Software Engineer - IAM
Location : Pune
About Team & About Role:
As a Software Engineer (SE) in the Continuous Product Delivery (CPD) team, you will play a key role in providing long term stability and last mile delight to our customers. You will work closely with the core engineering team, product, and support org.
You will be working across Rubrik releases on our on-premise data backup & management offering, with a focus on the identity and access layer that secures it. You are expected to develop a strong understanding of our product and engineering architecture — particularly how authentication and authorization flow through the system, including our integrations with enterprise identity providers, directory services, and certificate-based trust chains.
We are seeking a highly skilled Golang developer with deep, practical experience in identity protocols (OIDC/OAuth 2.0, SAML 2.0) and applied cryptography/PKI. As a Software Engineer on this team, you will be responsible for designing, building, and hardening the systems that authenticate users, machines, and services across our platform — reasoning carefully about threat models, not just shipping features. You should have strong programming and troubleshooting skills, excellent design skills, and a solid understanding of distributed systems, OS fundamentals, and networking. The successful candidate will preferably have working knowledge of Active Directory and be able to work independently and as part of a team.
Responsibilities
Design, build, and harden identity and access flows — OIDC/OAuth 2.0, SAML 2.0, Active Directory integrations — that sit in front of mission-critical systems.
Own token and assertion lifecycle correctness: issuance, validation, expiry, rotation, and failure-mode handling for JWT/JWKS and SAML assertions.
Apply strong applied-cryptography and PKI practices (X.509 certs, key rotation, TLS) to keep the auth path secure by default, not as an afterthought.
Build and maintain reverse-proxy/HTTP-layer components (TLS termination, header handling) that front customer authentication traffic.
Debug and resolve customer-facing identity/access issues, working with support to triage escalations quickly.
Contribute to build/release and cross-platform packaging (Linux deb/rpm, Windows MSI) as needed.
Maintain a small Windows companion application written in C#/.NET.
Write and enhance end-to-end tests covering auth flows, failure modes, and edge cases (clock skew, revoked tokens, malformed assertions, etc.).
Document known issues, workarounds, and design decisions in the team knowledge base as the team and product mature.
Communicate clearly with product and engineering stakeholders on design tradeoffs, security posture, and escalation status.
Requirements
Must-have
Strong hands-on programming skills in Golang.
Deep, practical knowledge of identity protocols: OIDC/OAuth 2.0 and SAML 2.0 — including token/assertion internals, standard flows, and failure modes.
Working knowledge of Active Directory.
Applied cryptography/PKI experience: X.509, JWT/JWKS, key rotation, TLS.
Strong security engineering discipline — comfortable reasoning about threat models and building software to protect mission-critical systems, not just make features work.
Solid understanding of OS fundamentals, networking, and concurrency.
Working knowledge of Linux; comfortable writing shell/bash scripts.
Simple, effective written and verbal communication.
Nice-to-have
Directory internals (schema, bind operations).
HTTP internals and reverse proxying (TLS, header injection).
Build/release and cross-platform packaging (Linux deb/rpm, Windows MSI).
Secret-manager internals, Redis, Win32, policy engines.
Basic C#/.NET (to maintain the companion app).
Join Us in Securing and Accelerating the World's AI Transformation