Own custom Keycloak development for enterprise identity platforms not just configuring Keycloak, but extending it.
- Build custom authenticators, identity providers, and other SPI implementations
- Tune Infinispan caching and session behavior for high availability
- Run the platform in Kubernetes via the Keycloak Operator
- Integrate Keycloak with downstream applications over OIDC and SAML 2.0
- Implement user lifecycle with SCIM 2.0
- Configure identity brokering and federation with external IdPs
- Build modern authentication flows including passkeys / WebAuthn
- Own the operational health of the platform end-to-end
This is a hands-on engineering role for someone who has already shipped real Keycloak extensions and debugged session replication in production. Mid-level candidates with strong Keycloak plugin experience and senior candidates who can own platform architecture are both encouraged to apply.
Preferred candidate profile
Must-have:
- Robust Java development experience Keycloak runs on Quarkus, so comfort in that ecosystem is expected
- Demonstrable Keycloak plugin/extension development you've built and deployed custom SPI implementations (authenticators, providers, required actions, event listeners, REST endpoints, user-federation)
- Working knowledge of Infinispan — cache configuration, clustering, embedded vs. remote cache modes, persistent sessions, and how Keycloak relies on it for session/state replication
- Solid grasp of identity and access protocols — OIDC / OAuth 2.0, SAML 2.0, and SCIM 2.0
- Experience running containerized services in Kubernetes (Helm, operators, or equivalent)
- Comfort with Git-based workflows and CI/CD pipelines, managing realm and client configuration as code
- Ability to communicate technical tradeoffs clearly to both engineers and non-engineers
Good to have:
- Keycloak Operator and GitOps tooling (ArgoCD, Flux)
- Passkeys / WebAuthn and step-up / fallback factor implementation
- Identity brokeri