10 Aug
|
GreyOrange
|
Bengaluru
10 Aug
GreyOrange
Bengaluru
This is a build role, not a security-review role. You will write production code, design backend services, and integrate with access-control systems across GCP, Kubernetes, and Kafka. The security background is required because the product you are building is security-critical - mistakes are access breaches or audit failures.
Strong bias toward shipping working software over designing perfect systems. Your primary focus for the first six months is the Just-In-Time (JIT) Access Portal: an internal product that becomes the single entry point for elevated access across every system in the platform. After establishing that, you rotate into other engineering areas - contributing to the compliance evidence layer, CI/CD security hardening - expanding your footprint across the broader platform.
What You Will Do First Six Months - JIT Portal Build
- Own the JIT portal from design through production. Inherit and extend the foundation already established by the existing Staff Engineer.
- Extend portal coverage to Kafka ACLs via the Kafka admin client; SQL grants via GCP CloudSQL IAM; internal admin UI surfaces.
- Design and ship the TTL-enforcement mechanism across all backend systems — the hardest engineering problem in this area, because different access-control systems have different revocation semantics.
- Build the audit log pipeline: access events → Kafka → InfluxDB → Grafana. SOC2 access-control evidence view available to the GRC team on demand.
- Integrate with the incident tool: emergency break-glass access automatically granted at incident-open and revoked at incident-close.
Next Six Months - Expanding Scope
- Own the compliance evidence layer: map incidents to SOC2/ISO controls; auto-collect evidence artifacts at incident-close (ticket, post-mortem document, access logs, deployment manifest); generate audit dossiers on demand.
- Connect the compliance layer to the access-portal audit log and the configuration-management audit log — one continuous evidence trail covering access, configuration change, and incident response.
- Contribute to CI/CD security hardening: container image signing (Cosign), SBOM generation and storage, External Secrets Operator rollout, tfsec/Checkov in Terraform pipelines, CVE gating in the build pipeline.
Ongoing
- Contribute to cross-team architecture reviews with a security and identity lens - flag credential handling issues, ACL gaps, and audit-log omissions.
- Maintain the JIT portal as a production system - it is part of the platform team's on-call rotation.
- Write and maintain design documents and runbooks for everything you build.
Requirements What We Are Looking For
- 8+ years of backend software engineering with a strong identity and access-management focus
- Has built or substantially contributed to an identity or access platform - not just used IAM tools, but written the code behind access grants, revocations, and audit pipelines
- Production experience with at least three of: GCP IAM, Kubernetes RBAC, Kafka ACLs, OAuth2/OIDC, SAML 2.0, Google Workspace admin APIs
- Understanding of SOC2 control requirements from an engineer's perspective - specifically the access-control and change-management control families
- Robust backend engineering in Java or Go - the portal backend is Java/Spring Boot to match the broader platform stack
- Comfortable being the primary security engineering expertise in a team without a dedicated security function above you
Nice to Have
- Experience with zero-trust access architectures or enterprise Privileged Access Management products - understanding their failure modes helps in building our own
- Background with Cosign, Sigstore, or container image signing infrastructure
- Familiarity with Erlang or willingness to integrate at an application-gateway layer - Mnesia does not have native ACLs, so enforcement happens at the gateway
- Experience evaluating commercial JIT tools before deciding to build - familiarity with what Teleport, StrongDM, Britive, or CyberArk do well and where they fall short
- Has worked in a compliance-adjacent engineering environment where audit evidence is a first-class deliverable
📌 Staff Software Engineer (Bengaluru)
🏢 GreyOrange
📍 Bengaluru