Build the Identity Provider and Authorization platform for a fast-scaling energy company focused on security and access management.
Posted by employer 8 hours ago
First seen on Joblaze 4 hours ago
Last verified on the company career page 4 hours ago
What you'll build
Must have
Nice to have
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Joblaze summary
In this role, the Software Engineer focuses on developing and managing the Identity Provider and Authorization platform, ensuring secure access to Base's systems. Key skills include backend engineering in languages like Go or Java, along with experience in identity systems and cryptographic identity primitives. This position is suited for engineers who thrive in fast-paced environments and can navigate ambiguity while making critical technical decisions. The team plays a vital role in establishing a robust identity layer for a rapidly growing energy startup.
Joblaze insights
Quick facts
From the original posting
We are seeking Software Engineers to build the Identity Provider and Authorization platform that decides who — and what — can access Base's systems.
Base runs on a growing mix of internal apps, cloud infrastructure, and machines that all need to authenticate and authorize safely: employees signing into AWS and GCP, services talking to each other, and devices proving their own identity in the field. This role will own the platform layer that turns fragmented, ad hoc access into a single, auditable identity system.
You will design the core primitives for identity and access: workforce SSO, cloud federation, entitlements-as-code, and workload identity backed by a governed PKI. The ideal candidate is a hands-on engineer who takes security-critical systems seriously, moves fast without cutting corners on least privilege, and can turn a still-forming scope into durable infrastructure other engineers build on.
Build and operate Okta as Base's workforce identity provider — SSO, SAML/OIDC app integrations, SCIM provisioning, and joiner/mover/leaver lifecycle automation.
Design authentication policy (MFA, device assurance) and authorization primitives (RBAC, least-privilege role catalog, break-glass access) that other teams can safely build on.
Federate cloud access through AWS IAM Identity Center and GCP Workforce Identity Federation, replacing long-lived IAM users and service-account keys with short-lived credentials.
Define and maintain entitlements-as-code: every role, group mapping, and access grant lives in the GitOps monorepo as a reviewable pull request.
Build workload and headless identity infrastructure — private CA/PKI, AWS Roles Anywhere, GCP WIF-X509, and hardware-backed key custody (Secure Enclave, TPM, YubiKey).
Define Identity Assurance Level requirements, per NIST SP 800-63-3, for internal, partner, and service-to-service access.
Partner with IT, security, and application teams to keep identity, groups, and tokens as the shared foundation, while apps continue to own their own authorization business logic.
Strong backend engineering experience in Go, Java, or a similar systems language.
Experience designing or operating identity systems — SSO/IdP, authn/authz, entitlements, or workload identity.
Working knowledge of OIDC, SAML, and SCIM, and judgment about when to use each.
Comfort with cryptographic identity primitives — PKI, mTLS, or hardware-backed keys.
High ownership, clear communication, and comfort making durable technical decisions in ambiguous, fast-moving environments, including scope that's still being defined.
The Identity Provider and Authorization team decides who — and what — can access Base's systems. We build and operate the workforce identity provider, federate access to cloud and internal infrastructure, define entitlements as code, and issue workload identity from a single governed PKI.
Our scope spans internal and partner access today, with customer-facing (CIAM) and fine-grained ABAC still being scoped, plus the service-to-service and headless identity that keeps Base's growing fleet of software and devices secure. Application teams own their own authorization business logic — we supply the identity, groups, and tokens they build on.
This is a rare opportunity to build the identity layer for one of the fastest-scaling energy companies in the country, from close to zero.
First Principles Thinking: Question assumptions. Principles > rules.
Standard company text repeated across Base Power Company's postings is omitted here.
Explore more