Principal Platform Engineer || Identity Platform (AuthN/AuthZ)
IFS
Company Description At IFS, we're building the next generation of AI-native enterprise software, transforming how some of the world's largest organisations manage assets, operations and critical services.   Before you apply This role is about building and operating identity infrastructure, not administering it or governing it. It is not a fit if your identity experience is: Managing Entra ID, Okta or AWS IAM as a consumer of a platform someone else operates: RBAC, PIM, Conditional Access, SSO configuration, least-privilege policy Identity governance and administration: SailPoint, Saviynt, joiner-mover-leaver, access certification campaigns, provisioning workflows Security governance, IAM audit, policy authoring or architecture-only work Kubernetes RBAC and cloud IAM policies as part of a DevOps or SRE role All valuable work.
None of it is this job. It is a fit if you have personally run an identity provider in production. Installed it, configured it, extended it, upgraded it, sized it, cut over between versions, restored it, and been on call when authentication broke at three in the morning. If you have done that with Curity, we want to talk to you today. This is a hands-on role and we expect you to still be writing code.
We also expect that AI tooling has changed how you work. We'll ask what you delegate, what you still do yourself, and what you built to stop it breaking. Specifics, not a list of tools... so if you can evidence the correct experience for our role, please read on.  IFS is a billion-dollar revenue company with 7000+ employees on all continents. We deliver award-winning enterprise software solutions through the use of embedded digital innovation and a single cloud-based platform to help businesses be their best when it really matters–at the Moment of Service™.
At IFS, we're flexible, we're innovative, and we're focused not only on how we can engage with our customers, but on how we can make a real change and have a worldwide impact. We help solve some of society's greatest challenges, fostering a better future through our agility, collaboration, and trust. We celebrate diversity and accept that there are so many different perspectives in this world. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view.
By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world. We're looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs.
If you want to change the status quo, we'll help you make your moment. Join Team Purple. Join IFS. Job Description The job Authorisation is the single biggest blocker to our next-generation platform right now. Two Principal Platform Engineers are joining to unblock it. We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud.
It is built on SpiceDB (relationship-based access control) on PostgreSQL, and it has to be correct, fast, and multi-tenant at enterprise scale. Alongside it, we run enterprise authentication on Curity, with Keycloak estates migrating onto it. You will architect and build that, own it in production, and set the identity patterns the rest of engineering follows. This is a hands-on engineering role. You will write Go.
What we need to see Authorisation Fine-grained authorisation systems you have built and run at production scale, in distributed multi-tenant environments Hands-on production experience with a Zanzibar-style authorisation engine: SpiceDB, OpenFGA, Ory Keto or equivalent Authorisation schemas and permission models you have designe