ForgeApply
Try it free

ForgeApply · Job listing

Senior Software Engineer 2, IAM

Drata

US$175k – $236khybridSaaS

See all 43 open roles at Drata

Tailor your resume for this Drata job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Drata's site with it. You review everything before it's sent. Free trial, no card required.

About this role

Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from.

Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for:

- Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go.

- Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them.

- A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level.

- Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience.

- A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here https://drata.com/about/careers/life and follow us on LinkedIn https://www.linkedin.com/company/drata/posts/?feedView=all for company news, employee stories, and career updates.

Job Summary:

Drata's Identity & Access Management team owns the identity, authentication, and access control infrastructure that every customer uses to access the platform — and that every internal platform service relies on for trust boundaries.

- Authentication — SSO (SAML 2.0, OIDC), session/token management, MFA. We're focused on authentication for enterprise customers — large user populations, sophisticated identity setups, and the uptime and observability that scale demands.

- Authorization — the access control model that determines what users, services, and agents can do across the platform — from role-based access to fine-grained authorization for enterprise customers, internal services, and AI-driven actions.

- Provisioning & lifecycle — SCIM 2.0 provisioning for enterprise customers like Okta, Microsoft Entra ID, and others. Group-to-role mapping, conflict resolution, and the long tail of behaviors enterprise identity setups demand.

- Identity sync infrastructure — keeping Drata's view of the customer's workforce accurate via against Okta, M365, Google, and beyond. Efficiency across provider support, customers with small to enterprise user populations and to surface what's happening clearly when something goes wrong.

- Auth for platform services and AI — providing the trust primitives other Drata services build on, and supporting authentication and human-in-the-loop authorization patterns for AI features and agentic workflows.

What you'll do:

- Design and operate Drata's authentication surface: SSO integrations (SAML, OIDC), session and token handling, MFA, and flexible enterprise identity configurations.

- Contribute to Drata's authorization architecture — collaborating on direction, owning meaningful pieces of execution, and bringing your perspective on the tradeoffs (RBAC vs. ABAC vs. etc., policy engines, audit and observability of access decisions).

- Build and harden SCIM provisioning at enterprise scale: group sync, role mapping, deactivation, conflict resolution, and the long tail of IdP-specific behavior.

- Build and operate identity sync workflows — full and delta syncs across major identity providers — with the observability, retry semantics, and parity guarantees enterprise sync demands.

- Build authentication and authorization for AI features and agentic flows: scoped credentials for AI agents, human-in-the-loop approval workflows, and the audit trail needed to defend AI-driven actions in a compliance product.

- Provide the auth primitives other platform services depend on, and represent IAM in cross-team architecture discussions.

- Threat-model identity surfaces, partner with security on hardening, and own the response when identity is implicated in an incident.

What you'll bring:

- 7+ years building production software, with meaningful time spent on authentication, authorization, or identity infrastructure.

- 3+ years experience in a NodeJS / TypeScript codebase with a deep understanding of Typescript.

- Working knowledge of the identity protocols this team operates against: OAuth 2.0 / OIDC, SAML 2.0, SCIM 2.0. You don't need to have shipped all three — fluent enough to design against them.

- Experience designing or operating access control systems — at minimum RBAC, ideally with exposure to attribute-based or relationship-based authorization.

- Working knowledge of surfacing observability & security information from complex systems.

- Experience designing and collaborating on API design and architecture

- Strong fundamentals in session management, token lifecycle, MFA, and the security tradeoffs that come with each.

- Production experience operating on a major cloud (AWS preferred; we use it heavily).

- Security-first instinct: you think about misuse before you ship, and you can defend a design decision against a threat model.

- Comfortable in collaborative architecture work — contributing to designs you don't fully own while owning execution on the pieces you do.

Nice-to-Haves

- Experience integrating with or building on top of identity platforms: Okta, Microsoft Entra ID, Auth0, Ping, WorkOS.

- Experience with authorization engines (OpenFGA, Cedar, OPA) or with designing a custom policy model.

- Experience operating S

Salary insight

The midpoint of this range ($205k) is right around the median disclosed salary for San Francisco roles listed on ForgeApply ($200k across 8,773 jobs).

See full Software Engineer salary data for San Francisco

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Drata role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Software Engineer Jobs · Software Engineer Jobs in San Francisco · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)