Staff Software Engineer, Cloud Identity

Temporal

USonsite$212k-$286k/yrPosted May 28, 2026

Skills

kotlinpythonjavago

About the role

Summary

Temporal is hiring a Staff Software Engineer for Identity to design, build, and operate the identity and access platform behind Temporal Cloud — a multi-tenant SaaS serving high-throughput workloads. You'll own the systems that authenticate humans and workloads, authorize fine-grained access to namespaces and APIs, federate with customer IdPs, and distribute auth material to clients and workers at scale. This role partners closely with Security, Product, and platform teams to deliver "secure by default" capabilities without compromising developer or operator experience.

What You'll Do

- Design and build Temporal Cloud's identity platform end-to-end — authentication (OAuth 2.0/2.1, OIDC, SAML, token exchange), authorization (RBAC/ReBAC/policy engines), and workload identity federation — so customers and workloads authenticate without long-lived secrets

- Scale the auth hot path to meet Temporal Cloud's SLOs: in-memory auth bundles, JWKS caching, decision caching, and revocation strategies that keep latency low and eliminate single points of failure

- Integrate with enterprise IdPs (Okta, Entra ID, Google Workspace, SAML/OIDC), own SCIM 2.0 provisioning, and threat-model identity flows against token replay, confused deputy, scope escalation, and mix-up attacks

- Partner with Security, Product, and platform teams to ship secure-by-default patterns, define IAM lifecycle and audit strategies, and shape the technical roadmap by tracking emerging standards (IETF OAuth WG, OpenID Foundation)

- Mentor engineers, maintain clear architecture docs, and engage directly with customers to understand requirements and unblock adoption

What You'll Bring

- Deep hands-on experience building and operating production identity systems — OAuth 2.0/2.1, OIDC, SAML, JWT/JOSE, JWKS rotation, SCIM, and at least some exposure to workload identity (SPIFFE/SPIRE, WIF, mTLS, or short-lived federated credentials)

- Strong grasp of authorization at scale (RBAC, ABAC, ReBAC/Zanzibar) and familiarity with policy engines like OPA, Cedar, or OpenFGA

- Track record operating latency-sensitive distributed systems in production, including on-call ownership and operational excellence

- Proficiency in Go; experience with Python, Java, or Kotlin is a plus

- Strong communication skills with the ability to align stakeholders across security, product, and engineering and drive execution end-to-end

Nice to Have

- Contributions to identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE) or standards bodies (IETF OAuth WG, OpenID Foundation)

- Experience with compliance frameworks (FedRAMP, SOC 2, ISO 27001, HIPAA) as they apply to IAM

- Familiarity with Temporal or other durable-execution engines, especially auth implications around workers and task queues

- Experience designing customer-facing API auth (scoped tokens, API keys, rotation UX) and building well-structured APIs

Compensation

- Base Salary Range - $212,000 to $286,000, depending on qualifications and location

- Equity Options - Eligible for stock options as part of Temporal's equity plan

Compensation

This Software Engineer role pays $212k-$286k/yr. Within typical range for software engineer roles in United States.

Questions about this role

  • How do I apply to this Staff Software Engineer, Cloud Identity role at Temporal?

    Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

  • What's the typical salary for Software Engineer in United States?

    Compensation for Software Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Software Engineer hub for United States medians across recent openings.

  • How fast does AI Applyd auto-apply?

    Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

  • What ATS does Temporal use?

    AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.