Senior Software Engineer, Cloud Identity
Temporaltechnologies•4d ago
United StatesRemote$212K–$237KFull-timeSenior Level5+ yrs exp
Top focus
Software EngineerSenior Software EngineerSoftware Engineer IiCloud EngineerIdentity Engineer
- About Us
- Temporal is an open source programming model that can simplify code, make applications more reliable
- help developers focus on the important things like delivering features faster. We are on a mission to be the reliable foundation of every developer’s toolbox
- are building the team that will make that happen.
- Our values guide us —they are present in how we show up, make decisions, and work together to make an impact. We’re curious, driven, collaborative, genuine and humble.
- Temporal is growing and we are looking for those who share our values, challenge 'standard' thinking
- want to influence our future. If you have a passion for improving the developer experience, building world-class open-source software and communities
- want to be a part of our amazing team, we'd love to hear from you!
- Summary
- Temporal is hiring a Senior Software Engineer for Identity to help design, build
- operate the identity and access systems behind Temporal Cloud — a multi-tenant SaaS platform. You'll work on the systems that authenticate users and workloads, authorize access to namespaces and APIs
- integrate with customer identity providers. You'll partner with Security, Product
- infrastructure teams to deliver "secure by default" capabilities while keeping the developer and operator experience strong.
- What You'll Do
- Build and improve core parts of Temporal Cloud's identity platform — authentication (OAuth 2.0/OIDC, SAML), authorization (RBAC and policy-based access)
- workload identity — so customers and workloads can authenticate securely
- Help keep the auth path fast and reliable to meet Temporal Cloud's SLOs through caching, token handling, and revocation strategies
- Integrate with enterprise identity providers (Okta, Entra ID, Google Workspace) and support user provisioning (SCIM), with attention to common identity threats such as token replay and privilege escalation
- Partner with Security, Product, and platform teams to ship secure-by-default patterns and contribute to IAM lifecycle and audit practices
- Write clear architecture and design docs, and contribute to the team's technical direction
- What You'll Bring
- Solid hands-on experience building and operating production identity or auth systems — OAuth 2.0/OIDC, SAML, JWT, and token/key rotation
- Good understanding of authorization models (RBAC, ABAC); familiarity with policy engines like OPA, Cedar, or OpenFGA is a plus
- Experience operating distributed systems in production, including some on-call responsibility
- Proficiency in Go; experience with Python, Java, or Rust is a plus
- Strong communication skills and the ability to collaborate across security, product, and engineering teams
- Nice to Have
- Exposure to workload identity or short-lived / federated credentials (SPIFFE/SPIRE, mTLS, WIF)
- Experience with SCIM provisioning and enterprise SSO integrations
- Contributions to identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE)
- Familiarity with compliance frameworks (SOC 2, ISO 27001, HIPAA) as they apply to IAM
- Familiarity with Temporal or other durable-execution engines, especially auth implications around workers and task queues
- Experience designing customer-facing API auth (scoped tokens, API keys, rotation)
- Compensation
- Base Salary Range - $212,000 to $237,000, depending on qualifications and location
- Equity Options - Eligible for stock options as part of Temporal's equity plan
- Compensation ranges reflect salary and commission compensation (when applicable) across several geographic markets. Employment offers carefully consider multiple factors, including prior experience, knowledge, expertise, skillset, market location
- job level assessed during the interview process.
- Employee benefits and perks below are for full-time employees, part-time or temporary positions are excluded.
- U.S. Benefits
- Unlimited PTO, 12 Holidays + 2 Floating Holidays
- 100% Premiums Coverage for Medical, Dental, and Vision
- AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
- Empower 401K Plan
- Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!
- International Benefits
- Paid Time Off (PTO) and Benefits outside the United States vary by country
- are issued in partnership with Remote.com . Additionally, Temporal offers perks to all international employees for learning & career development, a lifestyle spending account, in-home office setup (in addition to company-issued hardware), professional memberships, work-from-home meals
- access to the Calm app for mental wellness.
- Travel
- Temporal is a globally distributed, collaborative team that values opportunities for in-person connection. Occasional travel may be required for company events, team offsites
- other meaningful moments that bring us together.
- Additional Perks
- $3,600 / Year Work from Home Meals
- $1,800 / Year Professional Enrichment (Career Development & Professional Memberships)
- $1,200 / Year Lifestyle Spending Account
- $1,000 / Year In-Home Office Setup (In addition to Temporal issued equipment - laptop, monitor, keyboard, mouse, trackpad, and extension power cable at no cost to you)
- $74 / Month Reimbursement for Internet
- Calm App Subscription for Mental Health & Wellness
- Temporal Technologies is an Equal Opportunity Employer. Temporal Technologies does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status
- any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit
- business need. We embrace and celebrate differences and diversity.
- Temporal is committed to providing access, equal opportunity
- reasonable accommodation for individuals with disabilities in employment, its services, programs
- activities. If you need to request a reasonable accommodation, please let your Recruiter know so we can assist.
- We are not working with external recruitment agencies, thanks.
Required skills
OAuth 2.0OIDCSAMLJWTGoPythonJavaRustRBACABACOPACedarOpenFGASCIM