Principal Platform Engineer || Identity Platform (AuthN/AuthZ)

Posted 4 Days Ago
Be an Early Applicant
Düsseldorf, Nordrhein-Westfalen, DEU
Hybrid
Expert/Leader
Information Technology • Software
The Role
Build and operate shared authentication and authorization platform capabilities across distributed, multi-tenant environments. Develop platform services, APIs, integrations, infrastructure, and automation using code; support Kubernetes-based production systems; implement OAuth 2.0, OpenID Connect, access control, federation, tenant isolation, and self-service workflows. Own reliability, observability, testing, safe deployments, recovery, and production troubleshooting while providing technical leadership to engineering teams.
Summary Generated by Built In
Company Description

Please note that before you apply for this role, you should be a hands-on platform engineer who builds through code and automates by default.  Last week you would have been writing a lot of code! 

Architecture, administration and product configuration alone are not sufficient. We want to understand what you personally implemented, tested, automated and supported in production.

At IFS, we're building the next generation of AI-native enterprise software, transforming how some of the world's largest organisations manage assets, operations and critical services.

This is an opportunity to work at the forefront of modern AI engineering, building intelligent products that combine Large Language Models (LLMs), agentic AI and cloud-native technologies to solve complex, real-world business challenges at enterprise scale.

We're looking for engineers who are passionate about building production AI systems and excited by the opportunity to shape the future of enterprise software.

Please note that this role requires demonstrable, hands-on experience designing, building and shipping production AI applications.

Candidates whose AI experience is limited to using tools such as ChatGPT, Claude, Cursor or GitHub Copilot to assist software development, without demonstrable experience building AI-powered products or systems, will not meet the requirements for this role.

IFS is a billion-dollar revenue company with 7000+ employees on all continents. We deliver award-winning enterprise software solutions through the use of embedded digital innovation and a single cloud-based platform to help businesses be their best when it really matters–at the Moment of Service™.

At IFS, we're flexible, we're innovative, and we're focused not only on how we can engage with our customers, but on how we can make a real change and have a worldwide impact. We help solve some of society's greatest challenges, fostering a better future through our agility, collaboration, and trust.

We celebrate diversity and accept that there are so many different perspectives in this world. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view.

By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world.

We're looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs.

If you want to change the status quo, we'll help you make your moment. Join Team Purple. Join IFS.

Job Description

At IFS, we’re building the next generation of AI-native enterprise software. We’re looking for a Principal Platform Engineer to build the shared authentication and authorisation capabilities that our product engineering teams depend on.

You should be a hands-on platform engineer who builds through code and automates by default. Your experience might centre on infrastructure as code, deployment pipelines, automation, platform tooling or service integrations. What matters is that you have built reliable, repeatable capabilities that engineering teams use to deliver and operate software.

Your background may be in platform engineering, infrastructure, SRE, identity engineering or systems integration. What matters is substantial hands-on experience building or extending platform capabilities through code and automation, supporting the delivery and operation of software.

A software development background is particularly valuable, but it is not a prerequisite. We welcome engineers whose coding experience has developed through platform engineering, infrastructure or SRE work.

Architecture, administration and product configuration alone are not sufficient. We want to understand what you personally implemented, tested, automated and supported in production.

We’re interested in what you have personally built and automated: how you provisioned it, tested changes, delivered it safely and enabled other teams to use it without depending on manual intervention. Identity and access is the domain you will work in; specialist experience in that domain is particularly welcome.

This is an opportunity to shape a critical platform capability, with substantial technical ownership and impact across our engineering organisation.

The job

We are hiring two Principal Platform Engineers to help unify authentication and authorisation across our next-generation enterprise software platform.

We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud. It must be correct, fast and reliable in distributed, multi-tenant environments.

Our current stack includes SpiceDB backed by PostgreSQL for authorisation, and Curity for authentication, with Keycloak estates migrating onto it. These describe the systems you will work on; prior experience with every product is not required.

You will design and build platform services, APIs and automation, own them in production, and establish patterns that product engineering teams can adopt confidently. A central part of the role is making secure authentication and authorisation available through documented, automated, self-service workflows.

This is a hands-on role. You will write and review infrastructure and automation code, build platform integrations, and contribute to tooling and services, including those written in Go.

What we need to see

Platform engineering and automation

  • Software platforms or shared services you have built and operated for application engineering teams.
  • Infrastructure code, automation, delivery pipelines, integrations or platform tooling you have personally built and maintained.
  • Automation covering provisioning, configuration, deployment, upgrades and recovery, managed through version control and repeatable delivery pipelines.
  • Self-service capabilities that reduce manual intervention and enable developers to work independently.
  • Experience deploying and operating containerised application services on Kubernetes in a software delivery environment.

Authorisation

  • Practical understanding of access control within applications and APIs, including role-based, attribute-based and relationship-based models.
  • Experience implementing permission checks or designing permission models, with an understanding of tenant isolation and security boundaries.
  • The ability to reason about correctness, latency, consistency and the traceability of authorisation decisions.
  • Familiarity with fine-grained authorisation engines or policy-as-code approaches is valuable.

Authentication

  • Practical understanding of authentication for software applications and services, including OAuth 2.0, OpenID Connect and token lifecycle management.
  • Experience implementing or extending authentication flows in software, with an understanding of validation, trust boundaries and failure modes.
  • Understanding of enterprise federation, SSO and external identity-provider integration in a customer-facing platform.
  • Deeper experience engineering and operating authentication infrastructure at scale is particularly welcome.

Production ownership

  • Experience with cloud infrastructure, Kubernetes, containers, GitOps and Infrastructure as Code.
  • An approach to reliability that includes observability, performance testing, safe rollouts, rollback, backup and recovery.
  • Examples of diagnosing production failures and using code or automation to prevent recurrence.
  • Sound engineering judgement across distributed systems, relational data and event-driven services.

How we work

You will remain close to the code while helping other engineers make good architectural decisions. We value clear technical reasoning, constructive challenge and ownership from design through production.

We are interested in how AI-assisted engineering fits into your work: what you delegate, how you review and test the results, and how you remain accountable for the software you ship.

Qualifications

Must have — platform engineering

  • Substantial hands-on experience building and operating platforms or shared infrastructure that support software engineering teams.
  • Strong coding and scripting skills applied to infrastructure, automation, deployment tooling or integrations. You should be comfortable maintaining code, reviewing changes and using automated tests.
  • Experience automating provisioning, configuration, deployment and operational tasks through version-controlled, repeatable workflows.
  • Production experience with Kubernetes and containers in an environment delivering and operating software applications.
  • Practical experience with a major public cloud platform, Infrastructure as Code, CI/CD and GitOps.
  • Experience building reusable platform capabilities or self-service workflows that reduce manual work for engineering teams.
  • Sound understanding of APIs, networking, data stores and distributed-system behaviour, with the ability to troubleshoot production issues.
  • Evidence of technical leadership through design decisions, code reviews, engineering standards and support for other engineers.

Experience developing application or backend services is a strong advantage, but is not required. Your coding experience may come primarily from infrastructure and platform engineering. You should be willing to work with our Go-based tooling and services and develop your capabilities where needed.

Must have — authentication and authorisation foundations

  • Practical experience implementing authentication and access control within software applications, APIs or shared platform services.
  • Working knowledge of OAuth 2.0, OpenID Connect and token-based authentication, including secure validation and common failure modes.
  • Understanding of permission models, least privilege and tenant isolation, and the ability to explain where access decisions are enforced.
  • The ability to translate security requirements into working software, automated tests and maintainable platform capabilities.

We would particularly like to talk to you if…

  • You have production experience with Curity, especially extending it, automating its configuration and lifecycle, or operating it as part of a software platform.
  • You have engineered and operated Keycloak in a software product environment, including customisation, automated delivery or migrations.
  • You have built fine-grained authorisation using SpiceDB or a comparable relationship-based authorisation engine.
  • You have deeper experience with enterprise federation, SAML, policy-as-code or authentication and authorisation in distributed, multi-tenant systems.
  • You have built self-service identity capabilities, APIs or SDKs that other engineering teams use.
  • You have worked with Go, PostgreSQL and Kafka or RedPanda in production.

These are advantages, not substitutes for strong platform engineering, coding and automation skills. Strong platform engineers with relevant authentication and authorisation foundations are encouraged to apply even if they have not used our specific products.

Additional Information

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

Skills Required

  • Substantial hands-on experience building and operating platforms or shared infrastructure for software engineering teams.
  • Strong coding and scripting skills for infrastructure, automation, deployment tooling, or integrations.
  • Experience maintaining code, reviewing changes, and using automated tests.
  • Experience automating provisioning, configuration, deployment, and operational tasks through version-controlled workflows.
  • Production experience with Kubernetes and containers for software application delivery and operations.
  • Experience with a major public cloud platform, Infrastructure as Code, CI/CD, and GitOps.
  • Experience building reusable platform capabilities or self-service workflows that reduce manual engineering work.
  • Understanding of APIs, networking, data stores, and distributed-system behavior, including production troubleshooting.
  • Evidence of technical leadership through design decisions, code reviews, engineering standards, and support for other engineers.
  • Practical experience implementing authentication and access control in applications, APIs, or shared platform services.
  • Working knowledge of OAuth 2.0, OpenID Connect, and token-based authentication, including secure validation and failure modes.
  • Understanding of permission models, least privilege, tenant isolation, and enforcement points for access decisions.
  • Ability to translate security requirements into working software, automated tests, and maintainable platform capabilities.
  • Willingness to work with Go-based tooling and services and develop Go capabilities as needed.
  • Application or backend service development experience.
  • Production experience with Curity, including configuration automation, lifecycle management, or platform operations.
  • Production experience engineering, customizing, delivering, or migrating Keycloak.
  • Experience with SpiceDB or a comparable relationship-based authorization engine.
  • Experience with enterprise federation, SAML, policy-as-code, or identity and authorization in distributed multi-tenant systems.
  • Experience building self-service identity capabilities, APIs, or SDKs for engineering teams.
  • Production experience with Go, PostgreSQL, and Kafka or RedPanda.

IFS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about IFS and has not been reviewed or approved by IFS.

  • Retirement Support Retirement support is presented as part of the package in North America through a 401(k) plan and references to pension/defined contribution arrangements in some contexts.
  • Healthcare Strength Healthcare coverage is described as available in some regions, including health, dental, life, and disability insurance offerings.
  • Strong & Reliable Incentives Variable pay elements such as monthly bonuses and profit sharing are described as meaningful in certain roles, with bonuses tied to performance outcomes like reduced downtime.

IFS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Linköping
6,788 Employees
Year Founded: 1983

What We Do

IFS develops and delivers enterprise software for companies around the world who manufacture and distribute goods, build and maintain assets, and manage service-focused operations. Within our single platform, our industry specific products are innately connected to a single data model and use embedded digital innovation so that our customers can be their best when it really matters to their customers – at the Moment of Service. The industry expertise of our people and of our growing ecosystem, together with a commitment to deliver value at every single step, has made IFS a recognized leader and the most recommended supplier in our sector. Our team of 5,000 employees every day live our values of agility, trustworthiness and collaboration in how we support our 10,000+ customers. Learn more about how our enterprise software solutions can help your business today at ifs.com. Follow us on Twitter: @ifs Facebook: www.facebook.com/ifsdotcom Instagram: www.instagram.com/ifsdotcom Visit the IFS Blog on technology, innovation and creativity: https://blog.ifs.com/

Similar Jobs

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Account Manager

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
5 Locations
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Customer Success Manager

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
2 Locations
85422 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Client Delivery Lead Top Accounts

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office or Remote
7 Locations
85422 Employees

Sonar Logo Sonar

AI Research Engineer (f/m/d)

Artificial Intelligence • Cloud • Security • Software
Easy Apply
Hybrid
Bochum, Nordrhein-Westfalen, DEU
800 Employees
90K-160K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account