Staff Engineer - Identity & Access Platform
CanadaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Team:
The User Management team owns the full identity lifecycle at AlphaSense — from creating and provisioning users, through managing their identities, to authenticating who they are and authorizing what they can do in the system. Our work spans three core domains:
- User Management — creating, provisioning, and managing user identities
- Authentication — verifying who users are
- Authorization — determining what users can do in the system
We are a product platform team, not a product team: we build the identity and access infrastructure that other engineering teams build on top of, rather than shipping user-facing features ourselves. We also act as a security guardrail for AlphaSense, since identity and access sit at the center of how the platform stays secure.
The team is well-established and senior, based in Helsinki, Finland. We're now expanding into Canada to build follow-the-sun coverage, so our customers get proper support around the clock, and to push deliberately toward a true platform model — scaling our authentication and authorization systems so they can be safely self-served by teams across the company.
About the Role:
This is a Staff Engineer role on the team that manages identity and access for AlphaSense's entire, and constantly growing, customer base, and that nearly every product engineering team depends on for user and entitlement data. You'll work across all three pillars of identity: creating and managing users, authenticating them, and authorizing what they can do — designing systems built to scale with a constantly growing number of users. Security is core to this role, not adjacent to it — you'll work closely with our security teams to make sure what we build is secure by design, in an environment governed by SOC2 and GDPR.
We're looking for a genuinely senior, self-sufficient engineer with strong experience building and operating identity, authentication, or authorization platforms at scale, ideally in a platform/product-platform engineering context. This is someone who doesn't just execute a roadmap, but helps understand the needs behind it, shapes it, and then drives execution — largely autonomously, and in close collaboration with our core team based in Helsinki. You're genuinely interested in security, comfortable partnering closely with security teams on secure-by-design systems, and comfortable working in a distributed, cross-timezone setup — based in Canada, collaborating closely with a Helsinki-based team.
Who You Are:
- Backend: Java 2X, Spring Boot 3.X.X, WebFlux, Maven
- Data & APIs: SQL, GraphQL, gRPC, REST
- Cloud & Infrastructure: AWS, GCP, Kubernetes, Helm
- Identity & Security Protocols: RBAC/ABAC/ReBAC; OAuth 2.0, OIDC, and JWT; SAML 2.0 and enterprise SSO federation (assertion validation, signature/encryption handling, IdP- vs. SP-initiated flows); SCIM for user provisioning and deprovisioning
- Engineering Practices: Event-driven architecture patterns; TDD or a genuine passion for automated testing
[Nice to Have]
- Auth0 experience
- SpiceDB / Zanzibar-style authorization system experience
- Apollo Federation
- OpenTelemetry
- Experience operating within SOC2 and/or GDPR-compliant environments
What You’ll Do:
This role spans all three pillars of our identity platform in equal measure — this is not an authorization-only or authentication-only role.
- Design, build, and evolve our authorization platform (RBAC/ABAC/ReBAC), enabling teams across the company to answer "what can this user do?"
- Design, build, and evolve our authentication platform, covering authentication patterns across our range of use cases, working closely with our Auth0 integration
- Design, build, and evolve our user management platform — creating, provisioning, and managing user identities and entitlements — supporting our entire customer base
- Partner closely with security teams to ensure our authentication, authorization, and user management platforms are secure by design and aligned with SOC2 and GDPR requirements
- Design and implement highly scalable systems that keep pace with a constantly growing number of users and customers
- Help define the long-term roadmap across all three domains — authentication, authorization, and user management — not just execute against one handed to you
- Build self-service systems and APIs (GraphQL, gRPC, REST) that make authentication, authorization, and user data consumable by product engineering teams across the company
- Drive projects autonomously from Canada while staying closely aligned with our Helsinki-based team
- Champion strong testing, observability, and reliability practices across the platform
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.