Drata
Senior Software Engineer 2, IAM
Hybrid - San Francisco · Senior
Sponsorship not specified$175k-$236kDetected 56 days ago
TypeScriptNode.jsAWSAPI DevelopmentOAuthHRISControls
About the role
- Authentication - SSO (SAML 2.0, OIDC), session/token management, MFA.
- We're focused on authentication for enterprise customers - large user populations, sophisticated identity setups, and the uptime and observability that scale demands.
- Authorization - the access control model that determines what users, services, and agents can do across the platform - from role-based access to fine-grained authorization for enterprise customers, internal services, and AI-driven actions.
Responsibilities
- Build and harden SCIM provisioning at enterprise scale: group sync, role mapping, deactivation, conflict resolution, and the long tail of IdP-specific behavior.
- Build and operate identity sync workflows - full and delta syncs across major identity providers - with the observability, retry semantics, and parity guarantees enterprise sync demands.
- Build authentication and authorization for AI features and agentic flows: scoped credentials for AI agents, human-in-the-loop approval workflows, and the audit trail needed to defend AI-driven actions in a compliance product.
- Threat-model identity surfaces, partner with security on hardening, and own the response when identity is implicated in an incident.
- 7+ years building production software, with meaningful time spent on authentication, authorization, or identity infrastructure.
- Working knowledge of the identity protocols this team operates against: OAuth 2.0 / OIDC, SAML 2.0, SCIM 2.0. You don't need to have shipped all three - fluent enough to design against them.
- Experience designing and collaborating on API design and architecture
Requirements
- Experience with authorization engines (OpenFGA, Cedar, OPA) or with designing a custom policy model.
- Experience with HRIS API integrations
- Working knowledge of the identity protocols this team operates against: OAuth 2.0 / OIDC, SAML 2.0, SCIM 2.0.
Nice to have
- Experience designing or operating access control systems - at minimum RBAC, ideally with exposure to attribute-based or relationship-based authorization.
- Working knowledge of surfacing observability & security information from complex systems.
- Strong fundamentals in session management, token lifecycle, MFA, and the security tradeoffs that come with each.
- Production experience operating on a major cloud (AWS preferred
- we use it heavily).
Compensation
- A variety of factors are considered when determining someone's leveling and compensation-including a candidate's professional background and experience.
- These ranges may be modified in the future and final offer amounts may vary from the amounts listed above.
- We believe that to do your best work, you should get the time you need for rest, rejuvenation and recovery.
- This role will receive a competitive base salary, benefits, and stock, typically in the form of Restricted Stock Units (RSUs).
- $174,500 - $236,100.
Benefits
- We provide stock equity to ensure that as the company grows, you share directly in that success.
- Equity gives every employee a sense of ownership and the opportunity to celebrate our wins together-because your contributions don't just support our progress; they help drive our collective success.
- We want to support you in life's most important moments, so we offer a paid Parental Leave policy, after six months of employment.
- Employees also receive access to Kindbody fertility and family-building benefits and dedicated leave specialists who help guide you through the entire process.
- Design and operate Drata's authentication surface: SSO integrations (SAML, OIDC), session and token handling, MFA, and flexible enterprise identity configurations.
- Drata offers a flexible vacation policy, paid holidays, and other perks to recharge.
Company info
- Hear the Voice of the Team https://drata.com/about/life-at-drata: Explore our "Life at Drata" page for employee testimonials on our collaborative and the growth opportunities available.
- Experience the Impact https://www.greatplacetowork.com/certified-company/7044563: See why we are consistently recognized on Fortune's Best Workplaces lists.
- LinkedIn https://www.linkedin.com/company/drata/posts/?feedView=all - follow us for company updates, employee stories, and career news.
- A comprehensive suite of financial benefits, including a 401(k) plan, company-paid life and disability insurance, tax-advantaged spending accounts, and a range of discounted voluntary offerings to help you customize and strengthen your overall financial position.
- Authentication - SSO (SAML 2.0, OIDC), session/token management, MFA. We're focused on authentication for enterprise customers - large user populations, sophisticated identity setups, and the uptime and observability that scale demands.
- Provisioning & lifecycle - SCIM 2.0 provisioning for enterprise customers like Okta, Microsoft Entra ID, and others. Group-to-role mapping, conflict resolution, and the long tail of behaviors enterprise identity setups demand.
- Experience operating SCIM, SSO, or identity sync at enterprise scale (multi-IdP, multi-domain customers).
This listing is sourced directly from Drata's careers page and normalized into a canonical job model.