The Team
The Ads Platform Foundations team builds the core platforms, frameworks, and shared services that accelerate development across the Ads organization. We focus on enabling teams to move faster and build consistently through scalable UI infrastructure, common components, and foundational workflows. Our work also powers access control across domains and underpins core systems such as Public API, GenAI foundations, and the Ads Entity Service — a knowledge graph connecting all Ads entities. Together, we provide the technical backbone that drives consistency, reliability, and velocity across Ads.
Responsibilities
Co-drive the build vs. buy evaluation for centralized authorization - contribute to vendor bake-offs (Oso, Permit.io, Cerbos, OpenFGA, AuthZed, AWS Verified Permissions/Cedar) against an in-house option, weighing latency, flexibility, operational cost, and vendor lock-in.
Help design the policy model: roles vs. permissions vs. relations, org-level vs. resource-level roles, role hierarchies, resource ownership/sharing, multi-tenancy.
Partner on the decision engine architecture: low-latency authorization checks, caching, consistency tradeoffs, audit/versioning of policies.
Work with platform/security/IAM teams to integrate authz checks into services (sync and async enforcement points).
Build reference implementations, SDKs, and middleware so other engineering teams can adopt the centralized model instead of ad hoc checks.
Contribute to testing practices (policy unit tests, authorization test suites) and the migration plan from today's scattered checks to a single policy engine.
Must-have qualifications
5–8+ years backend/software engineering experience shipping production systems.
Hands-on experience working on or building an authorization system - solid RBAC fundamentals, with real understanding of roles, permissions, role hierarchies, and resource-level vs. org-level scoping.
Solid conceptual grounding in authz fundamentals - able to reason through tradeoffs between RBAC, ABAC, and ReBAC (relationship-based / Zanzibar-style) approaches.
Some exposure to evaluating or integrating a policy engine/framework (Oso, OPA/Rego, Cerbos, OpenFGA, AuthZed/SpiceDB, AWS Cedar) - or having worked on an equivalent in-house.
Strong systems design skills: low-latency decision services, caching, consistency vs. performance tradeoffs.
Proficient in one backend stack (Java/Kotlin/Go/Node/Python).
Nice-to-have
Experience with policy-as-code languages (Rego, Cedar, Polar) or Zanzibar-paper-inspired systems.
Has participated in a build-vs-buy or vendor RFP process before.
Familiarity with AuthN (OAuth/OIDC) and how the AuthN/AuthZ boundary is typically drawn.
Experience on large-scale multi-tenant SaaS platforms.
Experience building this external organizations in a b2b (not just internal access controls)
Open-source contributions to authz projects (OpenFGA, Cerbos, Casbin, etc.).
Generally, our compensation structure consists solely of an annual salary; we do not have bonuses. You choose each year how much of your compensation you want in salary versus stock options. To determine your personal top of market compensation, we rely on market indicators and consider your specific job family, background, skills, and experience to determine your compensation in the market range. The range for this role is $388,000.00 - $558,000.00.
Netflix provides comprehensive benefits including Health Plans, Mental Health support, a 401(k) Retirement Plan with employer match, Stock Option Program, Disability Programs, Health Savings and Flexible Spending Accounts, Family-forming benefits, and Life and Serious Injury Benefits. We also offer paid leave of absence programs. Full-time hourly employees accrue 35 days annually for paid time off to be used for vacation, holidays, and sick paid time off. Full-time salaried employees are immediately entitled to flexible time off. See more details about our Benefits here.