24 Sep
|
RIB Software India
|
Nashik
24 Sep
RIB Software India
Nashik
## About the role
- As Platform Architect / Technical Lead, you own the architecture of RIB Product. You design the authentication, authorization, and tenancy model that every RIB product will build on, and you set the technical standard for the engineers building it. You report to the Head of Software Architecture and work closely with product and security leadership.
- This is a hands-on architecture role. You write architecture documentation, review code, and stay close to implementation. You are not designing in isolation.
## What you will do
- - Design and own the end-to-end architecture of RIB Product, covering authentication, authorization, tenancy, and the integration contracts other product teams use to connect to the platform.
- - Design the relationship-based access model that represents organizational hierarchies (tenant, company, project, and resource) and supports inheritance, regional data separation, and data deletion requests.
- - Define how tokens are issued, validated, and revoked across the platform, including performance targets for validation at scale and fast revocation when access needs to be cut off.
- - Set the boundary between platform-owned authorization and the permission logic that individual product teams own, so product teams can ship their own permission changes independently.
- - Define the APIs, SDKs, and integration patterns that let other product teams onboard to RIB Product with minimal support from your team.
- - Set the technical quality bar for the engineering team: code review standards, design documentation, and architectural consistency.
- - Work directly with the Head of Software Architecture on cross-product architecture alignment,
and with the security and compliance team on meeting data protection and security certification requirements.
- - Support a phased rollout across RIB's cloud products first, followed by hybrid and on-premises products.
## Technical skills we are looking for
- - Robust hands-on experience with OAuth 2.0 and OpenID Connect, including how an authorization server issues, validates, and manages the lifecycle of tokens. This goes beyond consuming an identity provider in application code.
- - Experience designing or operating relationship-based or fine-grained authorization systems (for example OpenFGA, Zanzibar-style models, or comparable engines), rather than simple role-based permission lists.
- - Experience with SCIM-based user provisioning, including account creation, updates, deactivation, and reconciliation between systems.
- - Strong background in multi-tenant SaaS architecture, including tenant isolation, data residency, and cross-tenant security boundaries.
- - Deep, current experience with Azure, including AKS, API Management, Service Bus, Key Vault, and managed identity patterns. This role requires genuine Azure depth, not general cloud experience gained primarily on another provider.
- - Strong .NET platform engineering background, including experience with high-performance, low-latency services.
- - A track record of writing architecture documentation that other engineers actually use,
and of running or contributing to a formal design review process.
## Skills that strengthen your application
- - Experience with an identity server product such as Duende IdentityServer, Keycloak, or Auth0, including migrating from a self-managed identity server to a managed identity platform.
- - Experience with enterprise federation protocols: SAML 2.0 and OpenID Connect federation, single sign-on routing, and just-in-time account provisioning.
- - Experience with event-driven architectures for cache invalidation or real-time revocation across distributed services.
- - Familiarity with data protection regulations such as GDPR, and with compliance frameworks such as SOC 2 or ISO 27001, from an architecture perspective.
- - Experience with secretless service-to-service authentication using managed identities or workload identity federation.
## Who succeeds in this role
- - You can explain a complex authorization model clearly to both engineers and non-technical stakeholders.
- - You make architectural trade-offs explicit and defend them with reasoning, not authority.
- - You mentor engineers directly through code review and design discussion, and you raise the bar for the whole team over time.
- - You work well with product and security counterparts who do not share your technical background, and you adjust your communication accordingly.
- - You are comfortable owning a decision, documenting it, and revisiting it when new information arrives.
- - You have some fluency with AI-assisted development and architecture tools, and you can critically evaluate their output rather than accepting it at face value.
📌 Platform Architect / Technical Lead (Nashik)
🏢 RIB Software India
📍 Nashik