Team Lead Backend Engineer

location_onRussiaschedule8 araw ang nakalipas
trending_upAntas ng karanasan:Nangunguna
historyMinimum na karanasan:7+ taon

Paglalarawan ng trabaho

You will lead the technical strategy and architecture for authentication, authorization, and session management at scale. You will design OAuth and OIDC flows, strengthen web-security controls, guide Ory and CockroachDB decisions, and lead a zero-downtime identity migration. You will review security-critical code, resolve systemic risks, contribute to critical security features, manage and mentor engineers, and coordinate roadmap delivery with dependent product teams.

Responsibilities

  • Own the technical strategy and architecture for authentication, authorization, and session management
  • Design and evolve OAuth 2.0 and OIDC flows, token lifecycles, and security primitives
  • Lead decisions on Ory, custom authentication methods, and Auth API orchestration
  • Own cookie security, CSRF and XSS protection, token storage, TLS, and session management
  • Drive CockroachDB strategy for geo-distributed data residency
  • Review security-critical code and enforce best practices
  • Drive zero-downtime migration from legacy Xsolla Login with bidirectional identity synchronization
  • Identify and resolve systemic risks and performance bottlenecks
  • Make system-design, security-architecture, and technology decisions
  • Contribute hands-on to critical security features
  • Lead and mentor up to eight backend engineers
  • Conduct 1:1s, performance reviews, and career-development conversations
  • Hire and onboard engineers with IAM and security expertise
  • Manage workload and delivery commitments
  • Own delivery predictability for the platform
  • Collaborate with Product on IAM roadmap and priorities
  • Coordinate with dependent product teams
  • Report security posture, platform reliability, and team progress

Requirements

  • 5+ years of commercial Go experience, or 7+ years in other backend languages with Go proficiency
  • Expertise in OAuth 2.0, OIDC, and IAM systems
  • Knowledge of authorization code with PKCE, client credentials, device flow, token introspection, and refresh strategies
  • Understanding of JWT, token refresh flows, and session management
  • Knowledge of password hashing and secure storage
  • Knowledge of cookie security, CSRF, XSS, TLS, and secure session management
  • Knowledge of MySQL, PostgreSQL, and Redis
  • Experience with distributed-system trade-offs
  • Experience designing highly available systems
  • Understanding of security best practices and OWASP vulnerabilities
  • Experience with Docker, Kubernetes, and production deployments
  • 2+ years of engineering-team leadership experience
  • Experience delivering mission-critical infrastructure
  • Ability to lead multi-quarter cross-team technical initiatives
  • Experience with security-focused code review
  • Written and verbal communication skills
  • Ability to balance security requirements and delivery timelines

Mga kasanayang nabanggit

Mag-apply para sa trabahong ito

Use the application link supplied with this listing to apply to Xsolla (USA), Inc.. Check the destination before entering personal information.