Base Career helps you apply smarter for this job.
Key skills for this role
Issuer systems — building signed grant issuance, JWKS publishing, key rotation, and verifier-facing trust primitives
Approval infrastructure — designing device, backchannel, host-mediated, and service-mediated approval flows that preserve both user experience and security guarantees
Runtime and operator controls — building the surfaces for runtime registration, operator trust, default budgets, delegated execution, and admin review
Capability policy — defining least-privilege grants, constraints, bounded-use authorization, principal-on-grant semantics, and revocation behavior
Verification model — shaping offline verification, request signing, replay protection, cache behavior, and the practical tradeoffs between verification and revocation
Control plane and org policy — building tenant-level trust configuration, approval policy, auditability, runtime management, and enterprise admin controls
Adoption bridge — building the platform that lets agents securely access real services before native agent auth support exists, while creating a clean path toward first-class protocol adoption
New primitives in code — implementing issuer, verifier, SDK, and IDP primitives from scratch across the Better Auth plugin, client SDK, and platform surfaces
Experience level — 7+ years building production systems in security-sensitive or protocol-heavy domains
Security-sensitive systems — strong experience building systems where correctness, trust, and misuse resistance matter
Protocol judgment — the ability to reason about hard tensions like offline verification versus revocation, delegation versus misuse resistance, approval UX versus security guarantees, and issuer/runtime/service boundaries
Token and key systems — hands-on experience with signed token formats, key lifecycle, and binding tokens to specific requests in real systems
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
San Francisco, USA
San Francisco, USA
San Francisco, USA
San Francisco, USA
Secure-by-default product judgment — strong instincts for making secure behavior the easy default, and for knowing when ergonomics and security are genuinely in tension versus when thoughtful design can deliver both
Systems implementation — strong TypeScript and backend engineering ability, with comfort building production libraries, APIs, control planes, and developer-facing tooling
Collaboration and ownership — low ego, high conviction, and the ability to work across protocol, product, and engineering details without waiting for perfect specs
Capability-based authorization — experience with delegated access, attenuation models, bounded-use grants, or related authorization systems
Open source infrastructure — experience maintaining OSS libraries or developer-facing infrastructure with real external users
Enterprise identity — familiarity with SSO, SCIM, org policy, auditability, compliance-oriented controls, or multi-tenant trust systems
Standards and interoperability — experience contributing to protocol discussions, writing technical proposals, or working across ecosystem boundaries
Comprehensive authentication and authorization framework for TypeScript.
Visit company websiteJobs and hiring trendsFull-time
Senior · 7+ years experience
Onsite
Apply faster on company sites with our extension.