Back to jobs

Senior Software Engineer I - Identity & Access Management

Bengaluru

Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here.  We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world. 

We are seeking a Senior Software Engineer I to join our Customer Trust & Engineering team working on Identity and Access Management. IAM is the bedrock of trust at DigitalOcean; our services sit in the critical path of every request, authorizing billions of transactions per second with single-digit millisecond latency.

In this role, you will own significant technical workstreams within our Identity platform; not just implementing features, but shaping how they are designed, tested, and operated. You will go deep on identity protocols, distributed systems challenges, and security engineering, and you will actively raise the technical quality of the team around you. If you are a strong engineer who wants to combine technical depth with growing cross-team influence, this is the team for you.

What You’ll Do

  • Own Technical Workstreams: Design and develop high-availability, low-latency authentication and authorization services in Go, taking end-to-end ownership from design through production operation.
  • Drive Identity Protocol Work: Lead the implementation of OIDC and SAML integrations, enabling seamless federated Single Sign-On (SSO) for enterprise customers and strategic global partners owning the design decisions, not just the implementation.
  • Advance AuthZ Capabilities: Extend our Policy Engine (Rego/OPA) to support advanced resource-level permissions, dynamic scoping, and network-aware access conditions translating product requirements into robust, scalable policy logic.
  • Build for AI Workloads: Contribute to IAM foundations for emerging AI/ML platforms, designing secure token exchange patterns and identity context propagation for agentic workflows.
  • Evolve Identity Models: Design and scale multi-tenant data models to manage complex hierarchical structures (users, teams, organizations, and resource boundaries) that map cleanly to enterprise customer needs.
  • Operational Ownership: Drive service reliability improvements from Kubernetes tuning to data pipeline modernization and participate actively in on-call, treating operational excellence as a first-class engineering concern.
  • Security First: Proactively identify and remediate complex security vulnerabilities, ensuring auth flows are resilient against credential stuffing, session hijacking, and configuration theft.
  • Mentor & Elevate: Mentor junior engineers through code reviews and design feedback, sharing knowledge in distributed systems and identity best practices without needing to formally lead workstreams.

What You’ll Add to DigitalOcean

  • Experience: 4–7 years of software engineering experience, with at least 1–2 years focused on Identity (AuthN/AuthZ), Security Products, or high-scale Distributed Systems.
  • Language Proficiency: Strong proficiency in Go and solid understanding of gRPC microservices architecture.
  • Identity Knowledge: Working knowledge of identity protocols (OIDC, OAuth2, SAML) and access control models (RBAC, ABAC, PBAC); able to reason about trade-offs across models.
  • Distributed Systems Depth: Solid understanding of consensus, replication, and partitioning — able to design systems that behave correctly under failure conditions.
  • Cloud Native: Hands-on experience with Kubernetes, SQL (MySQL), and Infrastructure as Code (Terraform).
  • Problem Solver: A track record of decomposing complex systems into clean, maintainable abstractions.
  • Communication: Able to collaborate effectively across teams (Inference, Billing, DOKS) and clearly communicate technical decisions to peers and senior engineers.

Nice to Have

  • Experience with Open Policy Agent (OPA) and Rego.
  • Familiarity with Cloud-native deployment strategies (Canary/Blue-Green) via Kubernetes.
  • Prior exposure to enterprise IAM integrations (SCIM, LDAP, directory services).

*This job is located in Bengaluru, India

JR: 2026-7770

#LI-Hybrid

Why You’ll Like Working for DigitalOcean

  • We innovate with purpose. You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
  • We prioritize career development. At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
  • We care about your well-being. Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
  • We reward our employees. The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
  • DigitalOcean is an equal-opportunity employer. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
GDPR Notification: Please read the applicable GDPR Notification at the bottom of this page and confirm your acknowledgement and agreement here. *
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in DigitalOcean’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...