WorkOS
Software Engineer - Infrastructure Security
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 17h ago · Found 6h ago
First listed today.
Salary
$175,000 to $275,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States & Canada, Remote"
- Job description states: "US Only"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About WorkOS 🚀
WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations. We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Sierra, and Plaid. As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.
About the Security Platform team
The Infrastructure Security team provides and supports the primitives that enable engineering to securely build applications and meet compliance obligations, while abstracting away the underlying complexity for the best possible developer experience.
Our work centers on workload identity and authorization: how internal applications authenticate to each other and to the services they depend on, and how that access is granted and enforced. We're replacing static secrets with short-lived identity credentials, bringing identity-based authentication to the services engineers use every day, and unifying how authorization is managed across the company.
We're a platform engineering team with a security mission. We measure success by the security outcomes we enable and by how much engineers enjoy building on what we ship — the secure path should be the easiest path.
Who we're looking for
A platform builder. You love building infrastructure that other engineers rely on every day, and you sweat the developer experience details that make adoption effortless.
Fluent in service-to-service auth. You know authentication and authorization deeply: JWTs, X.509 certificates, and when to reach for each.
A systems thinker. You reason carefully about bootstrapping, circular dependencies, availability, and failure modes, especially for infrastructure that everything else depends on.
A pragmatic migrator. You know that shipping the primitive is half the job. You can drive adoption across many teams, meet them where they are, and retire the legacy path.
A strong partner to engineering. You build trust with engineers by understanding their priorities and making security frictionless.
Excited about AI. You're embracing AI and automation to scale platform work and reduce toil.
Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.
Responsibilities
Build workload identity infrastructure. Make short-lived identity credentials a default part of every application's runtime environment, in partnership with application platform owners.
Bring identity-based authentication to internal services. Work with the owners of major internal dependencies to support identity certificates, make them the golden path for newly onboarding applications, and drive migration of existing ones.
Eliminate static secrets. Replace all static passwords and service tokens with short-lived identity credentials, and build identity-authenticated egress proxies and API abstractions that inject and automatically rotate managed secrets for the external dependencies that still require them.
Unify authorization. Build a single interface and framework through which authorization policies are centrally managed and enforced.
Qualifications
5+ years of experience in software engineering, with a focus on security-related platform, infrastructure, or distributed systems.
Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems.
Familiarity with the Kubernetes ecosystem and authentication/authorization technologies such as JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA.
Experience building and operating production infrastructure that other teams depend on, with attention to availability and failure modes.
Requirements
- ·5+ years of experience in software engineering, with a focus on security-related platform, infrastructure, or distributed systems.
- ·Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems.
- ·Familiarity with the Kubernetes ecosystem and authentication/authorization technologies such as JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA.
- ·Experience building and operating production infrastructure that other teams depend on, with attention to availability and failure modes.
- ·Proven ability to drive cross-team adoption of platform capabilities or lead large-scale migrations.
Benefits
- ·Competitive Equity
- ·Healthcare, dental and vision coverage
- ·FSA, ST/LT Disability, Voluntary Life
- ·Carrot fertility benefits
- ·20 days paid vacation + 10 holidays + unlimited sick leave
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at WorkOS, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 7h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$175,000 to $275,000 · You'll be taken to the employer's careers page.