At IFS, we’re building the next generation of AI-native enterprise software. We’re looking for a Principal Platform Engineer to build the shared authentication and authorisation capabilities that our product engineering teams depend on.
You should be a hands-on platform engineer who builds through code and automates by default. Your experience might centre on infrastructure as code, deployment pipelines, automation, platform tooling or service integrations. What matters is that you have built reliable, repeatable capabilities that engineering teams use to deliver and operate software.
Your background may be in platform engineering, infrastructure, SRE, identity engineering or systems integration. What matters is substantial hands-on experience building or extending platform capabilities through code and automation, supporting the delivery and operation of software.
A software development background is particularly valuable, but it is not a prerequisite. We welcome engineers whose coding experience has developed through platform engineering, infrastructure or SRE work.
Architecture, administration and product configuration alone are not sufficient. We want to understand what you personally implemented, tested, automated and supported in production.
We’re interested in what you have personally built and automated: how you provisioned it, tested changes, delivered it safely and enabled other teams to use it without depending on manual intervention. Identity and access is the domain you will work in; specialist experience in that domain is particularly welcome.
This is an opportunity to shape a critical platform capability, with substantial technical ownership and impact across our engineering organisation.
We are hiring two Principal Platform Engineers to help unify authentication and authorisation across our next-generation enterprise software platform.
We are consolidating a fragmented authorisation landscape into one model across three hosting environments: our cloud-native platform, our legacy hosting platform and our lifecycle cloud. It must be correct, fast and reliable in distributed, multi-tenant environments.
Our current stack includes SpiceDB backed by PostgreSQL for authorisation, and Curity for authentication, with Keycloak estates migrating onto it. These describe the systems you will work on; prior experience with every product is not required.
You will design and build platform services, APIs and automation, own them in production, and establish patterns that product engineering teams can adopt confidently. A central part of the role is making secure authentication and authorisation available through documented, automated, self-service workflows.
This is a hands-on role. You will write and review infrastructure and automation code, build platform integrations, and contribute to tooling and services, including those written in Go.