
Staff Software Engineer I - Internal Access Management
Confluent · United States
- Hybrid
- Full-time
- CA$264,500 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Lead access management architecture and roadmap.
- Implement least privilege and zero-trust models.
- Build scalable authorization systems and workflows.
- Strengthen security with threat modeling.
- Mentor engineers and influence decisions.
About the role
Staff Software Engineer - Internal Access Management
We are seeking a Staff Software Engineer to lead the technical vision, architecture, and execution for Internal Access Management at Confluent. This role is central to our trusted compute environment and requires deep expertise in distributed systems, cloud security, authentication, and policy-driven authorization frameworks. As the domain owner, you will define how Confluent enforces least privilege, manages workload identity, governs access boundaries, and ensures secure, auditable authorization across all engineering systems. You will partner with Security, Product, and Engineering to establish a cohesive end-to-end access posture.
What You Will Do
- Define and drive the long-term architecture and roadmap for Internal Access Management across Kubernetes and multi-cloud environments.
- Architect and implement least privilege, just-in-time access, and zero-trust models across Confluent services.
- Build and evolve scalable access-authorization workflows and lifecycle management systems using technologies such as OPA, cloud IAM policies, workload identity, and internal enforcement engines.
- Strengthen security boundaries through threat modeling, defense-in-depth practices, and comprehensive access-auditing capabilities.
- Partner with cross-functional teams—including Platform, Kafka, Observability, Developer Productivity, Release Engineering, and SRE—to drive adoption of secure identity and access patterns.
- Mentor senior engineers, elevate engineering standards, and influence architectural decisions across the organization.
- Communicate complex technical decisions clearly and align stakeholders across engineering and security.
What You Will Bring
- 10+ years of engineering experience, with 4+ years in security, IAM, or distributed systems.
- Deep expertise in Kubernetes, workload identity, cloud IAM (AWS, GCP, Azure), and zero-trust architectures.
- Strong understanding of authentication technologies: IAM, OAuth2, OIDC, policy engines, and modern zero-trust principles.
- Proven track record leading multi-team technical initiatives at a Staff or Senior Staff level.
- Strong knowledge of distributed systems, cloud infrastructure, container orchestration, and service mesh.
- Excellent communication and stakeholder-influence skills across engineering and security domains.
What Gives You An Edge
- Experience leading cross-org security platform architecture initiatives.
- Background in building developer-focused authentication and authorization platforms.
Key skills/competency
- Staff Software Engineer
- Internal Access Management
- Kubernetes
- Cloud Security
- IAM
- Zero Trust Architecture
- Distributed Systems
- Authentication Technologies
- Policy Engines
- Stakeholder Influence
Skills & topics
- Staff Software Engineer
- Internal Access Management
- Software Engineering
- Security
- IAM
- Kubernetes
- Cloud Security
- Distributed Systems
- Zero Trust
- Authentication
- Authorization
- Policy Engines
- AWS
- GCP
- Azure
- OIDC
- OAuth2
- Leadership
- Architecture
- Roadmap
- Mentorship
- Confluent
How to get hired
- Tailor your resume: Highlight your 10+ years of engineering experience, focusing on 4+ years in security, IAM, or distributed systems. Emphasize expertise in Kubernetes, cloud IAM, and zero-trust architectures.
- Showcase leadership: Detail your proven track record of leading multi-team technical initiatives at a Staff or Senior Staff level.
- Prepare for technical questions: Be ready to discuss your deep understanding of authentication technologies like IAM, OAuth2, OIDC, and policy engines.
- Demonstrate communication skills: Prepare examples of how you've clearly communicated complex technical decisions and influenced stakeholders across engineering and security.
- Research Confluent's culture: Understand their focus on data streaming, collaborative environment, and commitment to belonging.
Technical preparation
Master Kubernetes security concepts.,Deep dive into IAM, OAuth2, and OIDC.,Understand and apply zero-trust principles.,Practice threat modeling for distributed systems.
Behavioral questions
Describe a complex technical decision you led.,How do you mentor other engineers?,Give an example of influencing stakeholders.,How would you define least privilege?
Frequently asked questions
- What are the key technical skills required for the Staff Software Engineer Internal Access Management role at Confluent?
- The Staff Software Engineer Internal Access Management role at Confluent requires deep expertise in Kubernetes, workload identity, cloud IAM (AWS, GCP, Azure), zero-trust architectures, and authentication technologies like IAM, OAuth2, OIDC, and policy engines. Strong knowledge of distributed systems, cloud infrastructure, and container orchestration is also essential.
- What is the expected experience level for this Staff Software Engineer position at Confluent?
- Confluent is looking for candidates with a minimum of 10 years of engineering experience, including at least 4 years specifically in security, IAM, or distributed systems. A proven track record of leading multi-team technical initiatives at a Staff or Senior Staff level is also a key requirement.
- How does Confluent approach Internal Access Management and security for its engineering systems?
- Confluent's Internal Access Management focuses on defining how least privilege, workload identity, access boundaries, and secure authorization are enforced across all engineering systems. They aim for a cohesive end-to-end access posture using technologies like OPA, cloud IAM policies, and zero-trust principles.
- What are the opportunities for mentorship and influence in this Staff Software Engineer role at Confluent?
- As a Staff Software Engineer at Confluent, you will have the opportunity to mentor senior engineers, elevate engineering standards, and influence architectural decisions across the organization. You will also communicate complex technical decisions and align stakeholders, playing a key role in shaping the company's security posture.
- What is Confluent's stance on diversity and inclusion for this Staff Software Engineer position?
- Confluent emphasizes belonging as a baseline, working across time zones and backgrounds to foster diverse perspectives. They are committed to being an equal opportunity workplace, making employment decisions based on job-related criteria without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
- What is the compensation range for the Staff Software Engineer Internal Access Management role at Confluent?
- The compensation range for the Staff Software Engineer Internal Access Management role at Confluent is CA$225,100 - CA$264,500 annually.