs: in-memory auth bundles, JWKS caching, decision caching, and revocation strategies that keep latency low and eliminate single points of failure
  • Integrate with enterprise IdPs (Okta, Entra ID, Google Workspace, SAML/OIDC), own SCIM 2.0 provisioning, and threat-model identity flows against token replay, confused deputy, scope escalation, and mix-up attacks
  • Partner with Security, Product, and platform teams to ship secure-by-default patterns, define IAM lifecycle and audit strategies, and shape the technical roadmap by tracking emerging standards (IETF OAuth WG, OpenID Foundation)
  • Mentor engineers, maintain clear architecture docs, and engage directly with customers to understand requirements and unblock adoption

What You'll Bring

  • Deep hands-on experience building and operating production identity systems — OAuth 2.0/2.1, OIDC, SAML, JWT/JOSE, JWKS rotation, SCIM, and at least some exposure to workload identity (SPIFFE/SPIRE, WIF, mTLS, or short-lived federated credentials)
  • Strong grasp of authorization at scale (RBAC, ABAC, ReBAC/Zanzibar) and familiarity with policy engines like OPA, Cedar, or OpenFGA
  • Track record operating latency-sensitive distributed systems in production, including on-call ownership and operational excellence
  • Proficiency in Go; experience with Python, Java, or Kotlin is a plus
  • Strong communication skills with the ability to align stakeholders across security, product, and engineering and drive execution end-to-end

Nice to Have

  • Contributions to identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE) or standards bodies (IETF OAuth WG, OpenID Foundation)
  • Experience with compliance frameworks (FedRAMP, SOC 2
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $14.99/mo. Cancel anytime.
Join waitlist
Apply now
Staff Software Engineer, Cloud Identity at Temporaltechnologies — Remote