21 Aug
|
FACTSET
|
Hyderabad
Job Summary
In this role, you will join our Zero-Trust Service Identity team to define and deliver the standard for service-to-service authentication across internal APIs. You will lead the design and rollout of SPIFFE/SPIRE as the organization's identity plane, enabling strong, workload-based identity with mTLS (X.509 SVIDs) and JWT-SVIDs. This role spans architecture, implementation, automation, and operations-establishing HA/SPoF-free deployments, integrating with enterprise PKI/HSM, building verifier libraries for Java/Go/.NET, and enabling rapid adoption through self-service tooling and golden templates.
What You'll Do
- Design and deploy highly available SPIRE across dev/stage/prod, integrated with Security PKI/HSM as the upstream CA.
- Implement end-to-end service authentication: mTLS using X.509 SVIDs and JWT-SVID support with JWKS publishing and trust bundle management.
- Build and maintain verifier libraries/SDKs for Java, Go, and .NET with efficient caching, robust validation, and clock-skew handling; provide samples and integration guides.
- Define and standardize caller identity propagation
- Implement node and workload attestors for Kubernetes and VM environments; ensure secure bootstrap and attestation policies.
- Automate deployments and operations with IaC and CI/CD (e.g., Terraform/CloudFormation, Helm, GitHub Actions/Jenkins), including canary/blue-green strategies and signed artifacts.
- Deliver zero-downtime rotation for certificates, trust bundles, and JWKS; establish certificate/key lifecycle processes and guardrails.
- Plan and execute DR/HA: multi-region topologies, health checks, failover procedures, backup/restore runbooks, and chaos/DR drills.
- Build developer enablement: self-service portal/CLI, golden templates/Helm charts, linters/policy checks, and migration tooling from legacy mTLS/API keys.
- Own operational excellence: patching/upgrade schedules, scaling policies and capacity planning,
on-call runbooks and incident/rollback playbooks.
- Participate in code-reviews and proactively take ownership of PRs and make sure to catch all security vulnerabilities
- Proper collaboration and interaction with multiple teams across FactSet and respond to stakeholder queries in a timely manner
What We're Looking For
- Bachelor's degree, or higher, in Computer Science or a related technical field
- 6+ years of experience building backend/platform/security systems, with a focus on service identity, PKI, or zero-trust architectures.
- Hands-on experience with SPIFFE/SPIRE or equivalent workload identity systems (e.g., Envoy/Istio SDS, solid mTLS at scale).
- Strong grasp of X.509, PKI/CA hierarchies, certificate issuance/renewal, revocation, trust stores, and JWKS/JWT (JWS/JWK).
- Proficiency in at least two of: Go, Java, .NET
- Kubernetes production experience (networking, RBAC, admission/attestors) and Docker/containers proficiency.
- Infrastructure-as-code and CI/CD pipelines
- Strong AWS fundamentals (EKS, EC2, VPC, IAM, KMS/CloudHSM or HSM integrations), Linux debugging, and performance tuning.
- Security-first mindset with practical knowledge of mTLS, least-privilege, secrets management, and auditability.
- Clear communication, systems thinking, and end-to-end ownership from design through operations.
- Address production issues in a timely manner
Nice to have
- Experience with enterprise PKI, HSMs, or CA integrations; cert-manager/Vault.
- Policy enforcement integrations (OPA/Rego, Envoy ext_authz) and identity-aware authorization patterns.
- Multi-region reliability engineering, traffic management, and chaos/DR testing.
- Observability stacks (OpenTelemetry, Prometheus, Grafana, ELK/Loki) and SLO/error budget management.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Senior Software Engineer (Java/Golang) - Identity Management (Hyderabad)
🏢 FACTSET
📍 Hyderabad