About this job
<p><strong>Are you ready to unlock intelligence?</strong></p>
<p>If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others.</p>
</p>
<p><strong>About the Role:</strong><br />Kong is building the future of API management for developers. We’re a fast-growing, well-funded company with happy customers and motivated employees. Insomnia, acquired in 2019, is a full-lifecycle API development platform that has quickly become an integral part of Kong’s product portfolio.<br />As a Staff Software Engineer on the Konnect team at Kong, you’ll architect Kong Identity's multi-tenant identity platform supporting complex organizational hierarchies, cross-tenant isolation, and enterprise-grade security controls.</p>
</p>
<p><strong>What You'll Do:</strong></p>
<ul>
<li>
<p>Design and implement advanced token management systems, including refresh token rotation, proof-of-possession tokens, and custom token introspection with real-time revocation capabilities.</p>
</li>
<li>
<p>Lead development of Kong Identity's extensible claims engine supporting dynamic attribute resolution, contextual claim injection, and complex business logic evaluation at token issuance.</p>
</li>
<li>
<p>Architect global identity infrastructure with edge optimization, intelligent token caching, and cross-region replication strategies for sub-millisecond authentication latency worldwide.</p>
</li>
<li>
<p>Design sophisticated rate limiting, anomaly detection, and fraud prevention systems to protect against credential stuffing, token abuse, and distributed attacks.</p>
</li>
<li>
<p>Build enterprise identity federation capabilities, including SAML bridge patterns, external IdP chaining, and custom protocol adapters for legacy system integration.</p>
</li>
<li>
<p>Lead technical strategy for Kong Identity's developer experience, including SDKs, webhooks, audit logging, and real-time analytics dashboards for token lifecycle visibility.</p>
</li>
<li>
<p>Architect advanced client management systems supporting dynamic client registration, automated credential rotation, and programmatic policy enforcement.</p>
</li>
<li>
<p>Design Kong Identity's plugin architecture enables custom grant flows, protocol extensions, and third-party integrations while maintaining security boundaries.</p>
</li>
<li>
<p>Drive implementation of compliance frameworks (SOC 2, FedRAMP, GDPR), including comprehensive audit trails, data residency controls, and privacy-preserving token designs.</p>
</li>
<li>
<p>Lead technical initiatives for Kong Identity's integration with observability platforms, supporting distributed tracing, metrics collection, and security event correlation.</p>
</li>
<li>
<p>Mentor engineering teams on advanced identity concepts including zero-trust architectures, workload identity, and service mesh integration patterns.</p>
</p>
</li>
</ul>
<p><strong>What You'll Bring:</strong></p>
<ul>
<li>
<p>7+ years of experience building production identity platforms at leading identity providers or enterprise software companies, with proven track record of handling millions of authentication requests daily.</p>
</li>
<li>
<p>Deep expertise in advanced OAuth 2.0 extensions (PKCE, mTLS, JWT bearer assertions, token exchange), OpenID Connect profiles, and emerging standards like OAuth 2.1 and GNAP.</p>
</li>
<li>
<p>Proven experience architecting multi-tenant identity platforms with complex isolation requirements, tenant-specific configurations, and enterprise feature sets.</p>
</li>
<li>
<p>Strong background in cryptographic protocols including advanced JWT patterns, key rotation strategies, Hardware Security Module (HSM) integration, and post-quantum cryptography considerations.</p>
</li>
<li>
<p>Experience building identity platforms with sophisticated analytics, real-time monitoring, and security event detection capabilities at enterprise scale.</p>
</li>
<li>
<p>Expertise in global identity infrastructure including edge deployment strategies, geo-distributed token validation, and cross-region data consistency patterns.</p>
</li>
<li>
<p>Deep understanding of enterprise identity integration patterns including SAML federation, LDAP/AD bridges, SCIM provisioning, and custom protocol adapters.</p>
</li>
<li>
<p>Proven track record building developer-first identity platforms including comprehensive SDKs, webhook systems, and extensible API designs.</p>
</li>
<li>
<p>Experience with identity platform security including threat modeling, penetration testing coordination, and implementation of advanced attack prevention mechanisms.</p>
</li>
<li>
<p>Strong background in compliance and regulatory requirements for identity systems including audit trail design, data residency controls, and privacy engineering.</p>
</li>
<li>
<p>Experience building identity platforms supporting complex organizational structures, delegated administration, and fine-grained permission models.</p>
</li>
<li>
<p>Expertise in high-performance system design including horizontal scaling strategies, caching architectures, and latency optimization for identity operations.</p>
</li>
<li>
<p>Knowledge of service mesh identity patterns, workload identity bootstrapping, and integration with container orchestration platforms.</p>
</li>
<li>
<p>Experience with identity protocol extensions, custom grant flows, and building extensible identity platforms that support diverse use cases.</p>
</li>
<li>
<p>Proven ability to lead technical initiatives in complex, regulated environments while balancing innovation with security and compliance requirements.</p>
</li>
</ul>
<p>#LI-AW1</p>
</p>
<p><strong>About Kong:</strong> </p>
<p>Kong Inc., the AI Connectivity Company, is building the connectivity layer of AI. Trusted by the Fortune 500® and AI-native startups alike, Kong’s unified API and AI platform enables organizations to secure, manage, accelerate, govern, and monetize the flow of intelligence across APIs and AI traffic — on any model, any cloud. For more information, visit <a href="http://www.konghq.com" rel="nofollow ugc noopener" target="_blank">www.konghq.com</a>.</p></p>