Staff Software Engineer (Bengaluru)

Staff Software Engineer (Bengaluru)

10 Aug
|
GreyOrange
|
Bengaluru

10 Aug

GreyOrange

Bengaluru

This is a build role, not a security-review role. You will write production code, design backend services, and integrate with access-control systems across GCP, Kubernetes, and Kafka. The security background is required because the product you are building is security-critical - mistakes are access breaches or audit failures.

Strong bias toward shipping working software over designing perfect systems. Your primary focus for the first six months is the Just-In-Time (JIT) Access Portal: an internal product that becomes the single entry point for elevated access across every system in the platform. After establishing that, you rotate into other engineering areas - contributing to the compliance evidence layer, CI/CD security hardening - expanding your footprint across the broader platform.

What You Will Do First Six Months - JIT Portal Build

- Own the JIT portal from design through production. Inherit and extend the foundation already established by the existing Staff Engineer.
- Extend portal coverage to Kafka ACLs via the Kafka admin client; SQL grants via GCP CloudSQL IAM; internal admin UI surfaces.
- Design and ship the TTL-enforcement mechanism across all backend systems — the hardest engineering problem in this area, because different access-control systems have different revocation semantics.
- Build the audit log pipeline: access events → Kafka → InfluxDB → Grafana. SOC2 access-control evidence view available to the GRC team on demand.
- Integrate with the incident tool: emergency break-glass access automatically granted at incident-open and revoked at incident-close.

Next Six Months - Expanding Scope

- Own the compliance evidence layer: map incidents to SOC2/ISO controls; auto-collect evidence artifacts at incident-close (ticket, post-mortem document, access logs, deployment manifest); generate audit dossiers on demand.
- Connect the compliance layer to the access-portal audit log and the configuration-management audit log — one continuous evidence trail covering access, configuration change, and incident response.




- Contribute to CI/CD security hardening: container image signing (Cosign), SBOM generation and storage, External Secrets Operator rollout, tfsec/Checkov in Terraform pipelines, CVE gating in the build pipeline.

Ongoing

- Contribute to cross-team architecture reviews with a security and identity lens - flag credential handling issues, ACL gaps, and audit-log omissions.
- Maintain the JIT portal as a production system - it is part of the platform team's on-call rotation.
- Write and maintain design documents and runbooks for everything you build.

Requirements What We Are Looking For

- 8+ years of backend software engineering with a strong identity and access-management focus
- Has built or substantially contributed to an identity or access platform - not just used IAM tools, but written the code behind access grants, revocations, and audit pipelines
- Production experience with at least three of: GCP IAM, Kubernetes RBAC, Kafka ACLs, OAuth2/OIDC, SAML 2.0, Google Workspace admin APIs
- Understanding of SOC2 control requirements from an engineer's perspective - specifically the access-control and change-management control families
- Robust backend engineering in Java or Go - the portal backend is Java/Spring Boot to match the broader platform stack
- Comfortable being the primary security engineering expertise in a team without a dedicated security function above you

Nice to Have

- Experience with zero-trust access architectures or enterprise Privileged Access Management products - understanding their failure modes helps in building our own
- Background with Cosign, Sigstore, or container image signing infrastructure
- Familiarity with Erlang or willingness to integrate at an application-gateway layer - Mnesia does not have native ACLs, so enforcement happens at the gateway
- Experience evaluating commercial JIT tools before deciding to build - familiarity with what Teleport, StrongDM, Britive, or CyberArk do well and where they fall short
- Has worked in a compliance-adjacent engineering environment where audit evidence is a first-class deliverable

📌 Staff Software Engineer (Bengaluru)
🏢 GreyOrange
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: staff software engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: staff software engineer (bengaluru) / bengaluru