IFS logo
Est. Monthly
Estimated €5,000 - €6,000
Posted July 31, 2026 · 0 days agoLast seen July 30, 2026Est. expiry September 4, 2026

Platform Engineer

Principal Platform Engineer - Identity and Access Management
Staines-upon-Thames, United Kingdom
Hybrid · Software Engineering
Full-time · Senior
English
No People Management
How this salary compares
Salary Context: Platform Engineer

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("Market Average: Platform Engineer"), this listing's salary midpoint is about 92% lower. The offer sits below the benchmark range (€5,000–€6,000). The offer's range width is broadly in line with the benchmark. This benchmark is based on 1 comparable listings.

Monthly salary comparison for Platform Engineer
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
Market Average: Platform Engineer€5,000/per month€5,500/per month€6,000/per month
Pay in our data — not quoted in ad (Senior)€417/per month€458/per month€500/per month
About the role

As Principal Platform Engineer - Identity & Access Management, you will be the technical authority on authorisation (AuthZ) and authentication (AuthN) across the Kairos and Nexus platforms. You will architect, engineer, and operate enterprise-scale identity and access solutions that secure the IFS platform while remaining frictionless for the developers and end-users who rely on them. This is one of two Principal Platform Engineers being hired into the Identity & Access Management domain, with a strong emphasis on unifying authorisation across IFS hosting environments. The authorisation problem is complex and high-stakes: it must work consistently across Nexus, F1, and LEC, it must scale to enterprise, multi-tenant workloads, and it is currently a blocker for NGA (Kairos) adoption. You will work directly with the team building this today (the Authorisation subdomain under Udayanga Silva) and own the technical outcome. This is a hands-on engineering role with significant architectural scope. You will design and implement IAM patterns that are adopted as standards across IFS, and you will work closely with platform, product, and security teams to ensure identity and access are enablers, not bottlenecks. Architect and engineer the unified, enterprise-scale authorisation platform across Nexus, F1, and LEC, built on SpiceDB Design and implement fine-grained authorisation models: relationship-based access control (ReBAC / Zanzibar-inspired), alongside RBAC and ABAC where appropriate Model authorisation schemas, relationships, and permission checks that are correct, performant, and maintainable at scale Own the operation of the authorisation engine: SpiceDB on PostgreSQL, including the migration to cloud-native Postgres (CNPG) and blue-green deployment support Build the authorisation APIs and SDKs that product teams consume, making correct access control the path of least resistance Architect and engineer enterprise-scale AuthN solutions, and own the implementation, configuration, and operation of identity provider infrastructure, specifically Curity and/or Keycloak Implement and enforce OAuth 2.0, OpenID Connect (OIDC), and SAML patterns at scale, including token lifecycle management and claims-based authorisation Define IAM patterns, standards, and golden paths for product teams to implement securely and consistently Integrate identity and access services with the Internal Developer Platform (IDP) to enable self-service authentication and authorisation configuration Provide subject-matter expertise on identity and access security to product teams, architects, and security stakeholders Maintain platform identity and access service reliability, performance, and security posture Contribute to the broader platform engineering roadmap with an identity-and-access-first perspective Qualifications Authorisation (Must Have) Architecting and engineering fine-grained authorisation systems at production scale, in distributed, multi-tenant environments Hands-on production experience with a relationship-based / policy-based authorisation engine, ideally SpiceDB (or comparable Zanzibar-inspired systems such as OpenFGA, Ory Keto, or equivalent) Deep, practical knowledge of authorisation models: relationship-based access control (ReBAC), role-based (RBAC), and attribute-based (ABAC), and knowing when to apply each Experience designing authorisation schemas and permission models, and reasoning about correctness, latency, and consistency at scale Familiarity with policy-as-code approaches and tooling (OPA / Rego, Cedar, or equivalent) Understanding of the operational side: running the authorisation engine in production, backed by PostgreSQL, with observability and traceability of authorisation decisions Authentication (Must Have) Architecting and engineering enterprise-scale AuthN solutions, demonstrated at production scale Hands-on production experience with Curity and/or Keycloak: configuration, customisation, operations, and integration Deep, practical knowledge of OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and token-based authentication patterns (JWT, opaque tokens, token introspection) Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory) Strong hands-on engineering capability across the NGA stack, or the ability to get there fast: Backend: Go Messaging / Streaming: Apache Kafka / RedPanda Data: PostgreSQL Comfortable operating in a cloud-native environment: Kubernetes (AKS), containers, GitOps, Infrastructure as Code Event-driven and distributed systems architecture Secure coding practices and security-by-design principles

Job Details

Responsibilities

  • Architect and engineer a unified, enterprise-scale authorisation platform across Nexus, F1, and LEC using SpiceDB
  • Design and implement fine-grained authorisation models including ReBAC, RBAC, and ABAC
  • Model authorisation schemas, relationships, and permission checks for scale, performance, and maintainability
  • Operate the authorisation engine on PostgreSQL, including migration to cloud-native Postgres (CNPG) and blue-green deployment
  • Develop authorisation APIs and SDKs for product teams
  • Architect and engineer enterprise-scale AuthN solutions and manage identity provider infrastructure (Curity/Keycloak)
  • Implement and enforce OAuth 2.0, OpenID Connect (OIDC), and SAML patterns, including token lifecycle and claims-based authorisation
  • Define IAM patterns, standards, and golden paths for secure and consistent implementation by product teams
  • Integrate identity and access services with the Internal Developer Platform (IDP) for self-service configuration
  • Provide subject-matter expertise on identity and access security to architects, product teams, and security stakeholders
  • Maintain reliability, performance, and security posture of platform identity and access services
  • Contribute to the platform engineering roadmap from an identity-and-access-first perspective

Requirements

  • Experience architecting and engineering fine-grained authorisation systems at production scale in distributed, multi-tenant environments
  • Hands-on production experience with relationship-based/policy-based authorisation engines, ideally SpiceDB or comparable Zanzibar-inspired systems (OpenFGA, Ory Keto, etc.)
  • Deep practical knowledge of ReBAC, RBAC, and ABAC authorisation models
  • Experience designing authorisation schemas and permission models with a focus on correctness, latency, and consistency at scale
  • Familiarity with policy-as-code tooling such as OPA/Rego or Cedar
  • Experience running authorisation engines in production backed by PostgreSQL
  • Experience architecting and engineering enterprise-scale AuthN solutions at production scale
  • Hands-on production experience with Curity and/or Keycloak (configuration, customisation, operations, and integration)
  • Deep practical knowledge of OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and token-based authentication patterns (JWT, opaque tokens, token introspection)
  • Experience with enterprise identity federation, SSO, and directory integration (LDAP, Active Directory)
  • Strong engineering capability in Go
  • Experience with Apache Kafka or RedPanda
  • Experience with PostgreSQL
  • Proficiency in cloud-native environments: Kubernetes (AKS), containers, GitOps, and Infrastructure as Code
  • Knowledge of event-driven and distributed systems architecture
  • Adherence to secure coding practices and security-by-design principles
  • Demonstrable hands-on experience designing, building and shipping production AI applications

Skills & Technologies

SpiceDBGoPostgreSQLApache KafkaRedPandaKubernetes (AKS)CurityKeycloakOAuth 2.0OpenID Connect (OIDC)SAML 2.0ReBACRBACABACOPARegoCedarGitOpsInfrastructure as Code
Seen 1 day agoContent Complete
IFS logo
IFS · 345 open roles
Top locations: Remote - Global · 327 · Remote · 8 · Espoo, Finland · 3+5 other locations
View company
Most-hired roles
Account Executive
22
Product Manager
20
Software Engineer
11
Solution Architect
10
Strategic Account Executive
7
Role-level mix
Mid-Level (306)Senior (15)Manager (4)Entry-level (1)

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.