About The Position

Redpanda is seeking a Staff Software Engineer to own the technical direction for Authentication (AuthN), Authorization (AuthZ), and On-Behalf-Of (OBO) for agents within both the Agentic Data Plane and the Cloud platform. This is a high-autonomy, high-influence individual contributor role focused on designing and building systems that manage agent identity and access in production AI environments. The role involves extending existing authorization servers and token vaults, developing delegated tool-access flows, and creating cryptographic delegation models. A key aspect of the role is partnering with identity federation services (like Okta, Entra, Ping) to ensure Redpanda enforces access locally while cleanly federating with customer identity providers. The engineer will work cross-functionally with engineering, security, and product teams, represent Redpanda's technical position externally, and mentor other engineers on identity and access concepts. The position is measured by shipped, production-hardened systems.

Requirements

  • 10+ years of experience in software development and delivery, with deep, hands-on expertise in authentication, authorization, or identity systems specifically
  • Production experience with OAuth 2.0/2.1, OIDC, token exchange or delegation patterns (e.g. RFC 8693, on-behalf-of flows), and the practical tradeoffs of running an authorization server and token vault at scale
  • A strong, current point of view on where agent identity standards are heading — MCP auth, A2A, cross-app access patterns (e.g. Okta XAA, Entra Agent ID, Auth0 for AI Agents) — and the judgment to bet on a direction before the market fully settles
  • Experience designing systems that must federate with, rather than replace, a customer's existing identity provider (Okta, Entra, Ping, or similar) in security-conscious enterprise environments
  • A track record of driving technical direction across multiple teams or orgs as an individual contributor — through design docs, RFCs, code, and direct influence, including with teams outside your own reporting chain
  • Comfortable working with a globally distributed engineering team, collaborating on GitHub, in the open, and a self starter
  • Excellent written and verbal communication skills, including the ability to explain identity and delegation tradeoffs to engineers, security teams, and customers who may not share your specialist vocabulary

Nice To Haves

  • Direct experience building or operating an OAuth 2.1/OIDC authorization server, token vault, or equivalent identity infrastructure in production
  • Experience with agent-specific identity or delegation protocols (MCP auth, A2A, cross-app access/token exchange patterns) rather than only traditional human-user identity systems
  • Experience contributing to or closely tracking open standards bodies or working groups relevant to identity, OAuth, or agent authorization
  • Experience working in regulated or security-sensitive enterprise environments where identity and access decisions faced direct customer security review
  • Prior Staff/Principal-level individual contributor experience driving technical direction across multiple engineering organizations

Responsibilities

  • Own the technical direction for AuthN, AuthZ, and OBO across Agentic Data Platform and the Cloud platform — deciding which emerging industry patterns Redpanda adopts, adapts, or deliberately avoids
  • Design and build the systems yourself: extending the OAuth 2.1 authorization server and token vault, delegated tool-access flows, and the cryptographic delegation model that lets an agent act on-behalf-of a human or another agent with a provable, auditable chain of authority
  • Partner closely with the identity-federation surface (Okta, Entra, Ping, and similar) so Redpanda enforces access locally while federating cleanly with what enterprise customers already run
  • Work cross-functionally with Agentic Data Plane and Cloud platform engineering, Security, and Product to make sure identity and delegation decisions hold up under real customer security review — not just internal design review
  • Represent Redpanda's technical position on agent identity externally where relevant — in customer-facing security conversations, documentation, or engagement with emerging standards efforts
  • Ship to customers: this is an IC role measured on shipped, production-hardened systems, not just architecture proposals
  • Mentor and level up engineers across both Agentic Data Platform and Cloud platform on identity and access concepts, without formal management authority over them
  • Bring up difficult and/or systemic challenges and impediments to the attention of engineering leadership
  • Actively discuss strategic topics with peers and Directors to help shape engineering's environment
  • Track progress, assess risks, and actively communicate contingency and mitigation plans for the initiatives you own

Benefits

  • Team members around the globe
  • Culture based on trust, transparency, communication, and kindness
  • Nimble, high-impact team
  • Latest AI tools
  • Budget to use AI tools
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service