About the RoleRender's mission is to eliminate the undifferentiated work that goes into building software products by offering an easy-to-use, powerful cloud platform for developer teams of all sizes.
We're looking for a software engineer with a strong identity and security focus to join our Expansion team. You'll help build the authentication, authorization, and access-management primitives that Render's customers depend on including SSO, RBAC, audit logging, scoped credentials and SCIM provisioning.
This is not a security operations or compliance role. You'll own changes across Render's platform and think carefully about how to make security features feel built in, not bolted on.
What You'll Do- Design and ship authentication and authorization systems for users, agents, and services including credential scoping, SSO, SCIM provisioning and fine-grained permission models.
- Evolve Render's authorization model toward clear permissions and scopes for applications, environments, projects, and other platform resources.
- Own the security experience across the stack, from the interfaces used to manage features through to the APIs, data models and systems behind them.
- Build the controls and audit trails customers use to define, enforce and understand how people, services and agents act within their systems.
- Design shared auth APIs and primitives, then work closely with Product, Design, Security, and other Render teams to drive adoption adoption.
- Operate authentication and authorization systems that customers and other teams depend on, including observability, safe rollouts, incident response, and on-call.
What We're Looking For- 6+ years of experience shipping and operating production systems.
- You've built customer-facing authentication or authorization features and understand how security choices shape the product experience.
- You've designed and operated systems where correctness, availability, and safe rollout matter. You are comfortable working through API, data-model, caching, and migration tradeoffs.
- You can balance security and product tradeoffs. You understand why a control exists, the friction it creates and when a simpler design is enough.
- A track record of taking ambiguous projects from design through production while working with product, design, and engineers in other parts of the company.
We care more about the systems you've built and the decisions you made than whether your last role had a "security" title.
Nice-to-haves:- Hands-on experience with OAuth, OpenID Connect, SAML, SCIM, JWTs or other authentication methods.
- Experience with multi-tenant authorization models such as RBAC, ABAC, or ReBAC, including policy engines or fine-grained authorization systems.
- Experience with workload identity, short-lived credentials, secrets management, privileged access, or security controls for services and agents.
- Experience building developer platforms, cloud infrastructure, identity product or SaaS products where APIs and backwards compatibility matter.
- Familiarity with compliance frameworks such as SOC 2 or ISO 27001 and an ability to turn those requirements into security improvements for all customers.
- Contributions to open-source auth/security tooling.
If this role excites you but you don't meet every single requirement, we'd still love to hear from you-your unique experience might be just what we need.
Benefits- 4 weeks of paid vacation.
- 14 weeks of fully paid parental leave for all parents to bond with a newly born, adopted, or fostered child. We will also work with you to create a supportive plan of return.
- Long-term disability, life insurance, and 401K plans.
- 100% employer-paid medical coverage and 99% employer-paid dental and vision coverage for you and a dependent. FSAs and HSAs are available as well.
- Monthly lifestyle stipend for wellness, mental health and therapy, hobbies, etc.
- Monthly cell phone and internet subsidy.
- Commuter benefits for Renders in the Bay Area, and home office stipends for remote Renders.
- Continuous learning benefits & related support.
This position is generally not eligible for new visasponsorship. At Render's discretion, the business may sponsor existing visa transfers. Applicants who require sponsorship must receive business authorization.