Senior Engineer - Identity Platform

DrFirst Inc.,
$135,000 - $150,000Remote

About The Position

Every day, tens of thousands of clinicians launch into DrFirst applications to prescribe medications and manage patient care, and every launch flows through the identity platform. This role is the technical anchor for a production IAM platform built on Keycloak. It spans custom SPI development in Java, a major-version migration, standards-based modernization of partner SSO, and the session architecture behind a national e-prescribing network. This is platform ownership, not an integration seat. You will operate a living system with real scale, real incidents, and real migration deadlines, and you will hold the mandate to modernize it. You will regularly be the person who can read a JVM GC log, a Postgres session table, and an OAuth spec in the same afternoon. If you have wanted to be the engineer who both writes the custom grant provider and decides whether it should exist, this is that seat.

Requirements

  • 6+ years of professional software engineering with strong, production-grade Java, including significant focus on Identity and Access Management.
  • Expert Keycloak experience beyond the admin console, with hands-on SPI and extension development, realm and client architecture for multi-tenant platforms, and running Keycloak (Quarkus) in production on Kubernetes.
  • Deep OAuth 2.0 and OIDC fluency, including authorization code plus PKCE, client credentials, Token Exchange (RFC 8693), JWT Bearer (RFC 7523), and refresh rotation. Working knowledge of SAML 2.0.
  • Session and token architecture depth: stateful SSO sessions versus stateless JWT validation, online versus offline sessions, idle and max semantics, and JWKS validation and key rotation, with the judgment to choose per use case.
  • Hands-on distributed caching and state with Infinispan or comparable technology, including clustering, persistence, expiration, and the failure modes of distributed session state.
  • Production operations skill: JVM performance analysis (GC logs, heap and Metaspace sizing), correlating structured logs, and SQL-level investigation in PostgreSQL against live systems.
  • Security fundamentals and communication: OWASP-aligned secure coding, threat-model thinking around token theft and replay and brute-force protection, MFA and adaptive auth, plus the ability to write a design doc that survives review and translate trade-offs for leadership.

Nice To Haves

  • Healthcare integration experience, including EMR and EHR launch patterns, SMART on FHIR, or other regulated-industry SSO work.
  • Identity brokering experience, including Keycloak brokering and first-login flows, or federating with managed platforms such as Google Identity Platform, Azure AD and Entra, or Okta.
  • Observability with Prometheus, Grafana, or ELK, with an eye for authentication anomalies such as login-failure trends, session accumulation, and token-issuance spikes.
  • Cloud security certification (AWS Security Specialty or equivalent) and a Master’s degree in Computer Science or a related field.

Responsibilities

  • Design, build, and refactor custom Keycloak SPIs in Java, including authenticators, grant-type providers, mappers, and just-in-time provisioning. EMR SSO integrations run on custom extension code you will own end to end.
  • Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns, including JWT Bearer grants (RFC 7523), Token Exchange (RFC 8693), authorization code plus PKCE, and BFF architectures for web clients, making and defending the architectural calls.
  • Drive the Keycloak major-version upgrade, including the shift from external Infinispan session caching with JDBC persistence to persistent user sessions, and validate every downstream integration against the new version.
  • Own the session lifecycle model across SSO, client, and offline sessions, including idle and max semantics, token lifespans, and refresh rotation, and design per-client TTL policies that balance clinical workflow UX against security posture.
  • Serve as the deep-diagnosis engineer for JVM tuning (heap, Metaspace, GC), Infinispan cluster behavior, PostgreSQL session-store forensics, and log-driven root-cause analysis on live authentication traffic.
  • Design integrations with external identity systems (OIDC, SAML, cloud identity platforms), including JWKS trust, key rotation, and audience and issuer validation, and treat realm and client configuration as version-controlled, least-privilege, auditable code.
  • Raise the bar on OAuth and OIDC fluency and secure coding across the team, and represent the platform technical position to application teams and leadership.

Benefits

  • Medical, dental, and vision coverage.
  • Company-paid life and disability insurance.
  • 401(k) retirement plan with company match.
  • Flexible and generous paid time off, plus company holidays.
  • Remote-first work model with home-office support.
  • Parental leave and family support benefits.
  • Professional development and continuing-education support.
  • Employee wellness and assistance programs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service