JobsBackendStaff CIAM Security Engineer
Affirm

Affirm

ยท

Backend

Staff CIAM Security Engineer

RemoteLeadPosted Aug 17, 2026
PythonKotlinOAuthOIDCSAMLSCIMAWSKubernetes+15 more

About this role

Affirm is seeking a Staff CIAM Security Engineer to design and build core customer identity and authentication backend services. You'll implement OAuth 2.0, OIDC, SAML, and SCIM standards while owning secure registration, login, and authorization flows across B2C and B2B platforms at scale.

Must have

7+ years designing, developing and launching backend systems at scale

5+ years professional backend software engineering experience

Strong production experience in Python or similar backend language

Deep hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM beyond basic configuration

Experience designing APIs, automation frameworks, and distributed systems

Hands-on experience building and maintaining CI/CD pipelines

Experience with GitHub-based development workflows and Buildkite or similar

Experience with cloud-native development, preferably AWS

Hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C

Solid understanding of backend and distributed systems fundamentals

Experience with Infrastructure as Code and automation tools such as Terraform

Strong security fundamentals including access control, token handling, encryption, MFA, and privacy by design

Familiarity with tools such as Cursor and other AI-augmented development environments

Technologies

PythonSQLAWSSparkKotlinGitDockerRESTLinuxMySQLTerraformJSONGitHubOAuthKubernetesCI/CDAPISAMLOIDCSCIMBuildkiteMFACursor

Responsibilities

Design, build, and operate core CIAM backend services for customer registration, authentication, authorization, account lifecycle, and profile management

Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code

Develop backend APIs and services in Python and Kotlin that expose identity capabilities

Integrate CIAM platforms with internal systems including user data stores, messaging, fraud signals, and downstream platforms

Own secure authentication and account flows end to end including MFA, step-up authentication, device binding, consent, and adaptive authentication

Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines

Monitor, debug, and optimize CIAM services for performance, resilience, and abuse detection

Benefits

Flexible time offHealth insuranceDental insuranceVision insuranceEmployee share purchase planCompetitive salary and stock option planWellness allowanceHome office allowance

Amenities

100% subsidized medical coverage for you and dependentsFlexible Spending Wallets with generous stipends for technology, food, lifestyle needs, and family forming expensesCompetitive vacation and holiday schedulesESPP enabling purchase of Affirm shares at discount

Recruitment process

1

Role is hands-on engineering position inside Information Security

2

Work closely with partner engineering teams to deliver identity features with strong security fundamentals

3

Clear communication skills required to work with product, frontend, mobile, and security teams

4

Base pay grade is P, equity grade is USA 7

5

Employees new to Affirm typically come in at start of pay range

6

Affirm focuses on simple and transparent pay structure based on location, experience and job-related skills

7

This posting is for an existing vacancy

8

Affirm is proud to be remote-first company

9

Majority of roles are remote with flexibility to work almost anywhere within country of employment

10

Affirm offers inclusive interview experience with reasonable accommodations for people with disabilities