Team Lead Backend Engineer
location_onRussiaschedule8 araw ang nakalipas
trending_upAntas ng karanasan:Nangunguna
historyMinimum na karanasan:7+ taon
Paglalarawan ng trabaho
You will lead the technical strategy and architecture for authentication, authorization, and session management at scale. You will design OAuth and OIDC flows, strengthen web-security controls, guide Ory and CockroachDB decisions, and lead a zero-downtime identity migration. You will review security-critical code, resolve systemic risks, contribute to critical security features, manage and mentor engineers, and coordinate roadmap delivery with dependent product teams.
Responsibilities
- Own the technical strategy and architecture for authentication, authorization, and session management
- Design and evolve OAuth 2.0 and OIDC flows, token lifecycles, and security primitives
- Lead decisions on Ory, custom authentication methods, and Auth API orchestration
- Own cookie security, CSRF and XSS protection, token storage, TLS, and session management
- Drive CockroachDB strategy for geo-distributed data residency
- Review security-critical code and enforce best practices
- Drive zero-downtime migration from legacy Xsolla Login with bidirectional identity synchronization
- Identify and resolve systemic risks and performance bottlenecks
- Make system-design, security-architecture, and technology decisions
- Contribute hands-on to critical security features
- Lead and mentor up to eight backend engineers
- Conduct 1:1s, performance reviews, and career-development conversations
- Hire and onboard engineers with IAM and security expertise
- Manage workload and delivery commitments
- Own delivery predictability for the platform
- Collaborate with Product on IAM roadmap and priorities
- Coordinate with dependent product teams
- Report security posture, platform reliability, and team progress
Requirements
- 5+ years of commercial Go experience, or 7+ years in other backend languages with Go proficiency
- Expertise in OAuth 2.0, OIDC, and IAM systems
- Knowledge of authorization code with PKCE, client credentials, device flow, token introspection, and refresh strategies
- Understanding of JWT, token refresh flows, and session management
- Knowledge of password hashing and secure storage
- Knowledge of cookie security, CSRF, XSS, TLS, and secure session management
- Knowledge of MySQL, PostgreSQL, and Redis
- Experience with distributed-system trade-offs
- Experience designing highly available systems
- Understanding of security best practices and OWASP vulnerabilities
- Experience with Docker, Kubernetes, and production deployments
- 2+ years of engineering-team leadership experience
- Experience delivering mission-critical infrastructure
- Ability to lead multi-quarter cross-team technical initiatives
- Experience with security-focused code review
- Written and verbal communication skills
- Ability to balance security requirements and delivery timelines
Mga kasanayang nabanggit
Mag-apply para sa trabahong ito
Use the application link supplied with this listing to apply to Xsolla (USA), Inc.. Check the destination before entering personal information.

