Kong

Kong

Staff Software Engineer, Identity and Access Management

Toronto, Canada · Staff+

Sponsorship not specifiedDetected 98 days ago
API DevelopmentOAuthPenetration TestingComplianceZero Trust

About the role

  • We're a fast-growing, well-funded company with happy customers and motivated employees.
  • Insomnia, acquired in 2019, is a full-lifecycle API development platform that has quickly become an integral part of Kong's product portfolio.
  • As a Staff Software Engineer on the Konnect team at Kong, you'll architect Kong Identity's multi-tenant identity platform supporting complex organizational hierarchies, cross-tenant isolation, and enterprise-grade security controls.

Responsibilities

  • Design and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation capabilities.
  • Lead development of Kong Identity's extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business logic evaluation at token issuance.
  • Design sophisticated rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.
  • Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy system integration.
  • Lead technical strategy for Kong Identity's developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.
  • Design Kong Identity's plugin architecture enables custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.
  • Drive implementation of compliance frameworks (SOC 2, FedRAMP, GDPR), including comprehensive audit trails, data residency controls, and privacy-preserving token designs.
  • Lead technical initiatives for Kong Identity's integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.

Requirements

  • 7+ years of experience building production identity platforms at leading identity providers or enterprise software companies, with proven track record of handling millions of authentication requests daily.
  • Deep expertise in advanced OAuth 2.0 extensions (PKCE, mTLS, JWT bearer assertions, token exchange), OpenID Connect profiles, and emerging standards like OAuth 2.1 and GNAP.
  • Proven experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise feature sets.
  • Expertise in global identity infrastructure including edge deployment strategies, geo-distributed token validation, and cross-region data consistency patterns.
  • Experience with identity platform security including threat modeling, penetration testing coordination, and implementation of advanced attack prevention mechanisms.
  • Knowledge of service mesh identity patterns, workload identity bootstrapping, and integration with container orchestration platforms.
  • Experience with identity protocol extensions, custom grant flows, and building extensible identity platforms that support diverse use cases.

Skills

  • For more information, visit www.konghq.com http://www.konghq.com.

Company info

  • Nobody checks every box - we're looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.

This listing is sourced directly from Kong's careers page and normalized into a canonical job model.