The RoleWe are looking for a Senior Software Engineer to build and maintain the identity and authorization features of Gravitee Access Management (AM) - across the AM runtime and the access-management experience in Gamma, Gravitee's next generation product surface.
This is a new role. Today, AM engineering is based entirely in Europe. This hire establishes US-hours ownership of Level 3 and Level 4 authentication and authorization incidents, and adds delivery capacity toward AM parity in Gamma - part of building sustainable L3/L4 engineering capability in the US.
You will split your time roughly 80% feature delivery and 20% L3/L4 support and bug fixing (it varies week to week), working as an embedded member of the AM team, which is based in Europe.
What You Will Be DoingIn this role, you will:- Design and deliver features end to end, from discovery and technical design through implementation, testing, release, and iteration.
- Build and maintain identity and authorization features of Gravitee Access Management, across the AM runtime and the AM experience in Gamma.
- Implement and support OAuth 2.0 and OIDC flows (authorization code + PKCE, client credentials, token exchange), SAML 2.0 as both IdP and SP, SCIM, and FAPI/CIBA/UMA profiles.
- Work with token and session semantics - JWT, JWKS, key rotation, revocation, introspection, MFA and step-up, WebAuthn/FIDO2, and IdP federation and social login.
- Keep security behavior and upgrades safe: standards compliance, secure defaults, certificate and secret handling, consent, audit logs, and defenses against token replay, SSRF, and account takeover.
- Own safe migrations and backward compatibility across MongoDB and JDBC, and support multi-domain, multi-region deployments and login/token endpoint performance.
- Own US-hours Level 3 and Level 4 escalations for AM customers as part of the L3 pager duty rotation.
- Use LLMs and AI-assisted development tools thoughtfully for prototyping, implementation, testing, debugging, and exploration, applying sound engineering judgment to validate AI-generated work.
- Write meaningful automated tests and contribute to reliable delivery practices. • Collaborate with product managers, designers, engineers, and technical leaders - including the AM team based in Europe - to discover effective solutions and improve them through code and design reviews.
- Share what you learn and help the team make practical choices as identity standards and protocols evolve.
Essential SkillsWe are looking for evidence that you can succeed in the role, whether gained through employment, open-source work, or equivalent practical experience:
- 5+ years building and running production backend software, on a team that ships and supports its own product; you have personally resolved production incidents.
- Strong Java experience (C# accepted if the object-oriented depth is there), with Maven and a reactive stack such as Vert.x/RxJava.
- Deep working knowledge of identity standards: OAuth 2.0 and OIDC flows (authorization code + PKCE, client credentials, token exchange), SAML 2.0, SCIM, and FAPI/CIBA/UMA profiles. • Solid grasp of token and session semantics: JWT, JWKS, rotation, revocation, introspection, MFA/step-up, WebAuthn/FIDO2, and IdP federation.
- A security-first mindset: secure defaults, certificate and secret handling, audit logging, and awareness of token replay, SSRF, and account-takeover risks.
- Experience with safe migrations and backward compatibility across persistent data stores such as MongoDB or JDBCbacked relational databases.
- Git-based workflow, code review, and writing your own automated tests.
- Hands-on experience using LLMs or AI coding assistants as part of an engineering workflow, combined with the judgment to review and improve their output.
- Clear communication, collaborative problem-solving, and the ability to take an ambiguous problem through to production.
Desired SkillsYou do not need to match every item. We would be especially interested in experience with:
• Experience at an API gateway, proxy, or service-mesh vendor, or on the API platform team of a large company (e.g., Kong, Google Apigee, MuleSoft, Tyk, Solo.io, Traefik, WSO2).
- Kubernetes operators and CRDs; OpenAPI tooling; service mesh or Envoy experience.
- Docker, Kubernetes, and cloud-native application delivery.
- Model Context Protocol (MCP), Agent2Agent (A2A), tool calling, LLM proxies, or other emerging AI protocols and standards. Prior production experience is not required.
- Building or operating LLM-powered applications, RAG systems, or agentic workflows - especially their security, governance, and observability needs.
- Open-source software or enterprise developer platforms.Who Thrives at Gravitee
Our growth is powered by people who bring passion to what they build, professionalism to how they work, and a commitment to doing things well.
You will thrive here if you:• Bring energy and a constructive attitude to the team.
• Adapt quickly and enjoy learning unfamiliar technologies and domains.
• Take ownership, communicate clearly, and follow through with urgency.
• Balance delivery speed with thoughtful engineering judgment.
• Start with the customer problem and care about the quality of the experience you create.
• Enjoy working in a fast-moving, collaborative, international environment.
Life at GraviteeAt Gravitee, we invest in humans, not just roles.
You'll get:
• Salary of $160,000
• Competitive medical coverage.
• Pension / 401(k) program options.
• Stock options - you build it, you own it.
• 25 days of holiday plus in-country national holidays.
• Three mental health days and a wellness allowance.
• Your birthday off. 🎉
• A professional development budget to support your growth.
• A hybrid work culture with hubs across regions.
• Quarterly team events and an annual company offsite.
• A collaborative, international company culture.
• Opportunities to grow your scope and career as Gravitee grows.