Principal Software Engineer (Hybrid, Denver Metro Preferred)
About the role
FusionAuth is hiring a Principal Engineer to serve as a senior technical authority on customer identity. This person will be a key contributor to the architectural direction of the FusionAuth platform, carry deep protocol expertise (OAuth 2.x, OpenID Connect, SCIM, SAML), and guide enterprise customers on how FusionAuth fits into their identity architectures.
Responsibilities
Write, review, and own high-quality, secure production code on the FusionAuth core application. This is a hands-on technical leadership role, not a design-only position.
Provide leadership for the platform’s architectural evolution. Draft and review Technical Design Documents (TDDs), ensuring designs meet FusionAuth’s standards for scalability, security, and quality before implementation begins.
Serve as a go-to expert on OAuth 2.x, OIDC, SCIM, and SAML. Guide protocol-correct implementation across the product. Answer hard protocol questions from engineering, Support, Solutions Engineering, and customers.
Engage directly with enterprise prospects and customers on architectural and integration design decisions. Translate complex CIAM concepts clearly for both technical and semi-technical audiences.
Track not just protocol evolution but broader technology shifts (frameworks, languages, infrastructure patterns) that should influence the platform’s direction. Partner with Product Management to translate these insights into roadmap decisions.
Represent FusionAuth at industry conferences, working groups, and community events. Build FusionAuth’s technical credibility in the identity and security ecosystem.
Factor FusionAuth’s diverse deployment targets into every architectural and feature decision. Ensure backward compatibility, API versioning integrity, upgrade paths, and sound schema migration strategy for a product running across thousands of customer-managed environments.
Mentor engineers across the team. Raise CIAM knowledge through code reviews, design discussions, architectural sessions, and informal knowledge sharing.
Work closely with Product Management, Solutions Engineering, and Customer Success on complex customer situations, roadmap decisions, and new feature design.
Qualifications
Required Education: Bachelor’s degree in Computer Science or equivalent demonstrable technical depth.
CIAM Protocol Depth: Production-grade expertise in OAuth 2.x, OIDC, SCIM, and SAML. The ability to identify subtle misimplementations, guide protocol-correct designs, and explain nuanced tradeoffs.
Experience: 12+ years of professional software engineering, including 5+ years focused on identity, authentication, or security, with meaningful time at the principal, staff, or architect level.
Hands-On Development: Proven track record of shipping code alongside architectural responsibilities. Not an architect who stopped coding.
Distributed Systems: Experience with enterprise-grade, highly available, high-performance distributed systems.
Deployment Architecture: Experience designing or supporting software deployed across self-hosted, on-premise, or dedicated cloud environments. Understanding of backward compatibility, upgrade paths, and performance tuning across customer-managed infrastructure.
Customer-Facing Experience: Demonstrated ability to engage directly with enterprise customers and prospects on technical design and architecture.
Design Review: Experience reviewing and approving technical designs in a formal or informal architecture review capacity.
Emerging Standards: Familiarity with emerging identity protocols and standards (FIDO2/passkeys, DPoP, token binding, OAuth 2.x drafts, etc.).
AI Tooling: Willingness to adopt and use AI-assisted development tools (e.g., Claude Code, GitHub Copilot) as part of everyday workflow.
Pragmatism: Appreciates first-principles thinking, but knows when to stop theorizing and start building.
Work Location: FusionAuth is headquartered in Denver, Colorado, and we value the creative energy and collaboration that comes from working together in person. We strongly prefer candidates based in the Denver metro area and have a hybrid working arrangement for local employees. We are open to candidates in other locations who are willing to travel to our Denver headquarters approximately once per quarter.
Preferred CIAM Product Experience: Direct experience building or working within a CIAM product or identity platform.
Open Source & Thought Leadership: History of contributing to open-source identity or security projects, or publishing technical writing on identity topics.
AI-Native Development Practices: Experience leading or supporting an engineering team’s transition to AI-native development workflows.
Security & Compliance: Familiarity with compliance frameworks (SOC 2, FedRAMP, GDPR) and their impact on architectural decisions around data residency, encryption, and audit logging.
Database Expertise: Experience with PostgreSQL or MySQL at scale, including schema evolution strategy, query performance tuning, and data migration planning for a self-hosted product.
Java Proficiency: Strong Java skills. FusionAuth’s core application is Java-based.
Communication Style: Strong communicator who holds strong technical opinions while remaining open to other perspectives.