Job SummaryThe TeamChronosphere, a Palo Alto Networks company, is the observability platform built for control in the modern, containerized world. Chronosphere empowers customers to focus on the data and insights that matter by reducing complexity, optimizing costs, and remediating issues faster. Chronosphere reduces data volumes and associated costs by 84% on average while saving developers thousands of hours. Recognized as a leader by major analyst firms, Chronosphere is trusted by the world's most innovative brands, including DoorDash, Affirm, and Zillow.
Job SummaryThe Identity & Access Management team owns our authentication and access control platform: the APIs, libraries, services, and data stores other engineering teams integrate with to control who can do what in their part of the product. Other teams write the access rules for their own features. This team builds the system they plug into. We are increasing our investment in this area, and the team is growing rapidly.
These systems sit in front of every dashboard, API, and piece of customer data, so reliability and security posture come first. Much of our roadmap is customer-driven too: access control granularity, SSO and SCIM coverage, and service account scoping come up during procurement and renewal.
We are seeking a senior technical leader for this platform. You will set the architectural direction, lead the most complex and highest stakes work, stay hands-on with the code, and mentor other engineers on the team.
Qualifications Key Responsibilities- Lead and evolve the design of our granular access control framework: a sophisticated, scalable, and reliable system that nearly every other product team integrates with. Set the architectural direction for the platform on a 1-3 year horizon, including APIs for other teams, shippable iterations, build-versus-buy decisions, how we manage technical debt, and how to scale reliably.
- Lead initiatives that span teams. Much of this work lands in code other teams own, so negotiating priorities, resolving dependencies, and influencing peers without authority matter alongside technical skills.
- Ship and maintain platform capabilities in Go, deployed on Kubernetes across cloud platforms such as AWS and GCP. This is a hands-on role, and you will take on the parts of the system that are the most complex and most frequently used.
- Own the reliability of these systems in production. Monitor SLOs and take timely action to meet our reliability goals. Identify security and reliability risks, and build systems to address and mitigate them.
- Eliminate systemic failure modes and toil through architectural, deployment, and tooling improvements to keep this platform safe to change.
- Partner with your product manager to assess customer needs and co-create the roadmap. Your PM owns direction. You ground it in what is buildable. Both of you bring empathy for the admins who live in these systems every day, so you can tell which access control gaps are genuinely blocking customers.
- Balance large investments alongside a steady cadence of customer requests while making sure the team can deliver at a predictable pace.
- Partner with the teams who will build on what you ship. Build relationships and engage them early and often to stay connected to our needs in the organization.
- Work with our security and compliance partners on reviews, audits, and realistic commitments we make to customers.
- Track where identity and access management is heading outside the company, including new security models and the access control questions AI agents raise, and turn that into technical bets we can act on.
- Mentor engineers on this team and elsewhere in the organization. Help us grow the team by interviewing and onboarding new engineers into a challenging domain.
Required Qualifications- A track record of taking an ambitious vision from an idea to production.
- The ability to work through ambiguity collaboratively with customers and partners toward iterative execution.
- Experience owning initiatives that span several teams from inception to delivery, working alongside product managers, designers, and other engineers.
- Experience with large scale distributed systems, and the judgment to weigh reliability, scalability, security, cost, and time-to-market trade-offs.
- Strong product sense. You hold a technical and a product point of view at the same time. You can tell which gaps in a platform capability change what a customer is actually able to do, and you turn customer and contractual requirements into engineering priorities rather than waiting for them to be handed to you. You use data to make the case for architectural investment.
- Experience building platform capabilities that other engineering teams adopt, and driving adoption through collaboration and negotiation.
- Experience partnering and negotiating with infrastructure engineering teams, helping to align priorities, and building toward a shared technical vision.
- The technical depth to lead design reviews, assess risk in a design, understand critical code paths, and evaluate engineering trade-offs directly.
- Familiarity with enterprise software and the expectations security-conscious customers place on access control, authentication, and auditability.
- A background in platform engineering, ideally with exposure to identity, access control, or security-adjacent infrastructure. Deep IAM specialization is a nice-to-have.
- The curiosity and motivation to learn a deep, complex domain, and the habit of seeking feedback on your own designs.
- Fluency in a system level language such as Go, C++, Java, C#, or Rust. Knowing a specific language isn't important. What matters is that you have become fluent in one by spending a lot of time on the kinds of projects where these languages are used.
- The communication skills to frame complex trade-offs for a range of audiences, from engineers on other teams to product managers to leadership.
- A flexible, collaborative working style, and a way of working with other teams that raises the technical bar without routing every decision through you.
Compensation DisclosureThe compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.
- /yr