
Senior Software Engineer, Cloud Identity
Skills
About the role
SUMMARY
Temporal is hiring a Senior Software Engineer for Identity to help design, build, and operate the identity and access systems behind Temporal Cloud — a multi-tenant SaaS platform. You'll work on the systems that authenticate users and workloads, authorize access to namespaces and APIs, and integrate with customer identity providers. You'll partner with Security, Product, and infrastructure teams to deliver "secure by default" capabilities while keeping the developer and operator experience strong.
WHAT YOU'LL DO
- Build and improve core parts of Temporal Cloud's identity platform — authentication (OAuth 2.0/OIDC, SAML), authorization (RBAC and policy-based access), and workload identity — so customers and workloads can authenticate securely
- Help keep the auth path fast and reliable to meet Temporal Cloud's SLOs through caching, token handling, and revocation strategies
- Integrate with enterprise identity providers (Okta, Entra ID, Google Workspace) and support user provisioning (SCIM), with attention to common identity threats such as token replay and privilege escalation
- Partner with Security, Product, and platform teams to ship secure-by-default patterns and contribute to IAM lifecycle and audit practices
- Write clear architecture and design docs, and contribute to the team's technical direction
WHAT YOU'LL BRING
- Solid hands-on experience building and operating production identity or auth systems — OAuth 2.0/OIDC, SAML, JWT, and token/key rotation
- Good understanding of authorization models (RBAC, ABAC); familiarity with policy engines like OPA, Cedar, or OpenFGA is a plus
- Experience operating distributed systems in production, including some on-call responsibility
- Proficiency in Go; experience with Python, Java, or Rust is a plus
- Strong communication skills and the ability to collaborate across security, product, and engineering teams
NICE TO HAVE
- Exposure to workload identity or short-lived / federated credentials (SPIFFE/SPIRE, mTLS, WIF)
- Experience with SCIM provisioning and enterprise SSO integrations
- Contributions to identity OSS projects (Keycloak, Ory, Dex, OpenFGA, SPIRE)
- Familiarity with compliance frameworks (SOC 2, ISO 27001, HIPAA) as they apply to IAM
- Familiarity with Temporal or other durable-execution engines, especially auth implications around workers and task queues
- Experience designing customer-facing API auth (scoped tokens, API keys, rotation)
COMPENSATION
- Base Salary Range - $212,000 to $237,000, depending on qualifications and location
- Equity Options - Eligible for stock options as part of Temporal's equity plan
Compensation
This Software Engineer role pays $212k-$237k/yr. Within typical range for software engineer roles in United States.
Questions about this role
How do I apply to this Senior Software Engineer, Cloud Identity role at Temporal?
Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.
What's the typical salary for Software Engineer in United States?
Compensation for Software Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Software Engineer hub for United States medians across recent openings.
How fast does AI Applyd auto-apply?
Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.
What ATS does Temporal use?
AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.