Staff Software Engineer, Identity & Access Management
- Role
- Backend
- Experience
- Staff
- Company size
- Enterprise
Open to CA only. Set where you work from to check your eligibility.
No BS summary
Staff backend/platform engineer based in Canada for identity and access management at scale. Needs Java/Spring Boot, cloud/Kubernetes, APIs, and deep authentication/authorization/user-management experience. Security, SOC2/GDPR, and cross-timezone collaboration with Helsinki are central.
Core skills
Required skills
Optional skills
About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Team: The User Management team owns the full identity lifecycle at AlphaSense — from creating and provisioning users, through managing their identities, to authenticating who they are and authorizing what they can do in the system. Our work spans three core domains: User Management — creating, provisioning, and managing user identities Authentication — verifying who users are Authorization — determining what users can do in the system We are a product platform team, not a product team: we build the identity and access infrastructure that other engineering teams build on top of, rather than shipping user-facing features ourselves. We also act as a security guardrail for AlphaSense, since identity and access sit at the center of how the platform stays secure. The team is well-established and senior, based in Helsinki, Finland. We're now expanding into Canada to build follow-the-sun coverage, so our customers get proper support around the clock, and to push deliberately toward a true platform model — scaling our authentication and authorization systems so they can be safely self-served by teams across the company. About the Role: This is a Staff Engineer role on the team that manages identity and access for AlphaSense's entire, and constantly growing, customer base, and that nearly every product engineering team depends on for user and entitlement data. You'll work across all three pillars of identity: creating and managing users, authenticating them, and authorizing what they can do — designing systems built to scale with a constantly growing number of users. Security is core to this role, not adjacent to it — you'll work closely with our security teams to make sure what we build is secure by design, in an environment governed by SOC2 and GDPR. We're looking for a genuinely senior, self-sufficient engineer with strong experience building and operating identity, authentication, or authorization platforms at scale, ideally in a platform/product-platform engineering context. This is someone who doesn't just execute a roadmap, but helps understand the needs behind it, shapes it, and then drives execution — largely autonomously, and in close collaboration with our core team based in Helsinki. You're genuinely interested in security, comfortable partnering closely with security teams on secure-by-design systems, and comfortable working in a distributed, cross-timezone setup — based in Canada, collaborating closely with a Helsinki-based team. Who You Are: Backend: Java 2X, Spring Boot 3.X.X, WebFlux, Maven Data & APIs: SQL, GraphQL, gRPC, REST Cloud & Infrastructure: AWS, GCP, Kubernetes, Helm Identity & Security Protocols: RBAC/ABAC/ReBAC; OAuth 2.0, OIDC, and JWT; SAML 2.0 and enterprise SSO federation (assertion validation, signature/encryption handling, IdP- vs. SP-initiated flows); SCIM for user provisioning and deprovisioning Engineering Practices: Event-driven architecture patterns; TDD or a genuine passion for automated testing [Nice to Have] Auth0 experience SpiceDB / Zanzibar-style authorization system experience Apollo Federation OpenTelemetry Experience operating within SOC2 and/or GDPR-compliant environments What You’ll Do: This role spans all three pillars of our identity platform in equal measure — this is not an authorization-only or authentication-only role. Design, build, and evolve our authorization platform (RBAC/ABAC/ReBAC), enabling teams across the company to answer "what can this user do?" Design, build, and evolve our authentication platform , covering authentication patterns across our range of use cases, working closely with our Auth0 integration Design, build, and evolve our user management platform — creating, provisioning, and managing user identities and entitlements — supporting our entire customer base Partner closely with security teams to ensure our authentication, authorization, and user management platforms are secure by design and aligned with SOC2 and GDPR requirements Design and implement highly scalable systems that keep pace with a constantly growing number of users and customers Help define the long-term roadmap across all three domains — authentication, authorization, and user management — not just execute against one handed to you Build self-service systems and APIs (GraphQL, gRPC, REST) that make authentication, authorization, and user data consumable by product engineering teams across the company Drive projects autonomously from Canada while staying closely aligned with our Helsinki-based team Champion strong testing, observability, and reliability practices across the platform For base compensation, we set standard ranges for all roles based on function and level benchmarked against similar stage growth companies and internal comparables. In order to be compliant with local legislation, as well as to provide greater transparency to candidates, we share salary ranges on all job postings regardless of desired hiring location. Final offer amounts are determined by multiple factors including candidate experience/expertise and may vary from the amounts listed below. You may also be offered equity, and a generous benefits program. Compensation Range $164,450 — $226,550 CAD AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination. In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works. Recruiting Scams and Fraud We at AlphaSense have been made aware of fraudulent job postings and individuals impersonating AlphaSense recruiters. These scams may involve fake job offers, requests for sensitive personal information, or demands for payment. Please note: AlphaSense never asks candidates to pay for job applications, equipment, or training. All official communications will come from an @ alpha-sense.com email address. If you’re unsure about a job posting or recruiter, verify it on our Careers page . If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense please contact us. Your security and trust matter to us.
What you'll do
- Work across user management, authentication, and authorization for AlphaSense's identity platform
- Design, build, and evolve the authorization platform using RBAC, ABAC, and ReBAC
- Enable teams across the company to determine what users can do
- Design, build, and evolve the authentication platform across multiple use cases
- Work closely with the Auth0 integration
- Design, build, and evolve the user management platform for creating, provisioning, and managing user identities and entitlements
- Support the entire customer base through identity and entitlement systems
- Partner closely with security teams to ensure authentication, authorization, and user management platforms are secure by design
- Align identity platforms with SOC2 and GDPR requirements
- Design and implement highly scalable systems for a growing number of users and customers
- Help define the long-term roadmap across authentication, authorization, and user management
- Build self-service systems and APIs that make authentication, authorization, and user data consumable by product engineering teams
- Drive projects autonomously from Canada while staying aligned with the Helsinki-based team
- Champion strong testing, observability, and reliability practices across the platform
What they require
- Genuinely senior, self-sufficient engineer
- Strong experience building and operating identity, authentication, or authorization platforms at scale
- Ideally experienced in a platform or product-platform engineering context
- Able to understand needs behind a roadmap, shape it, and drive execution largely autonomously
- Genuinely interested in security
- Comfortable partnering closely with security teams on secure-by-design systems
- Comfortable working in a distributed, cross-timezone setup
- Based in Canada
- Able to collaborate closely with a Helsinki-based team
- Experience with Java 2X, Spring Boot 3.X.X, WebFlux, and Maven
- Experience with SQL, GraphQL, gRPC, and REST
- Experience with AWS, GCP, Kubernetes, and Helm
- Experience with RBAC, ABAC, and ReBAC
- Experience with OAuth 2.0, OIDC, JWT, SAML 2.0, enterprise SSO federation, and SCIM
- Experience with event-driven architecture patterns
- Experience with TDD or genuine passion for automated testing
- Preferred: Experience operating within SOC2 and/or GDPR-compliant environments
Benefits
- May be offered equity
- Generous benefits program
- Remote work in Canada
AlphaSense delivers AI-driven market intelligence and search built on public and private content including equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.