We are looking for a Senior Java Backend Engineer with deep, hands-on experience in designing, building, and operating authentication and authorization services. In this assignment, you will work at the heart of an identity platform that enables secure access to products for millions of users. You will play an important role in further developing and strengthening the organization’s IAM (Identity and Access Management) capabilities.
Assignment / Responsibilities
In this role, you will:
Design, build, and operate IAM capabilities based on Keycloak and Java microservices.
Extend and customize Keycloak through custom SPIs, providers, user federation, and themes to meet evolving business requirements.
Implement and maintain authentication and authorization flows using OAuth 2.0, OpenID Connect, SAML, MFA, and social or enterprise federation.
Drive security best practices, including secure token handling, session management, and threat modeling, as well as support audits and compliance activities.
Take ownership of services in production throughout their lifecycle – from design and deployment to observability and incident response.
Collaborate with product, security, and platform teams to deliver reliable and scalable identity solutions.
Must-have Requirements
Strong Java backend development experience, including building and operating microservices in production.
Proven, hands-on experience with Keycloak in real-world deployments, including customization through SPIs and providers.
Deep understanding of OAuth 2.0, OpenID Connect, JWT, and SAML.
Proven experience designing and operating distributed systems and microservices in production.
Solid database skills, for example PostgreSQL, and familiarity with caching relevant to Keycloak deployments, such as Infinispan or Redis.
Experience with Docker, Kubernetes, and CI/CD pipelines, as well as at least one major cloud platform, AWS or Azure.
A security-first mindset and experience supporting audits and compliance requirements.
Nice to Have
Experience with CIAM at scale, such as customer identity, identity resolution, or account deduplication.
Experience with WebAuthn/FIDO2/passkeys, Zero Trust architectures, or PKI.
Experience with event-driven architectures, such as Kafka.
Experience with observability tooling such as Prometheus, Grafana, and OpenTelemetry.
Uppdragsdetaljer
- Start: ASAP
- Slut: 6 months with possible extension
- Omfattning: 100 %
- Plats: Gothenburg