JobRaahGet matched free

Jobs

Senior Software Engineer (AM+ Auth)

Gravitee · Denver, United States · Hybrid

Posted Sep 10, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Gravitee is a 2025 Gartner® Magic Quadrant™ Leader , on a mission to govern the world’s intelligence . We deliver the industry’s most advanced platform for Any API, Any Event, and Any AI Agent , trusted by global leaders like Michelin, Roche, and Blue Yonder. Why join us? The Mission : We are the first to bridge traditional API Management with the new frontier of AI Agent Security The Momentum : A high-growth Leader - combining market credibility with startup speed The DNA : We hire people who Hold Nothing Back - passionate builders who want to redefine digital infrastructure Don’t just watch the AI revolution. Build the infrastructure that controls and secures it. The Role We are looking for a Senior Software Engineer to build and maintain the identity and authorization features of Gravitee Access Management (AM) — across the AM runtime and the access-management experience in Gamma, Gravitee's next generation product surface. This is a new role. Today, AM engineering is based entirely in Europe. This hire establishes US-hours ownership of Level 3 and Level 4 authentication and authorization incidents, and adds delivery capacity toward AM parity in Gamma — part of building sustainable L3/L4 engineering capability in the US. You will split your time roughly 80% feature delivery and 20% L3/L4 support and bug fixing (it varies week to week), working as an embedded member of the AM team, which is based in Europe. What You Will Be Doing In this role, you will: Design and deliver features end to end, from discovery and technical design through implementation, testing, release, and iteration. Build and maintain identity and authorization features of Gravitee Access Management, across the AM runtime and the AM experience in Gamma. Implement and support OAuth 2.0 and OIDC flows (authorization code + PKCE, client credentials, token exchange), SAML 2.0 as both IdP and SP, SCIM, and FAPI/CIBA/UMA profiles. Work with token and session semantics — JWT, JWKS, key rotation, revocation, introspection, MFA and step-up, WebAuthn/FIDO2, and IdP federation and social login. Keep security behavior and upgrades safe: standards compliance, secure defaults, certificate and secret handling, consent, audit logs, and defenses against token replay, SSRF, and account takeover. Own safe migrations and backward compatibility across MongoDB and JDBC, and support multi-domain, multi-region deployments and login/token endpoint performance. Own US-hours Level 3 and Level 4 escalations for AM customers as part of the L3 pager duty rotation. Use LLMs and AI-assisted development tools thoughtfully for prototyping, implementation, testing, debugging, and exploration, applying sound engineering judgment to validate AI-generated work. Write meaningful automated tests and contribute to reliable delivery practices. • Collaborate with product managers, designers, engineers, and technical leaders — including the AM team based in Europe — to…