Software Engineer, Backend (Security)

Base Power Company•Austin, TX
•Onsite

About The Position

Base is seeking Software Engineers to build the Identity Provider and Authorization platform that decides who — and what — can access Base's systems. Base runs on a growing mix of internal apps, cloud infrastructure, and machines that all need to authenticate and authorize safely: employees signing into AWS and GCP, services talking to each other, and devices proving their own identity in the field. This role will own the platform layer that turns fragmented, ad hoc access into a single, auditable identity system. You will design the core primitives for identity and access: workforce SSO, cloud federation, entitlements-as-code, and workload identity backed by a governed PKI. The ideal candidate is a hands-on engineer who takes security-critical systems seriously, moves fast without cutting corners on least privilege, and can turn a still-forming scope into durable infrastructure other engineers build on.

Requirements

  • Strong backend engineering experience in Go, Java, or a similar systems language.
  • Experience designing or operating identity systems — SSO/IdP, authn/authz, entitlements, or workload identity.
  • Working knowledge of OIDC, SAML, and SCIM, and judgment about when to use each.
  • Comfort with cryptographic identity primitives — PKI, mTLS, or hardware-backed keys.
  • High ownership, clear communication, and comfort making durable technical decisions in ambiguous, fast-moving environments, including scope that's still being defined.

Responsibilities

  • Build and operate Okta as Base's workforce identity provider — SSO, SAML/OIDC app integrations, SCIM provisioning, and joiner/mover/leaver lifecycle automation.
  • Design authentication policy (MFA, device assurance) and authorization primitives (RBAC, least-privilege role catalog, break-glass access) that other teams can safely build on.
  • Federate cloud access through AWS IAM Identity Center and GCP Workforce Identity Federation, replacing long-lived IAM users and service-account keys with short-lived credentials.
  • Define and maintain entitlements-as-code: every role, group mapping, and access grant lives in the GitOps monorepo as a reviewable pull request.
  • Build workload and headless identity infrastructure — private CA/PKI, AWS Roles Anywhere, GCP WIF-X509, and hardware-backed key custody (Secure Enclave, TPM, YubiKey).
  • Define Identity Assurance Level requirements, per NIST SP 800-63-3, for internal, partner, and service-to-service access.
  • Partner with IT, security, and application teams to keep identity, groups, and tokens as the shared foundation, while apps continue to own their own authorization business logic.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service