Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
IFS

Principal Platform Engineer – Identity and Access Management

IFS

Principal Platform Engineer focusing on identity and access management in AI-native enterprise software. Leading architectural solutions and engaging in hands-on engineering across production platforms.

Posted 7/29/2026full-timeRemote • 🇬🇧 United KingdomLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in architecting and engineering enterprise-scale identity and access management solutions, with a focus on authorisation models and secure coding practices. Proficient in operating and optimizing authorisation engines like SpiceDB in production environments.

Highest-signal resume keywords
Identity And Access Management (IAM)Authorisation ModelsSpiceDBOAuth 2.0Secure Coding Practices

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Production AI Applications DesignFine-Grained Authorisation SystemsAuthorisation SchemasPolicy-Based AuthorisationCloud-Native OperationsSecurity-By-Design Principles
Tools & Technologies
SpiceDBCurityKeycloakPostgreSQL
Industry Keywords
Relationship-Based Access ControlRole-Based Access ControlAttribute-Based Access ControlEnterprise Identity FederationSingle Sign-On (SSO)

Tech Stack

Tools & technologies
CloudPostgres

About the role

Key responsibilities & impact
  • Be the technical authority on authorisation and authentication across the Kairos and Nexus platforms
  • Architect, engineer, and operate enterprise-scale identity and access solutions
  • Work directly with the team building the Authorisation subdomain
  • Design and implement IAM patterns that are adopted as standards across IFS
  • Ensure identity and access are enablers, not bottlenecks
  • Build the authorisation APIs and SDKs that product teams consume
  • Own the operation of the authorisation engine: SpiceDB on PostgreSQL
  • Define IAM patterns, standards, and golden paths for product teams to implement securely
  • Provide subject-matter expertise on identity and access security

Requirements

What you’ll need
  • Hands-on experience designing production AI applications
  • Architecting and engineering fine-grained authorisation systems at production scale
  • Hands-on production experience with a relationship-based / policy-based authorisation engine, ideally SpiceDB or comparable Zanzibar-inspired systems
  • Deep, practical knowledge of authorisation models: relationship-based access control, role-based, and attribute-based
  • Experience designing authorisation schemas and permission models
  • Familiarity with policy-as-code approaches and tooling
  • Understanding of running the authorisation engine in production
  • Hands-on production experience with Curity and/or Keycloak
  • Deep knowledge of OAuth 2.0, OpenID Connect, SAML 2.0
  • Experience with enterprise identity federation, SSO, and directory integration
  • Strong hands-on engineering capability across the NGA stack
  • Comfortable operating in a cloud-native environment
  • Secure coding practices and security-by-design principles

Benefits

Comp & perks
  • Flexible work arrangements
  • Professional development opportunities