Datum
Senior Engineer - Auth
Remote (US) · Senior
Sponsorship not specifiedDetected 166 days ago
GoRustDistributed SystemsAlgorithmsGitPostgreSQLElasticsearchAWSGCPAzureCloud PlatformsKubernetesTerraformCI/CDPrometheusGrafanaGraphQLOAuthTest AutomationTCP/IPLoad BalancingLeadershipCollaborationMentoring
About the role
- We're seeking a senior/principal/staff level engineer focused on securely connecting 1k clouds together.
- Whether that's OAuth, SPIFFE, Authzed, Zitadel, k8s RBAC, or everything in between, the right candidate for this role can likely rattle off a few RFCs and has been dreaming of working on a system like this already.
Responsibilities
- Design, implement, and run Datum's core authentication and authorization stack
- Build customer-facing solutions to help our alt-cloud ecosystem thrive
- Design distributed solutions that scale from startup to hyperscale usage patterns
- Implement intelligent traffic routing, load balancing, and failover
- Build observability, monitoring, and diagnostic tools for complex environments
- Optimize control plane performance for AI workloads and high-bandwidth applications with our network team
- Drive technical networking decisions in collaboration with our open-source community
- Maintain high code quality standards and documentation for network APIs
- Design networking solutions that integrate seamlessly with Kubernetes and AI patterns
- Build network policies and security frameworks for multi-tenant cloud environments
Nice to have
- Strong working knowledge of OAuth in complex production environments with multiple IdPs, including social and commercial (AWS IAM, Azure Entra, GCP, Auth0, Okta, etc.)
- Strong working knowledge of authorization (ABAC, RBAC, PBAC) and its ecosystem (Zanzibar, SpiceDB, OpenFGA, Cedar)
- Experience with Workload Identity Federation and/or SPIFFE and opinions about where the puck is going
- 5+ years of running large-scale production systems on Kubernetes or similar, with security as a first principle
- Strong experience with distributed systems design, security, auth, consensus algorithms, async reconciliation, and fault tolerance
- Enough familiarity with Kubernetes patterns and APIs that you can speak custom resources and admission controllers
- Strong experience with infrastructure as code (Flux, Terraform, Pulumi) for provisioning
- Familiarity with SRv6, edge computing, or modern network routing would be a huge plus
Skills
- of applications, services, networks, and people.
- It's more secure, more operable, and even more enjoyable.
- Still interested?
- Practically speaking, it means someone who wakes up every day thinking about federated authentication and authorization.
- Cloudflare, AWS, GCP, Azure, multi-cloud networking
- Contributing to Datum's public networking repositories with transparent development
- Engaging with the community through GitHub issues, RFCs, and technical discussions
- Speaking at networking conferences and writing technical blog posts
- Maintaining high standards for code quality, performance, and documentation
- Adoption and growth for Datum in the cloud-native and AI infrastructure communities
- High-performance, reliable network connectivity across diverse cloud environments
- Strong developer experience as evidenced by community contributions and feedback
Company info
- Partner with leadership to advance projects with key customers, partners, and suppliers
This listing is sourced directly from Datum's careers page and normalized into a canonical job model.