Staff Identity Engineer

Runlayer

$120K — $150K *
Nye, MT 59061In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of software engineering experience focused on identity and authentication systems
  • Expertise in OAuth 2.0/OIDC, including dynamic client registration and token management
  • Experience building or integrating with enterprise identity systems like Okta and AWS IAM
  • Strong understanding of distributed systems and API security
  • Proficiency in Python and TypeScript, with a familiarity in FastAPI and React
  • Comfortable engaging with enterprise customers to address security needs
  • Active user of AI tools to enhance productivity

Responsibilities

  • Architect and implement robust authentication and authorization systems for MCP servers
  • Develop and enhance the OAuth broker for enterprise identity integrations
  • Design identity propagation processes for AI agents to ensure secure access
  • Integrate with identity providers such as Okta and Azure AD
  • Define access control policies for MCP tools and resources
  • Collaborate with customers to address identity challenges
  • Contribute to defining the MCP Auth specification

Benefits

  • Competitive salary and equity options
  • Generous paid time off including vacation and parental leave
  • Budget for professional development in AI and enterprise software
  • High-quality equipment for optimal work setup
  • Comprehensive health, dental, and vision insurance coverage
  • Direct engagement with innovative companies to see the impact of your contributions
Full Job Description
MCP is how AI connects to tools and data - the standard created by Anthropic and adopted by OpenAI, Google, Microsoft. We know because we helped establish it.

Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We're now building what enterprises need to adopt MCP safely.

Runlayer is the control plane for enterprise MCP - security, observability, and management that lets organizations connect AI to their systems without the risk. We raised $11M from Khosla Ventures and Felicis, and the creator of MCP is on our cap table.

We're a team of 15, mostly engineers, shipping fast and signing customers. If you want to work at the center of how AI gets things done - this is the moment.

Why You'll Thrive Here
  • Impact: Own the identity and authentication layer that secures every AI-to-enterprise connection on our platform.
  • Excellence: Work alongside engineers who've shipped AI systems at scale.
  • Ownership: Shape how MCP & AI agent authentication works, from spec-level decisions to production code.


What You'll Do
  • Architect and implement authentication and authorization systems for MCP servers (OAuth 2.0, Dynamic Client Registration, token management).
  • Build and extend our OAuth broker that handles enterprise identity integrations across dozens of vendors.
  • Design identity propagation for AI agents, ensuring secure, auditable access to enterprise systems.
  • Integrate with enterprise identity providers (Okta, WorkOS, Azure AD) and SCIM systems.
  • Define fine-grained access control policies for MCP tools and resources.
  • Collaborate directly with customers like Gusto and Rippling to solve real-world identity challenges.
  • Contribute to the MCP Auth spec and help define how agent identity works industry-wide.


What We're Looking For
  • 5+ years of software engineering experience with significant focus on identity, authentication, or authorization systems.
  • Deep experience with OAuth 2.0/OIDC, including DCR, token exchange, and audience restriction.
  • Background building or integrating with enterprise identity systems (Okta, WorkOS, Auth0, AWS IAM, GCP IAM).
  • Strong fundamentals in distributed systems and API security.
  • Experience with Python and TypeScript (our stack is Python/FastAPI backend, TypeScript/React frontend).
  • Comfortable working directly with enterprise customers to understand and solve their security requirements.
  • Heavy AI user who leverages tools like Claude Code or Cursor to multiply output.


Nice to Have
  • Experience with Kubernetes-native authorization patterns or service mesh security.
  • Background in ML security (differential privacy, LLM security research).
  • Prior work on identity for multi-tenant SaaS platforms.
  • Familiarity with the MCP specification.


What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
  • Competitive salary and equity - compensation that reflects your expertise and customer-facing responsibilities.
  • Paid time off - 4 weeks paid vacation, paid sick leave, and paid parental leave.
  • Professional development - budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
  • Top-tier equipment - your choice of laptop and accessories to create your ideal work environment.
  • Health benefits - comprehensive health, dental, and vision coverage.
  • Customer interaction opportunities - work directly with innovative companies and see the immediate impact of your work.


Not quite the right fit? Reach out to [email protected] with details about your experience and interests.

Similar Jobs

More Jobs at Runlayer

  • Solutions Engineer
    $90K — $130K *
    St. Mary Of The Woods, IN 47876 (Vigo County)
    Information Technology
    In-Person
  • Solutions Engineer
    $90K — $130K *
    Nye, MT 59061 (Stillwater County)
    Technical Services
    In-Person
  • Solutions Engineer
    $120K — $150K *
    New York, NY 10025 (New York County)
    Enterprise Technology
    In-Person
  • Head of Field Engineering
    $130K — $180K *
    New York, NY 10025 (New York County)
    Enterprise Technology
    In-Person
  • Head of GTM Operations
    $130K — $180K *
    New York, NY 10025 (New York County)
    Enterprise Technology
    In-Person

More Information Technology Jobs

Find similar Staff Identity Engineer jobs: