Job Description
Co-drive the build vs. buy evaluation for centralized authorization - contribute to vendor bake-offs (Oso, Permit.io, Cerbos, OpenFGA, AuthZed, AWS Verified Permissions/Cedar) against an in-house option, weighing latency, flexibility, operational cost, and vendor lock-in. Help design the policy model: roles vs. permissions vs. relations, org-level vs. resource-level roles, role hierarchies, resource ownership/sharing, multi-tenancy. Partner on the decision engine architecture: low-latency authorization checks, caching, consistency tradeoffs, audit/versioning of policies. Work with platform/security/IAM teams to integrate authz checks into services (sync and async enforcement points). Build reference implementations, SDKs, and middleware so other engineering teams can adopt the centralized model instead of ad hoc checks. Contribute to testing practices (policy unit tests, authorization test suites) and the migration plan from today's scattered checks to a single policy engine. 5-8+ years backend/software engineering experience shipping production systems. Hands-on experience working on or building an authorization system - solid RBAC fundamentals, with real understanding of roles, permissions, role hierarchies, and resource-level vs. org-level scoping. Solid conceptual grounding in authz fundamentals - able to reason through tradeoffs between RBAC, ABAC, and ReBAC (relationship-based / Zanzibar-style) approaches. Some exposure to evaluating or integrating a policy engine/framework (Oso, OPA/Rego, Cerbos, OpenFGA, AuthZed/SpiceDB, AWS Cedar) - or having worked on an equivalent in-house. Strong systems design skills: low-latency decision services, caching, consistency vs. performance tradeoffs. Proficient in one backend stack (Java/Kotlin/Go/Node/Python). Experience with policy-as-code languages (Rego, Cedar, Polar) or Zanzibar-paper-inspired systems. Has participated in a build-vs-buy or vendor RFP process before. Familiarity with AuthN (OAuth/OIDC) and how the AuthN/AuthZ boundary is typically drawn. Experience on large-scale multi-tenant SaaS platforms. Experience building this external organizations in a b2b (not just internal access controls) Open-source contributions to authz projects (OpenFGA, Cerbos, Casbin, etc.).