Staff Software Engineer

HealthEquity•Remote,
•$144,000 - $237,500•Remote

About The Position

HealthEquity is rebuilding how 17 million members, their employers, brokers and partners sign in and prove who they are. The Consumer Identity team owns that platform: passwordless sign-in with passkeys, identity verification, non-member authentication for employers and partners, retail enrollment, and the identity services behind our next-generation mobile app. We are in the middle of the largest change to member authentication in the company's history and are planning the next one. You will build the systems that decide whether a login is a member or an attacker. You will do it in a small senior team that owns the full stack and ships to production often. The team is led by a director who helped write the identity standards this industry uses and has shipped passkeys at consumer scale. AI-assisted development is part of how we work.

Requirements

  • Seven or more years of software engineering, with at least three on authentication, identity or security-sensitive systems in production.
  • Deep, hands-on knowledge of OIDC, OAuth2, SAML, FIDO2 and WebAuthn, including the failure modes and the attacks against them.
  • Strong TypeScript and Node (we use NestJS) and working C# and .NET; you can read and change both codebases and choose the right one for a service.
  • Experience with at least one customer identity platform at scale (for example Transmit Security, Ory, Ping, Duende IdentityServer, Auth0 or Okta), and an informed view on build versus buy.
  • Cloud-native delivery on Azure or an equivalent: Kubernetes and Helm, API gateways, key vaults, managed identities, and CI/CD pipelines you have written yourself.
  • Comfort with GraphQL and REST API design, SQL and Postgres, and event-driven integration.
  • Daily fluency with AI-assisted development tools, hands-on experience building or orchestrating AI agents in day-to-day development, and a track record of using them to raise quality and speed, not just output.
  • Security engineering habits: threat modeling, secure defaults, dependency hygiene, and the ability to explain a vulnerability and its fix to a non-engineer.
  • Clear written communication. You will work with product, fraud operations, member services and vendors, often in writing and often across time zones.

Nice To Haves

  • Identity verification and fraud integrations: phone risk, document and selfie IDV, bank account verification, call-center voice risk.
  • Mobile authentication: app attestation, device binding, biometric unlock, deep links and app-to-web handoff.
  • Regulated-industry experience: healthcare, benefits, banking or fintech, with HIPAA or PCI exposure.
  • Observability with Dynatrace and analytics with Databricks.
  • Experience migrating credentials or users between identity systems without downtime.

Responsibilities

  • Own technical decisions and lead design across the customer identity stack: authentication, authorization, session management, and the OIDC, OAuth2 and SAML flows for member-facing applications.
  • Build the services behind them end to end, including passkey (FIDO2 and WebAuthn) registration and sign-in, step-up and out-of-band verification, and the APIs that connect our member platforms.
  • Own authentication journeys on our customer identity platform, from design through production telemetry, including identity verification with document and selfie checks and phone-based risk signals.
  • Set the standards for secure credential handling and token and session lifecycle, and partner with Information Security and Compliance on the regulatory requirements that come with financial and health data.
  • Extend non-member authentication for employers, brokers, agents and partners, including corporate-email and phone factors, and the admin tooling around them.
  • Build the identity layer for the next-generation mobile app: token exchange, session and device trust, and the GraphQL and REST endpoints it consumes.
  • Lead parts of the platform consolidation: evaluating and implementing an open-source CIAM stack, retiring legacy federation, and designing the migration paths for member credentials.
  • Work with the fraud team to wire risk signals into the login path: phone intelligence, device and behavioral signals, bank account verification, and the rules that act on them.
  • Treat security findings as engineering work: triage SCA and SAST results, fix dependency and base-image vulnerabilities, keep PII out of logs, and build the checks that stop regressions.
  • Apply agentic development practices as a normal part of the job: author and maintain the AI agent skills and workflows the team uses for code review, testing and secure implementation, use agentic coding tools for implementation and remediation, and bring the judgment to verify what they produce. Help the team set the pattern for how identity engineering uses these tools well.
  • Instrument what you ship. Dashboards, alerts and queries are part of done, and you will use them to find the next problem before members report it.
  • Write things down. Architecture notes, runbooks and knowledge-base pages are how this team scales; your work should be understandable by the engineer who picks it up after you.

Benefits

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education & tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service