Software Engineer II, Identity and Access Management
Engineering at Brex
Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders.
What you'll do
The Identity and Access Management team builds and maintains secure, user-friendly authentication and authorization systems that protect users, safeguard company assets, and provide a seamless access experience for developers. The team owns critical platform capabilities including login methods, step-up authentication, our custom authorization platform, account delegation flows like Copilot, Pro Access login, embedded partnerships authentication, and core vendor integrations such as Okta and Oso.
As a Software Engineer II on IAM, you will build product and platform capabilities that make access to Brex secure, reliable, and easy to use for customers, partners, and internal systems. You will own well-scoped projects with clear impact, contribute to the team’s technical quality and operational excellence, and help evolve the identity platform as Brex invests in signed identity propagation, delegated and agent identity, fine-grained authorization, stronger auditability, and enterprise-ready customer authentication experiences.
Where you'll work
This role will be based in our São Paulo office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of 3 days per week in the office - Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work.
Responsibilities
Design, build, and operate backend systems and APIs for authentication, authorization, identity context, and audit-related workflows.
Deliver well-scoped projects end to end, from technical design and implementation through rollout, measurement, and operational support.
Improve login and access experiences across SSO, MFA, step-up authentication, delegated access, and enterprise identity flows.
Build and extend authorization systems that support custom roles, resource-aware access control, and secure defaults for product teams.
Help create durable, identity-aware audit trails and attribution for user, service, delegated, and agent-driven actions.
Partner closely with engineers across Brex to make IAM integrations secure by default and easier to adopt through clear patterns, tooling, and shared libraries.
Contribute high-quality code, design reviews, documentation, and operational improvements that raise the bar for reliability and maintainability across the team’s systems.
Requirements
You have strong software engineering fundamentals and experience building reliable production backend systems.
You have experience owning well-scoped technical projects and driving them to completion with limited support.
You have experience building APIs, services, or platform infrastructure with strong engineering rigor around testing, code quality, and documentation.
You communicate clearly, collaborate well across teams, and are effective in cross-functional technical discussions.
You care about operational excellence and know how to improve system reliability, reduce toil, and maintain high-quality services over time.
You have strong product and engineering judgment and can balance security, usability, and developer experience.
Strong written and verbal English communication and interpersonal abilities.
Bonus points
You have worked on identity and access management, authentication, authorization, or audit systems in a production environment.
You have hands-on experience with Okta, Oso, SSO, SAML, OIDC, OAuth, passkeys, or WebAuthn.
You have experience building enterprise-facing admin controls, custom roles, delegated access flows, or audit trails.
You have worked on platform teams that provide shared infrastructure, paved roads, or secure-by-default frameworks for other engineering teams.
If you don’t meet every qualification listed above, we still encourage you to apply. We’re looking for thoughtful engineers who want to build secure, scalable access systems and help shape how identity works across Brex.