Grupo QuintoAndar | Tech Lead Manager (Authorization and Authentication)
About Grupo QuintoAndar
We are Grupo QuintoAndar, the largest real estate ecosystem in Latin America. Guided by a shared purpose of helping people love where they live, we have a diversified portfolio of brands and solutions across different countries in Latin America, covering all phases of the housing journey. We also have a Technology Hub in Portugal. We develop technology and innovation to transform and enhance the overall living experience.
With the support of a world-class team of investors and advisors, including Kaszek, Qualcomm, General Atlantic, and SoftBank, Grupo QuintoAndar is currently valued at over USD 5.1 billion and continues to grow year over year.
Here, you will work with top professionals in the market, in an environment that breathes innovation, collaboration, and high performance. To learn more about our story, visit: https://grupoquintoandar.com/pt/.
Location & Remote Work for technology and remote-first roles
Our technology team operates under a "remote-first" model, which means we work from home and can live anywhere in Brazil. We also offer the option of working from our São Paulo offices or partner coworking spaces, up to twice a week.
Hiring Process Stages
The stages of our hiring processes aim to assess your experiences and allow you to meet our teams and explore career opportunities. They are structured as follows:
- Application
- Interview with Recruiters
- Tech Screening
- Technicals Interviews with Engineering Team
- Offer
About the Team
Join QuintoAndar's core engineering team to focus on building and evolving our Customer Identity and Access Management (CIAM) capabilities. As a Techlead Manager on the Identity Platform team, you will be instrumental in designing, developing, and maintaining the secure, scalable, and user-friendly systems that manage how our customers access our services.
About the Role: As a Tech Lead Manager on the Authorization Platform team, you will lead a talented team of engineers responsible for executing this strategic vision. You will be instrumental in building and operating the secure, scalable, and resilient systems that govern "who can do what" across all of QuintoAndar's services. This is a unique opportunity to solve complex distributed systems challenges and have a foundational impact on the company's security and engineering velocity.
These are the Techlead Manager (Identity Platform) responsibilities at QuintoAndar:
- Grow, coach, and manage a diverse and inclusive team of 2~5 skilled software engineers, supporting their career development and helping them achieve their goals.
- Design, develop, and operate core services, focusing on authentication, authorization, and security.
- Drive the technical strategy and execution for the new centralized authorization architecture, from development through to adoption.
- Ensure the security, reliability, scalability, and performance of the identity platform and its associated microservices.
- Collaborate closely with product managers, security teams, and other engineering teams to define and implement identity requirements and ensure a seamless, secure user experience.
- Improve the development experience at QuintoAndar by enhancing development tools, test coverage (especially for security and authorization flows), and code structure within the authorization platform.
- Actively participate in software design discussions and decisions, specifically for identity-related components, and contribute to clear documentation.
- Contribute to the long-term vision of evolving the platform towards a fully centralized, Zanzibar-inspired authorization model.
Requirements
What we are looking for:
- Strong proficiency in Java and experience with relevant frameworks (e.g., Spring Boot, Spring Security).
- Proven experience leading and managing software engineering teams in a fast-paced environment.
- Deep understanding of Authorization and Access Control concepts and patterns (e.g., RBAC, ReBAC).
- Experience designing, building, and consuming RESTful APIs, particularly in the context of distributed systems.
- Familiarity with JSON Web Tokens (JWT) and their usage in authentication and authorization flows.
- A strong understanding of security principles and best practices related to web applications and authorization.
- People that are seeking to learn, deliver real impact through high-quality, secure, and structured software, valuing work-life balance.
- Excellent English skills (verbal and written) are mandatory for documentation, technical discussions, understanding standards, and potential communication with international partners.
You'll stand out if you:
- Have hands-on experience building or integrating with established identity platforms or providers (e.g.,, ForgeRock, Okta, Ping Identity, Keycloak, Auth0, AWS Cognito, GCP Identity Platform) or deep expertise using libraries like Spring Security for complex identity scenarios.
- Have experience with cloud service platforms and their services, particularly identity-related services.
- Understand modern CI/CD practices and pipelines.
- Have experience with containers and container-orchestration.
- Know how to test (including security testing), performance tune, and ensure the scalability of identity systems.
- Have practical experience with Google's Zanzibar model or similar relationship-based access control systems.
- Practical experience with Open Policy Agent (OPA) and the Rego language is highly desirable.
Important
- Our hiring process starts with the application! If you truly want to be part of our team, please complete this step of the process. We analyze all candidates individually and provide feedback to all applicants.
- All communication will be conducted via email, so please stay tuned for our messages and release the domain @quintoandar.com.br to ensure our emails are not sent to spam.
Benefits
- Competitive salary
- Profit sharing
- Variable compensation (Somente para vagas comerciais)
- Meal allowance
- Health insurance
- Dental plan
- Life insurance
- Childcare subsidy and Atypical Parenthood subsidy
- Wellhub
- Home office allowance
- Employee assistance program (mental health, social, legal, and financial support)
- Extended parental leave
- Day off on birthday, Mother’s Day, and Father’s Day
- Benefits Club (discounts on everyday services)
- Discounts at educational institutions
- Reading kit for children – PlayKids
Diversity & Inclusion at Grupo QuintoAndar
We value diversity and want everyone to feel welcome here, regardless of their age, gender identity, sexual orientation, race, color, ethnicity, origin, disability, religion, or any other characteristic. All our job openings are open to all individuals!
You'll notice there are some diversity questions in the application form. For affirmative action roles, this information may be used to verify your alignment with the target audience for the opportunity. In such cases, it may be used for elimination purposes. For non-affirmative action roles, this data will be used anonymously, exclusively to monitor and improve our inclusion practices in the hiring process, and will have no impact on your application.
Privacy and Data Protection
The Grupo QuintoAndar operates in compliance with privacy and data protection laws, including, but not limited to, the Brazilian General Personal Data Protection Law (LGPD) (Law No. 13,709/2018), and ensures the security of your data. To learn more, please access our Privacy Notice for Candidates. For questions or to exercise your rights as a data subject, please contact us through our Service Channel.
#LI-FS4
Apply for this job
*
indicates a required field