Product Security Senior IAM Software Engineer

Rivian and Volkswagen Group TechnologiesIrvine, CA
$149,800 - $205,900

About The Position

The Product Security team develops and implements security protections into the vehicle and its supporting infrastructure. We cover the full chain of security: from defining requirements, planning both software and hardware security, to development, deployment and operationalization of the protections in production. As a Senior IAM Engineer, you will own core components of the identity and authorization platform that vehicles, cloud services, and internal teams depend on. This includes our fine-grained authorization service, OAuth2/OIDC identity stack, workload identity for cloud and on-vehicle workloads, and the authorization path for vehicle operations such as remote commands and OTA. You will drive this platform from requirements to implementation and operationalization. This role is cross functional across many aspects of RVT including vehicle software and enterprise teams.

Requirements

  • Bachelor’s degree in Computer Science, Computer Engineering, or similar field, or equivalent experience; 5+ years building and operating production backend services.
  • Strong Go (or comparable) experience building gRPC/REST services, including protobuf/API design and client SDKs.
  • Hands-on experience with modern identity and authorization: OAuth2/OIDC, JWT, mTLS, and fine-grained/relationship-based authorization (e.g. SpiceDB/Zanzibar, OPA, Cedar).
  • Experience running production services on Kubernetes and AWS (Helm/ArgoCD, EKS, IAM, KMS, VPC networking) with a SQL datastore (Postgres/CockroachDB).
  • Experience working cross functionally with heterogenous engineering teams to ensure the reliability of security critical services.
  • Experience delivering platform capabilities to heterogeneous internal engineering teams and leading projects from planning through completion.

Nice To Haves

  • SPIFFE/SPIRE or other workload-identity systems; PKCS#11 / secure-element integration.
  • Ory Hydra/Kratos or similar identity providers.
  • Event streaming (Kafka, NATS), Bazel monorepos.
  • Contributions to ADRs or security architecture documentation.

Responsibilities

  • Design, build, and operate security-critical identity and authorization services (authorization/ACL service, OAuth2/OIDC provider, workload identity, key distribution) in Go on Kubernetes/AWS.
  • Own the authorization data model: design and evolve the SpiceDB schema (resource hierarchies, roles/permissions) to enable business needs and provide APIs, SDKs, and tooling for teams to manage their permissions.
  • Demonstrate cloud native best practices through code reviews, mentorship, and partnership with other cloud first teams.
  • Participate in team incident response and on call processes.
  • Partner with the PKI team and service owners to adopt mTLS and workload identity (SPIFFE/SPIRE) as the authentication layer for the authorization platform, and guide teams on integrating certificate-based identity with SpiceDB-backed permissions
  • Mitigate vulnerabilities found or reported by internal and external parties by aligning with company’s goals and objectives.
  • Implement cybersecurity protections to comply with regulations and industry standards.

Benefits

  • competitive base salary
  • annual company performance bonus program
  • equity in the form of Restricted Stock Units (RSUs)
  • health coverage
  • retirement savings
  • time off
  • family planning programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service