Software Engineer, Identity
Mercor Alabaster
About Mercor Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You'll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
Why This Role We build systems that make billions of authorization decisions a week for hundreds of thousands of users, most of them contractors and experts rather than employees. A typical company's IdP models a few thousand employees. Ours models a global expert network where membership turns over constantly, every client engagement needs its own isolation boundary, and a wrong permission can expose a frontier lab's data. The team is small, led by one of Mercor's earliest engineers, and operates with a high degree of ownership. There's no spec handed to you: you own the product scope and direction, with the team weighing in on prioritization and technical detail.
Examples of What We Build IAM-Service is our authorization service for first-party surfaces. It sits in the hot path of every request across our own products, backed by SpiceDB , an open-source implementation of Google's Zanzibar. We model access as relationships rather than roles (ReBAC instead of RBAC), which is what lets us answer "can this person see this channel, in this workspace, on this project?" consistently and fast. Every millisecond here is felt across the platform. Audiences is our rule engine for identity orchestration across third-party services. You declare who should have access to what; Audiences resolves that into concrete grants, pushes them into twenty downstream providers (Slack, Google Workspace, GitHub, and the rest), and keeps them reconciled as membership changes underneath. It turns "this expert joined this project" into working access everywhere within minutes, and "this contract ended" into revocation everywhere. One Slack workspace per client project. It's provisioned automatically on Slack Enterprise Grid, and experts join as multi-channel guests scoped only to the channels their work requires, so a project brief in the morning can be a staffed workspace by the afternoon, and no expert carries information across client boundaries. More than 2,000 workspaces, over 85,000 active Okta accounts, one administrator. Slack wrote up how it works: How Mercor Coordinates a Global AI Workforce With Slack. First-party authentication on WorkOS. Sign-in, session handling, and directory data for our own products move onto WorkOS, so they have one owner instead of being handled in several places. The interesting part is the migration: no flag day, no single moment where everything switches. People are logging in the whole time, so the existing paths keep serving traffic while the new one runs alongside them. Moving GitHub to Enterprise Managed Users. EMU makes our IdP the source of truth for GitHub accounts: identities are provisioned, deprovisioned, and auditable the same way they are everywhere else we govern, and removing someone from the directory removes their GitHub access. The hard part is the cutover: mapping existing accounts to the identities we govern, and keeping a live engineering org and a large external contributor population pushing code the whole way through. Data-loss prevention across thousands of workspaces. Each client engagement carries its own confidentiality terms, so there is no single ruleset. There are thousands of overlapping ones, scoped per grid, per workspace, per project, and those are created and torn down automatically. The hard part is distributing and evaluating policy at that scale: getting the right rules onto every new workspace, channel, and DM as it appears, re-scoping when a project changes shape, and enforcing consistently without slowing communication down. Audiences decides who gets into a workspace; the same rule engine has to decide what can be said inside it.
What You'll Do
Why This Role We build systems that make billions of authorization decisions a week for hundreds of thousands of users, most of them contractors and experts rather than employees. A typical company's IdP models a few thousand employees. Ours models a global expert network where membership turns over constantly, every client engagement needs its own isolation boundary, and a wrong permission can expose a frontier lab's data. The team is small, led by one of Mercor's earliest engineers, and operates with a high degree of ownership. There's no spec handed to you: you own the product scope and direction, with the team weighing in on prioritization and technical detail.
Examples of What We Build IAM-Service is our authorization service for first-party surfaces. It sits in the hot path of every request across our own products, backed by SpiceDB , an open-source implementation of Google's Zanzibar. We model access as relationships rather than roles (ReBAC instead of RBAC), which is what lets us answer "can this person see this channel, in this workspace, on this project?" consistently and fast. Every millisecond here is felt across the platform. Audiences is our rule engine for identity orchestration across third-party services. You declare who should have access to what; Audiences resolves that into concrete grants, pushes them into twenty downstream providers (Slack, Google Workspace, GitHub, and the rest), and keeps them reconciled as membership changes underneath. It turns "this expert joined this project" into working access everywhere within minutes, and "this contract ended" into revocation everywhere. One Slack workspace per client project. It's provisioned automatically on Slack Enterprise Grid, and experts join as multi-channel guests scoped only to the channels their work requires, so a project brief in the morning can be a staffed workspace by the afternoon, and no expert carries information across client boundaries. More than 2,000 workspaces, over 85,000 active Okta accounts, one administrator. Slack wrote up how it works: How Mercor Coordinates a Global AI Workforce With Slack. First-party authentication on WorkOS. Sign-in, session handling, and directory data for our own products move onto WorkOS, so they have one owner instead of being handled in several places. The interesting part is the migration: no flag day, no single moment where everything switches. People are logging in the whole time, so the existing paths keep serving traffic while the new one runs alongside them. Moving GitHub to Enterprise Managed Users. EMU makes our IdP the source of truth for GitHub accounts: identities are provisioned, deprovisioned, and auditable the same way they are everywhere else we govern, and removing someone from the directory removes their GitHub access. The hard part is the cutover: mapping existing accounts to the identities we govern, and keeping a live engineering org and a large external contributor population pushing code the whole way through. Data-loss prevention across thousands of workspaces. Each client engagement carries its own confidentiality terms, so there is no single ruleset. There are thousands of overlapping ones, scoped per grid, per workspace, per project, and those are created and torn down automatically. The hard part is distributing and evaluating policy at that scale: getting the right rules onto every new workspace, channel, and DM as it appears, re-scoping when a project changes shape, and enforcing consistently without slowing communication down. Audiences decides who gets into a workspace; the same rule engine has to decide what can be said inside it.
What You'll Do
- Keep a billion-plus weekly permission checks correct and fast. Own the hot path: the SpiceDB schema, the relationship graph, and the caching, denormalization, and consistency tradeoffs that decide whether authorization is invisible or the reason a page is slow
- Model authorization in SpiceDB. Design the definitions, relations, and permissions expressing how experts, employees, workspaces, channels, projects, and client engagements relate, and evolve that schema without breaking live checks
- Extend the Audiences rule engine. Add providers, express new access rules, and make the fan-out reliable enough that operations trusts it without a human checking
- Scale the downstream providers themselves (Slack Enterprise Grid, GitHub, Google Workspace, DLP and monitoring), including the bulk operations, quota engineering, and reconciliation that none of them make easy
- Own provisioning fan-out end to end , with reconciliation that catches drift rather than trusting that every write succeeded
- Close the gap between HR truth and system truth. Joiner/mover/leaver is driven by upstream systems that lag real org change. Build lifecycle automation that degrades safely when the source of truth is wrong or late, because at our scale it will be
- Extend identity to non-human principals. Agents and services increasingly need first-class identities, scoped credentials, and auditable authorization: the same rigor as human access, with none of the same assumptions
- Talk directly with ops teams to understand business requirements, then translate them into large-scale distributed systems designed with security in mind from the start
- Design for the security implications of what you're building. Not auditing after the fact, but thinking through how gaps in system design compound at scale
- Strong product engineering fundamentals. You've built and operated systems in production, you care about correctness and reliability, and you're comfortable owning scope without a lot of hand-holding
- Large-scale distributed systems experience. This is the most identifiable signal on a resume and a strong filter; the problems here are genuinely unprecedented in scale
- Comfort with data modeling under consistency constraints. You've reasoned about stale reads, cache invalidation, and eventual consistency in a system where being wrong has real consequences
- Experience pushing third-party platforms past their intended limits. Rate limits, quotas, bulk APIs, and the reconciliation you build when a vendor's guarantees run out
- Security-minded thinking. Not a formal background necessarily, but the instinct to ask "how does this break, and what are the consequences?" when designing a system
- Adaptability. We don't want someone who will come in and replicate what they've done before; Mercor's landscape is unique and requires genuine intellectual flexibility
- Direct experience with SpiceDB, Zanzibar, OpenFGA, Ory Keto, or an in-house ReBAC/policy engine (Cedar, OPA, Oso)
- Having built or operated SCIM provisioning , SSO integrations (SAML, OIDC/OAuth 2.0), or an internal IdP integration layer
- Operating Slack Enterprise Grid, Google Workspace, or GitHub Enterprise at multi-tenant scale, or across hundreds of thousands of live access grants
- DLP, data governance, or insider-risk tooling deployed across a large and largely external population
- Work on workload or machine identity : SPIFFE/SPIRE, short-lived credentials, service-to-service authz
- Having migrated an org onto a managed identity provider, or replaced a role-based permission system with a relationship-based one, and lived through it
- Generous equity, vested over 4 years
- Up to $15K relocation bonus
- $10K housing bonus (if you live within 0.5 miles of the office)
- $1,500/month meals stipend
- Free Equinox membership
- $200/month laundry reimbursement
- $200/month personal wellness reimbursement
- Health, Dental, and Vision insurance
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Software Engineer, Identity in San Francisco, CA vacancy
- ...foundational systems and capabilities that enable Sierra to serve the world’s largest and most demanding enterprises. This includes the identity, access management, integration points, and extensibility that enterprise customers require to allow customers to embed Sierra...SuggestedFull timeFlexible hours
- ...Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE The largest, most... ...agents access the platform. This is the founding role for our identity and authorization team within enterprise engineering. You'll...SuggestedFull timeFlexible hours
- ...Francisco, NYC, or London offices. Why This Role Mercor's identity infrastructure is unlike anything else in the Valley. Our... ...systems problems we have. This team is led by Mercor's first engineer. It operates with a high degree of ownership: you'll take requirements...SuggestedFull timeFor contractorsWork at officeRelocation package
$180k - $225k
Software is eating the world, but AI is eating software. We live in unprecedented times -... ...products include the Generative AI Data Engine, SGP, Donovan, and others that power the... ...the foundation of these products is the Identity Engineering team. In this role, you will...SuggestedFull timeLive in- ...Senior Software Engineer At Commure, we're building the AI Operating System for healthcare, the foundation that defines how care is delivered... ...built right now. Come deliver this transformation. The Identity Platform team, within the broader Frameworks organization,...SuggestedWork at officeLocal areaImmediate start
$150k - $180k
...sophisticated marketing simple by unifying identity, intelligence, and omnichannel... ...powering the Zeta Identity Graph. How do you engineer distributed architectures to manage a profile... ...events? We seek an innovative Senior Software Engineer to help navigate this exact scale...$211k - $251k
...platform capabilities that allow Sierra to serve large, demanding organizations. We will develop the foundational systems for identity, access management, integrations, and extensibility so customers can embed Sierra into their existing ecosystems. We will help...Full timeFlexible hours$126k - $248k
...MongoDB clusters in just minutes.We're seeking a Senior Engineer to join the Atlas Identity and Access Management (IAM) team. IAM is a platform and... ...and initiativesCandidate Profile5+ years experience of software engineering, primarily focused on backend systemsProficient...Local areaRemote workWorldwideFlexible hours$150k - $200k
...vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single... ...available, low-latency, and built to scaleWe are looking for a Lead Software Engineer who brings strength in both backend distributed systems and...$130k - $196.5k
...groundbreaking leader in consumer privacy, data ethics, and foundational identity, LiveRamp is setting the new standard for building a connected... .... We on the Pixel Serving team are part of the Identity Engineering teams at LiveRamp. We are LiveRamp’s gateway for all real-time...Full timeWork from homeFlexible hoursNight shift$140k - $260k
...Substack is building a new economic engine for culture, giving the brightest, most interesting... ...Requirements At least 5+ years of software engineering experience. Independent... ...pregnancy, sexual orientation, gender identity or transgender status), age, national origin...Full time- ...qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by law. We also consider qualified...Full timeLocal area
- ...everything from stopping fraudulent credit card swipes, verifying identities, and maximizing clean energy capture. We've recently raised... ...A , led by Felicis. About the role We are hiring Software Engineers to join our team. This is an opportunity to join us in-...Full timeWork at officeFlexible hours
$145k - $170k
...Francisco, CA Department: Product + Engineering Reports to: Director of Engineering... ...You ~6+ years of experience as a software engineer, with strong full stack capabilities... ...applications from people with these identities, or who are members of other...Full timeTemporary workWork at officeRemote workWork visa$125k - $160k
...Role Overview We are seeking a versatile Full Stack Software Engineer to join our engineering team. Reporting to the Software Engineering... ...or discrimination on the basis of a candidate’s sex, gender identity, age, marital status, veteran status, non-jobrelated...Full timeLocal areaVisa sponsorshipWork visaShift work- ...Pacific or Mountain time zones.We're looking for a Fullstack Software Engineer to join our team, passionately focused on delivering... ...discriminate based on race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran,...Work at officeLocal areaRemote work
- ...in and out of the office. We are seeking a highly motivated Software Engineer (SWE) with experience in building robust and scalable web systems... ..., childbirth, or related medical conditions), gender identity or expression, genetic information, marital status, medical...Work at officeLocal areaRemote work
$130.6k - $192k
...help us build and develop tools serving hundreds of engineers internally! We’re looking for a Fullstack Software Engineer to join our Developer Insights team.... ...domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status...Hourly payWork at officeLocal areaRemote workFlexible hours$122k - $240.5k
Position Summary Software Engineer III with Agentic AI Experience, AI & Engineering/Engineering as a ServiceAgentic AI is moving from... ...to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status...Work at officeLocal areaFlexible hoursShift work$230k - $270k
...Workplaces NY (2020, 2021, 2022, 2023, 2024) About the Role As a staff level software engineer at Maven Clinic, you will be responsible for driving the technical vision and roadmap for our Identity Platform. You will lead the design, development, and maintenance of highly...Full timeContract workWork at officeImmediate startRemote workFlexible hours3 days per week- ...Greylock, and Conviction. Join us and help build the platform engineers turn to to ship AI products. THE ROLE As a Senior Enterprise... ...to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information,...Full timeFlexible hours
- ...groundbreaking leader in consumer privacy, data ethics, and foundational identity, LiveRamp is setting the new standard for building a... ...and privacy requirements. LiveRamp is looking for a Senior Software Engineer to help shape the next generation of Data Marketplace...Full timeWork from homeFlexible hoursNight shift
- ...believe agent development is an evolution of software development that requires new tools and... .... You’ll design systems that enable engineers and customers to build reliable, steerable... ...status, pregnancy, gender expression or identity, sexual orientation, citizenship, or any...Full timeFlexible hours
$213k - $320k
...the Role: As a Developer Platform engineer, you will directly contribute to the foundational... ...years of experience shipping production software, with a strong track record of owning... ...information, veteran status, gender identity or expression, sexual orientation, or...Full timeLocal area$114.1k - $268.18k
...Technology Organization. Responsibilities: Lead ServiceNow Identity Governance and Veza implementations including solution design,... ...management, access requests, reviews, certifications, role engineering, workflows, policies, and enterprise integrations Strong understanding...Full timeH1bLocal area$347k - $405k
About the TeamThe Enterprise Identity team builds the identity foundation that enables organizations to adopt and use OpenAI products... ...beyond the immediate team.Provide technical leadership to senior engineers and raise the quality of architecture and execution across the...Work at officeLocal areaImmediate startFlexible hours- ...artificial general intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this effort, designing and... .... About the Role We’re looking for a Staff+ Software Engineer to help build and evolve the identity infrastructure...Full timeWork at officeRelocation package
$134.5k - $265.1k
...including PlainID. This role combines deep technical ownership with engineering expertise, governance, and stakeholder management.Work you’ll... ...restrictions where needed.Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock)...Local areaVisa sponsorship$130.6k - $192k
...world's most reliable on-demand, logistics engine for delivery! We're looking for talented... ...~3+ years of industry experience in software engineering ~ Strong backend fundamentals... ...status, sexual orientation, gender identity or expression, disability status, or veteran...Hourly payWork at officeLocal areaRemote workFlexible hours- ...About Persona Persona is the configurable identity platform built for businesses in a... ...the role We are looking for passionate engineers who are excited to build the data foundation... ...Persona ~5+ years of experience in software engineering, with deep expertise in data...Full timeFor contractorsInternshipImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Software Engineer, Identity. Be the first to apply!
Related searches
- software developer positions San Francisco, CA
- senior software engineer remote San Francisco, CA
- software engineer contract San Francisco, CA
- IT software developer San Francisco, CA
- cybersecurity software engineer San Francisco, CA
- part time software developer remote San Francisco, CA
- junior software developer internship San Francisco, CA
- junior software engineer San Francisco, CA
- software system engineer San Francisco, CA
- software engineer remote San Francisco, CA




