Software Engineer - Infrastructure Security

Posted An Hour Ago
2 Locations
Remote
175K-275K Annually
Senior level
Software
The Role
Build and operate infrastructure security platforms centered on workload identity, service-to-service authentication, authorization, and short-lived credentials. Replace static secrets with identity-based systems, develop identity-authenticated proxies and APIs, and unify authorization policy management. Partner with platform and application teams to drive adoption, migrate legacy systems, and ensure reliable production infrastructure with strong developer experience.
Summary Generated by Built In

About WorkOS 🚀

WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations.
We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Sierra, and Plaid.
As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.

About the Security Platform team

The Infrastructure Security team provides and supports the primitives that enable engineering to securely build applications and meet compliance obligations, while abstracting away the underlying complexity for the best possible developer experience.

Our work centers on workload identity and authorization: how internal applications authenticate to each other and to the services they depend on, and how that access is granted and enforced. We're replacing static secrets with short-lived identity credentials, bringing identity-based authentication to the services engineers use every day, and unifying how authorization is managed across the company.

We're a platform engineering team with a security mission. We measure success by the security outcomes we enable and by how much engineers enjoy building on what we ship — the secure path should be the easiest path.

Who we're looking for
  • A platform builder. You love building infrastructure that other engineers rely on every day, and you sweat the developer experience details that make adoption effortless.

  • Fluent in service-to-service auth. You know authentication and authorization deeply: JWTs, X.509 certificates, and when to reach for each.

  • A systems thinker. You reason carefully about bootstrapping, circular dependencies, availability, and failure modes, especially for infrastructure that everything else depends on.

  • A pragmatic migrator. You know that shipping the primitive is half the job. You can drive adoption across many teams, meet them where they are, and retire the legacy path.

  • A strong partner to engineering. You build trust with engineers by understanding their priorities and making security frictionless.

  • Excited about AI. You're embracing AI and automation to scale platform work and reduce toil.

  • Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.

Responsibilities
  • Build workload identity infrastructure. Make short-lived identity credentials a default part of every application's runtime environment, in partnership with application platform owners.

  • Bring identity-based authentication to internal services. Work with the owners of major internal dependencies to support identity certificates, make them the golden path for newly onboarding applications, and drive migration of existing ones.

  • Eliminate static secrets. Replace all static passwords and service tokens with short-lived identity credentials, and build identity-authenticated egress proxies and API abstractions that inject and automatically rotate managed secrets for the external dependencies that still require them.

  • Unify authorization. Build a single interface and framework through which authorization policies are centrally managed and enforced.

Qualifications
  • 5+ years of experience in software engineering, with a focus on security-related platform, infrastructure, or distributed systems.

  • Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems.

  • Familiarity with the Kubernetes ecosystem and authentication/authorization technologies such as JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA.

  • Experience building and operating production infrastructure that other teams depend on, with attention to availability and failure modes.

  • Proven ability to drive cross-team adoption of platform capabilities or lead large-scale migrations.

Benefits and Perks (US Only) 💖

At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.

 
  • 401k matching

  • Competitive Equity

  • Healthcare, dental and vision coverage

  • FSA, ST/LT Disability, Voluntary Life

  • Carrot fertility benefits

  • 20 days paid vacation + 10 holidays + unlimited sick leave

  • 12 weeks fully paid parental leave

  • Fitness: Monthly stipend for gyms, yoga classes, race registrations or whatever keeps you active

  • Wellness: Monthly stipend for a massage, meditations class, therapy, or activities that enhance your well-being

  • Commuter benefits for hybrid employees in SF/NYC

  • Unlimited token usage!

Please inquire directly with our recruiting team for benefits available to those working outside the US.

 

Equal Opportunity Employer

WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Skills Required

  • 5+ years of experience in software engineering, focused on security-related platform, infrastructure, or distributed systems
  • Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems
  • Familiarity with Kubernetes and authentication and authorization technologies including JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA
  • Experience building and operating production infrastructure used by other teams, with attention to availability and failure modes
  • Proven ability to drive cross-team adoption of platform capabilities or lead large-scale migrations

WorkOS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about WorkOS and has not been reviewed or approved by WorkOS.

  • Fair & Transparent Compensation Pay is considered competitive for the tech market, with no prominent pay-related discontent raised in the provided information. Salary ranges shown for some roles and market-aligned bands reinforce perceptions of fairness.
  • Healthcare Strength Healthcare coverage is described as strong, with the employer covering a substantial share of medical, dental, and vision premiums for employees and dependents. This breadth and cost sharing are presented as a core strength of the total rewards package.
  • Wellbeing & Lifestyle Benefits Monthly fitness and wellness stipends plus a home-office budget support physical and mental health and remote-work comfort. Remote-first flexibility and autonomy further enhance day-to-day quality of life.

WorkOS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
48 Employees
Year Founded: 2019

What We Do

WorkOS provides APIs to make your app enterprise-ready, with pre-built features and integrations required by IT admins. Start selling to enterprise customers with just a few lines of code. Add Single Sign-On (SSO) to your app for free.

Similar Jobs

Sailor Health Logo Sailor Health

Advocate Support Coordinator

Healthtech • Social Impact • Telehealth
Remote
Canada
20 Employees
40K-50K Annually

Apollo.io Logo Apollo.io

Senior Back-end Engineer

Artificial Intelligence • Enterprise Web • Information Technology • Productivity • Sales • Software • Database
Easy Apply
Remote
Canada
850 Employees

2K Logo 2K

Lead Developer, Tools

Gaming • Information Technology • Mobile • Software • Esports
Remote or Hybrid
Québec, QC, CAN
4200 Employees

GitLab Logo GitLab

Operations Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
2 Locations
2500 Employees
139K-235K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account