Confluent Logo

Confluent

Staff Software Engineer I - Internal Access Management

Reposted 15 Days Ago
Remote
Hiring Remotely in United States
225K-265K Annually
Expert/Leader
Remote
Hiring Remotely in United States
225K-265K Annually
Expert/Leader
Lead the technical vision and architecture for Internal Access Management, ensuring secure, auditable authorization across engineering systems. Mentor others and drive adoption of secure identity patterns in cloud environments.
The summary above was generated by AI

We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.

It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.

One Confluent. One Team. One Data Streaming Platform.

About the Role:

We are seeking a Staff Software Engineer to lead the technical vision, architecture, and execution for Internal Access Management at Confluent. This role is central to our trusted compute environment and requires deep expertise in distributed systems, cloud security, authentication, and policy-driven authorization frameworks.

As the domain owner, you will define how Confluent enforces least privilege, manages workload identity, governs access boundaries, and ensures secure, auditable authorization across all engineering systems. You will partner with Security, Product, and Engineering to establish a cohesive end-to-end access posture.

What You Will Do:
  • Define and drive the long-term architecture and roadmap for Internal Access Management across Kubernetes and multi-cloud environments.

  • Architect and implement least privilege, just-in-time access, and zero-trust models across Confluent services.

  • Build and evolve scalable access-authorization workflows and lifecycle management systems using technologies such as OPA, cloud IAM policies, workload identity, and internal enforcement engines.

  • Strengthen security boundaries through threat modeling, defense-in-depth practices, and comprehensive access-auditing capabilities.

  • Partner with cross-functional teams—including Platform, Kafka, Observability, Developer Productivity, Release Engineering, and SRE—to drive adoption of secure identity and access patterns.

  • Mentor senior engineers, elevate engineering standards, and influence architectural decisions across the organization.

  • Communicate complex technical decisions clearly and align stakeholders across engineering and security.

What You Will Bring:
  • 10+ years of engineering experience, with 4+ years in security, IAM, or distributed systems.

  • Deep expertise in Kubernetes, workload identity, cloud IAM (AWS, GCP, Azure), and zero-trust architectures.

  • Strong understanding of authentication technologies: IAM, OAuth2, OIDC, policy engines, and modern zero-trust principles.

  • Proven track record leading multi-team technical initiatives at a Staff or Senior Staff level.

  • Strong knowledge of distributed systems, cloud infrastructure, container orchestration, and service mesh.

  • Excellent communication and stakeholder-influence skills across engineering and security domains.

What Gives You an Edge:
  • Experience leading cross-org security platform architecture initiatives.

  • Background in building developer-focused authentication and authorization platforms.

Ready to build what's next? Let’s get in motion.

Come As You Are

Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

Privacy Statement

Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here.

Confluent Mountain View, California, USA Office

899 W. Evelyn Ave, Mountain View, CA, United States, 94041

Similar Jobs

31 Minutes Ago
Easy Apply
Remote or Hybrid
7 Locations
Easy Apply
171K-243K Annually
Senior level
171K-243K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead technical pre-sales and strategic advisory for Zero Trust Cloud solutions across hybrid and multi-cloud environments. Drive Proof-of-Value engagements, collaborate with sales, SEs, and product teams, influence product roadmap, and present Zero Trust strategies to technical and executive stakeholders to accelerate regional GTM.
Top Skills: AWSAzureGCPSaseSd-WanSseZero Trust ArchitectureZero Trust ExchangeZscaler Internet Access (Zia)Zscaler Private Access (Zpa)
34 Minutes Ago
Remote or Hybrid
122K-208K Annually
Expert/Leader
122K-208K Annually
Expert/Leader
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Develop and apply stochastic cost models and quantitative analyses to evaluate supplier proposals, estimate construction costs from designs, quantify materials/labor/equipment, analyze subcontractor bid realism, perform close-out cost analysis, and coordinate cost constraints with project managers to support risk-informed decision making.
34 Minutes Ago
Remote or Hybrid
88K-150K Annually
Senior level
88K-150K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Build and maintain Nexthink automations, remote actions, dashboards, and integrations (especially with ServiceNow) to enable proactive, preventative, and self-healing digital employee experience. Engineer data workflows, analyze telemetry, create dashboards and reports, and collaborate with IT support teams to reduce ticket volume and improve endpoint health and experience.
Top Skills: Active DirectoryEndpoint DiagnosticsExcelGroup PolicyItsmNexthinkNqlPower BIPowershellServicenowServicenow CmdbSQLWindows InternalsWmi

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account