Padmi
Atlassian logo
Atlassian

project management software · Jira

Principal Backend Engineer - Identity and Security Infrastructure

BangalorePosted 1 month ago
Software engineeringStaff+Full Time; Regular
Apply at Atlassian

Opens the source posting on shine.com

Source description

About the role

View original

Principal Software Engineer, Identity & Security Infrastructure Overview Working at Atlassian Atlassians can choose where they work whether in an office, from home, or a combination of the two. That way, Atlassians have more control over supporting their family, personal goals, and other priorities. We can hire people in any country where we have a legal entity. Responsibilities About the Role We are looking for a Principal Engineer to lead the architecture, evolution, and operational excellence of our identity and security infrastructure platforms. These systems underpin service-to-service authentication, staff-to-service authentication, authorization policy enforcement, and cryptographic key management across thousands of microservices at scale. You will own the technical vision for how our cloud platform establishes and verifies trust from ingress/egress authentication at the service mesh layer to cryptographic keypair lifecycle management. This is a high-leverage, cross-organizational role where your decisions directly impact the security posture and developer experience of the entire engineering organisation. What You'll Do Architect and evolve platform-wide authentication and authorization systems handling millions of requests per second across a global microservices fleet. Design and own ingress and egress authentication mechanisms for microservices, including proxy-based sidecars, service mesh integration, and token validation pipelines. Lead the technical strategy for service-to-service authentication using JWT-based protocols including token issuance, audience-scoped validation, claims design, and revocation strategies. Own cryptographic key infrastructure key generation, rotation, auto-rotation, revocation, and secure distribution of asymmetric keypairs (RSA/EC) at scale via CDN-backed repositories. Design and scale the Policy Decision Point (PDP) for centralized authorization (AuthZ), enabling fine-grained, policy-as-code access control across all services. Define trust models for staff-to-service authentication bridging human identity providers (SSO/OIDC/SAML/Kerberos) into machine-trust contexts for developer and operator access. Architect build token and workload identity systems enabling CI/CD pipelines and ephemeral workloads to authenticate securely without long-lived credentials. Drive reliability and operational excellence for Tier-0 security infrastructure SLO definition, incident response, capacity planning, and chaos engineering. Influence cross-org technical direction through RFCs, architecture reviews, and engineering-wide standards for authentication, authorization, and secrets management. Mentor and grow senior engineers; raise the security engineering bar across multiple teams. Essential Skills & Experience Core Requirements 12+ years of software engineering experience, with 5+ years designing and operating large-scale identity, authentication, or security infrastructure systems. Deep expertise in service-to-service authentication mTLS, signed JWT tokens (RS256/ES256), certificate-based identity, SPIFFE/SPIRE, or equivalent trust frameworks. Hands-on experience with JWT ecosystems token issuance services, audience-bound validation, claims schema design, key rotation strategies, and token revocation/blacklisting. Strong understanding of ingress/egress authentication patterns API gateways, Envoy/proxy-based auth plugins, sidecar architectures, and service mesh trust propagation. Experience building or operating a Policy Decision Point (PDP) for authorization (AuthZ) policy-as-code engines (OPA/Rego, Cedar, or equivalent), policy distribution, and decision logging for audit/compliance. Expertise in cryptographic key management asymmetric keypair generation, automated rotation, secure storage, and large-scale public key distribution (CDN/S3-backed or equivalent). Experience with build tokens and workload identity authenticating CI/CD pipelines, ephemeral compute, and automated systems without static secrets. Staff-to-service authentication design integrating enterprise identity providers (Okta, SAML 2.0, OIDC, Kerberos) with service-layer trust to enable secure developer/operator access. Proficiency in Java/Kotlin (primary) and Go (secondary); comfortable working across polyglot service ecosystems. Production Kubernetes experience pod identity, network policies, admission controllers, and workload security in multi-tenant clusters. Cloud IAM expertise (AWS IAM / GCP IAM) role assumption, workload identity federation, and least-privilege access patterns. Track record of operating Tier-0/Tier-1 systems on-call ownership, SLO-driven reliability, incident management, and post-incident reviews. Architecture & Leadership Proven ability to drive cross-organisational technical strategy authoring RFCs, leading architecture reviews, and building consensus across 50+ engineering teams. Experience migrating or evolving authentication/authorization systems .

One address, no account. We’ll tell you when matching roles go live.

More at Atlassian

Related open roles

View all roles