Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Software Engineer, Cloud Identity

$212k - $286k

Temporal Technologies

Staff Software Engineer, Cloud Identity

United States - Remote Opportunity

About Us

Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster. We are on a mission to be the reliable foundation of every developer's toolbox, and are building the team that will make that happen. Our values guide us —they are present in how we show up, make decisions, and work together to make an impact. We're curious, driven, collaborative, genuine and humble. Temporal is growing and we are looking for those who share our values, challenge 'standard' thinking, and want to influence our future. If you have a passion for improving the developer experience, building world-class open-source software and communities, and want to be a part of our amazing team, we'd love to hear from you!

Summary

Temporal is hiring a Staff Software Engineer for Identity to design, build, and operate the identity and access platform behind Temporal Cloud — a multi-tenant SaaS serving high-throughput workloads. You'll own the systems that authenticate humans and workloads, authorize fine-grained access to namespaces and APIs, federate with customer IdPs, and distribute auth material to clients and workers at scale. This role partners closely with Security, Product, and platform teams to deliver "secure by default" capabilities without compromising developer or operator experience.

What You'll Do

  • Design and build Temporal Cloud's identity platform end-to-end — authentication (OAuth 2.0/2.1, OIDC, SAML, token exchange), authorization (RBAC/ReBAC/policy engines), and workload identity federation — so customers and workloads authenticate without long-lived secrets
  • Scale the auth hot path to meet Temporal Cloud's SLOs: in-memory auth bundles, JWKS caching, decision caching, and revocation strategies that keep latency low and eliminate single points of failure
  • Integrate with enterprise IdPs (Okta, Entra ID, Google Workspace, SAML/OIDC), own SCIM 2.0 provisioning, and threat-model identity flows against token replay, confused deputy, scope escalation, and mix-up attacks
  • Partner with Security, Product, and platform teams to ship secure-by-default patterns, define IAM lifecycle and audit strategies, and shape the technical roadmap by tracking emerging standards (IETF OAuth WG, OpenID Foundation)
  • Mentor engineers, maintain clear architecture docs, and engage directly with customers to understand requirements and unblock adoption

What You'll Bring

  • Deep hands-on experience building and operating production identity systems — OAuth 2.0/2.1, OIDC, SAML, JWT/JOSE, JWKS rotation, SCIM, and at least some exposure to workload identity (SPIFFE/SPIRE, WIF, mTLS, or short-lived federated credentials)
  • Strong grasp of authorization at scale (RBAC, ABAC, ReBAC/Zanzibar) and familiarity with policy engines like OPA, Cedar, or OpenFGA
  • Track record operating latency-sensitive distributed systems in production, including on-call ownership and operational excellence
  • Proficiency in Go; experience with Python, Java, or Kotlin is a plus
  • Strong communication skills with the ability to align stakeholders across security, product, and engineering and drive execution end-to-end

Nice to Have

  • Contributions to identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE) or standards bodies (IETF OAuth WG, OpenID Foundation)
  • Experience with compliance frameworks (FedRAMP, SOC 2, ISO 27001, HIPAA) as they apply to IAM
  • Familiarity with Temporal or other durable-execution engines, especially auth implications around workers and task queues
  • Experience designing customer-facing API auth (scoped tokens, API keys, rotation UX) and building well-structured APIs

Compensation

  • Base Salary Range - $212,000 to $286,000, depending on qualifications and location
  • Equity Options - Eligible for stock options as part of Temporal's equity plan

Compensation ranges reflect salary and commission compensation (when applicable) across several geographic markets. Employment offers carefully consider multiple factors, including prior experience, knowledge, expertise, skillset, market location, and job level assessed during the interview process. Employee benefits and perks below are for full-time employees, part-time or temporary positions are excluded.

U.S. Benefits

  • Unlimited PTO, 12 Holidays + 2 Floating Holidays
  • 100% Premiums Coverage for Medical, Dental, and Vision
  • AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
  • Empower 401K Plan
  • Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!

International Benefits

Paid Time Off (PTO) and Benefits outside the United States vary by country, and are issued in partnership with Remote.com. Additionally, Temporal offers perks to all international employees for learning & career development, a lifestyle spending account, in-home office setup (in addition to company-issued hardware), professional memberships, work-from-home meals, and access to the Calm app for mental wellness.

Travel

Temporal is a globally distributed, collaborative team that values opportunities for in-person connection. Occasional travel may be required for company events, team offsites, and other meaningful moments that bring us together.

Additional Perks

  • $3,600 / Year Work from Home Meals
  • $1,800 / Year Professional Enrichment (Career Development & Professional Memberships)
  • $1,200 / Year Lifestyle Spending Account
  • $1,000 / Year In-Home Office Setup (In addition to Temporal issued equipment - laptop, monitor, keyboard, mouse, trackpad, and extension power cable at no cost to you)
  • $74 / Month Reimbursement for Internet
  • Calm App Subscription for Mental Health & Wellness

Temporal Technologies is an Equal Opportunity Employer. Temporal Technologies does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need. We embrace and celebrate differences and diversity. Temporal is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist. We are not working with external recruitment agencies, thanks.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Staff Software Engineer, Cloud Identity in United States vacancy
  • $218.03k - $256.5k

     ...foster collaboration, connection, and alignment. Attendance is expected and fully supported. We're hiring a Staff Software Engineer to lead the Identity Accounts team — the platform foundation that powers every user, organization, and account at Coinbase. This is one... 
    Suggested
    Local area

    Coinbase

    Nashville, TN
    12 hours ago
  • $233.5k - $321.2k

     ...since 2010. Join us! GoFundMe is searching for a Senior Staff Software Engineer for Identity Platform to serve as the technical leader driving the...  ...experience deploying and operating identity services on cloud infrastructure (AWS, GCP, or Azure) at scale.... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Relocation
    Flexible hours
    3 days per week

    GoFundMe

    San Francisco, CA
    4 days ago
  • $230k - $270k

     ...(2022) About the Role As a staff level software engineer at Maven Clinic, you will be responsible...  ...technical vision and roadmap for our Identity Platform. You will lead the design,...  ...Propose, design, develop and implement cloud-based identity solutions that ensure... 
    Suggested
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work
    Flexible hours
    3 days per week

    Maven Clinic

    United States
    2 days ago
  • A technology company specializing in digital identity is seeking a Staff Software Development Engineer to design and build core services for identity management. The ideal candidate will have over 8 years of experience in backend development and API design, with expertise... 
    Suggested
    Full time

    ID.me

    Mountain View, CA
    5 days ago
  • A digital identity company is seeking a Staff Software Development Engineer to join their team in designing and building core services for managing identity. Responsibilities include developing APIs, ensuring data security, collaborating with various engineering teams,... 
    Suggested

    ID.me

    San Francisco, CA
    5 days ago
  • $185k - $260k

     ...zones, united by the mission to create a safer digital world. We invite you to apply today! We are looking for a Staff Software Engineer, Identity & Access Management , to serve as the technical authority for identity, authentication, and authorization across the... 
    For subcontractor
    Work at office
    Local area
    Remote work
    Flexible hours

    SimSpace Corporation

    Richmond, VA
    1 day ago
  •  ...Staff Software Engineer (Esusu Identity Services) Remote Esusu: Building Credit Access for All Your financial future shouldn't depend on your...  ...CSS. Experience with hosting platforms like Heroku and cloud providers such as Google Cloud Platform (GCP). Above... 
    Remote work
    Flexible hours

    Esusu

    United States
    16 hours ago
  • $137.6k - $212.85k

     ...We are seeking an experienced and highly-skilled Staff Software Engineer to join our Identity and Access Management (IAM) team. In this pivotal role...  ...language (e.g., Go, Java, Ruby, Node.js) and working with cloud platforms (AWS, Azure, or GCP). Experience with identity... 
    Remote work
    Work from home
    Night shift

    Bugcrowd

    United States
    2 days ago
  •  ...Staff Software Engineer for Identity Management (Go/Golang) Home Based - Americas; Home based - EMEA Canonical is a leading provider of open source...  ...used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our... 
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide

    Canonical Group Ltd

    New York, NY
    2 days ago
  •  ...Staff Software Engineer Are you ready to unlock intelligence? If you don't think you meet all of the criteria below but are still interested...  ...on the Konnect team at Kong, you'll architect Kong Identity's multi-tenant identity platform supporting complex organizational... 
    Remote work
    Worldwide

    KONG Company

    United States
    16 hours ago
  • $211.7k - $292k

     ...motivated by impact, scale, and the chance to help lead the patient revolution, come build with us. The Role As a Staff Software Engineer on Ro's Identity and Privacy team, you will build and scale systems that support secure user identity and privacy-first data... 
    Local area
    Remote work
    Flexible hours

    Ro

    New York, NY
    4 days ago
  • $197k - $247k

     ...Software Engineer San Francisco, CA At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll...  ...during the interview process. About The Team The Identity Engineering team is responsible for safeguarding customer accounts... 
    Full time
    Work at office
    Local area
    2 days per week
    3 days per week

    Gusto

    San Francisco, CA
    3 days ago
  • $236k - $339.2k

     .... There is only one Data Cloud. Snowflake's founders started...  ...it didn't stop there. They engineered Snowflake to power the Data...  ...possibilities of tomorrow. The identity & access management (IAM)...  ...engineers. AS A STAFF SOFTWARE ENGINEER - IDENTITY & ACCESS... 
    Flexible hours

    Snowflake Computing

    Bellevue, WA
    1 day ago
  • $198k - $346.5k

     ...sent from @Rippling.com addresses. About the role The Identity team's mission is to provide a single source of truth for...  ...on Rippling. We are seeking an exceptional Senior Staff Software Engineer to spearhead the evolution of our Identity and Access Management... 
    Work at office
    Worldwide
    3 days per week

    Rippling

    San Francisco, CA
    12 hours ago
  •  ...Staff Software Engineer Focused On Identity And Access Patreon is a media and community platform where over 300,000 creators give their biggest fans access to exclusive work and experiences. We offer creators a variety of ways to engage with their fans and build a lasting... 
    Work at office
    Remote work
    Worldwide
    Flexible hours
    2 days per week

    Patreon

    San Francisco, CA
    3 days ago
  • $221k - $260k

     ...people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our...  ...collective progress in identity, cryptography, AI, and global...  ...We are seeking a Senior/Staff Android Engineer to...  ...TEE) on device and in the cloud to optimize security, privacy... 
    Flexible hours

    Tools for Humanity

    San Francisco, CA
    4 days ago
  • $194k - $267k

     ...Secure Every Identity, from AI to Human Identity is the key to...  ...We are seeking a world-class Staff Engineer to help us architect and build...  ..., and resilient security software, this is the role for you....  ...scale Deep knowledge of cloud-native infrastructure... 
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    San Francisco, CA
    4 days ago
  • $110k - $220k

     ...Position Summary... We are seeking a Staff Software Engineer, Information Security to design, build, and scale identity, authentication, and authorization capabilities for...  ...systems. ~ Strong knowledge of cloud-native identity , workload identity , service... 
    Full time
    Temporary work
    Part time

    Walmart

    Bentonville, AR
    2 days ago
  • $293k - $385k

     ...intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this...  ...critical systems across multiple cloud environments. We partner with teams...  ...the Role We're looking for a Staff+ Software Engineer to help build and evolve the... 
    Work at office
    Relocation package

    OpenAI

    San Francisco, CA
    3 days ago
  • $140.4k - $372.3k

     ...leading platform for agentic software development - powered by...  ...them. We are seeking a Staff Software engineer to join this team and drive...  ...enterprise experiences for identity and authorization. In this...  ...and design, particularly in cloud-based environments, with a... 
    Remote work

    GitHub

    San Francisco, CA
    12 hours ago
  • $211.7k - $292k

     ...alone, we ranked top 5 among medium workplaces in Health Care and New York, and top 50 nationwide. The Role As a Staff Software Engineer on Ro’s Identity and Privacy team, you will build and scale systems that support secure user identity and privacy‑first data practices... 
    Local area
    Flexible hours

    Roman Health Pharmacy LLC

    New York, NY
    4 days ago
  • $293k - $385k

     ...intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this...  ...critical systems across multiple cloud environments. We partner with teams...  ...About the Role We’re looking for a Staff+ Software Engineer to help build and evolve the... 
    Full time
    Work at office
    Local area
    Relocation package
    Flexible hours

    Slope

    San Francisco, CA
    5 days ago
  •  ...Init Backfill - Senior Cloud Identity & DevOps Engineer The Senior Cloud Identity DevOps Engineer (Hands-On) will be responsible for engineering, automating, and operating enterprise Cloud Identity capabilities across AWS and Azure. This role focuses on modernizing... 

    ClifyX

    Chandler, AZ
    4 days ago
  •  ...transfer visas at this time.*** ***No Vendors/3rd parties.*** We are seeking a highly skilled and hands-on Senior Cloud Identity DevOps Engineer / Cloud Architect with strong expertise in AWS, Microsoft Azure, Terraform, and Identity & Access Management (IAM). The... 
    Remote work
    Visa sponsorship
    3 days per week

    The Brixton Group, Inc.

    United States
    3 days ago
  • $160.6k - $205.22k

     ...Senior Staff Software Engineer, Cloud Brain Corp is the global leader in robotic AI software that powers the largest fleet of autonomous mobile...  ...insurance, Employee Assistance Program (EAP), Legal/Identity support plans, pet insurance. ~ Access to Flexible Spending... 
    Work experience placement
    Work at office
    Immediate start
    Remote work
    Relocation
    Flexible hours
    Night shift

    Softbank Investment Advisers

    United States
    18 hours ago
  •  ...the enhancement of Single Sign-On (SSO) and Identity and Access Management (IAM) platforms, the part-time Identity DevOps Engineer will manage platform operations, collaborate...  ...EE, Python, PowerShell, and familiarity with cloud and DevOps tools Ability to troubleshoot... 
    Part time
    Remote work

    Virtual Vocations Inc

    United States
    19 hours ago
  •  ...systems to zonal controllers to cloud and connectivity solutions,...  ...will set the standards for software-defined vehicles around the...  .... Role Summary The Staff Software Engineer will play a critical role in...  ...reliable integration of user identity, access mechanisms, and... 
    Full time
    Contract work
    Local area

    Rivian and Volkswagen Group Technologies

    Palo Alto, CA
    3 days ago
  • $196k - $245k

     ...infrastructure that powers the Internet of Value. THE WORK: As a Staff Software Engineer, Cloud Infrastructure, you will own Ripple's cloud platform...  ...or applicants because of race, color, religion, gender identity, sex, sexual identity, pregnancy, national origin,... 
    Full time
    Work at office
    Local area

    Ripple

    Chicago, IL
    3 days ago
  • $140.4k - $372.3k

     ...leading platform for agentic software development - powered by...  ...within Actions, working across cloud infrastructure, networking,...  ...'re looking for a hands-on Staff Software Engineer to set technical direction...  ...applicants based on gender identity or expression, sexual... 
    Remote work
    Worldwide

    GitHub

    San Francisco, CA
    12 hours ago
  •  ...IDR is seeking a Identity DevOps Engineer to join one of our top clients for an opportunity in Denver...  ...trust enhancements across hybrid and cloud environments. Requirements for...  .... ~ Familiarity with PingIdentity software suite (PingOne, PingProtect, PingFed)... 
    Remote work

    IDR Healthcare

    Denver, CO
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Software Engineer, Cloud Identity. Be the first to apply!