Kong
Staff Software Engineer, Identity and Access Management
Toronto, Canada · Staff+
Sponsorship not specifiedDetected 98 days ago
API DevelopmentOAuthPenetration TestingComplianceZero Trust
About the role
- We're a fast-growing, well-funded company with happy customers and motivated employees.
- Insomnia, acquired in 2019, is a full-lifecycle API development platform that has quickly become an integral part of Kong's product portfolio.
- As a Staff Software Engineer on the Konnect team at Kong, you'll architect Kong Identity's multi-tenant identity platform supporting complex organizational hierarchies, cross-tenant isolation, and enterprise-grade security controls.
Responsibilities
- Design and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation capabilities.
- Lead development of Kong Identity's extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business logic evaluation at token issuance.
- Design sophisticated rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.
- Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy system integration.
- Lead technical strategy for Kong Identity's developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.
- Design Kong Identity's plugin architecture enables custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.
- Drive implementation of compliance frameworks (SOC 2, FedRAMP, GDPR), including comprehensive audit trails, data residency controls, and privacy-preserving token designs.
- Lead technical initiatives for Kong Identity's integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.
Requirements
- 7+ years of experience building production identity platforms at leading identity providers or enterprise software companies, with proven track record of handling millions of authentication requests daily.
- Deep expertise in advanced OAuth 2.0 extensions (PKCE, mTLS, JWT bearer assertions, token exchange), OpenID Connect profiles, and emerging standards like OAuth 2.1 and GNAP.
- Proven experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise feature sets.
- Expertise in global identity infrastructure including edge deployment strategies, geo-distributed token validation, and cross-region data consistency patterns.
- Experience with identity platform security including threat modeling, penetration testing coordination, and implementation of advanced attack prevention mechanisms.
- Knowledge of service mesh identity patterns, workload identity bootstrapping, and integration with container orchestration platforms.
- Experience with identity protocol extensions, custom grant flows, and building extensible identity platforms that support diverse use cases.
Skills
- For more information, visit www.konghq.com http://www.konghq.com.
Company info
- Nobody checks every box - we're looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.
This listing is sourced directly from Kong's careers page and normalized into a canonical job model.