Location: Remote, Vietnam
Employment Type: Full-time
Schedule: Flexible time
Level: Senior
Compensation: 45.000.000 - 60.000.000 VND/month
Company: Twin Signal
About Twin Signal
Twin Signal, a ZenitechCS company, is dedicated to launching new products and expanding into new markets, building on our proven foundation of excellence. For more than 15 years, ZenitechCS has delivered reliable IT solutions to clients across California, USA. Through Twin Signal, we’re extending that legacy with focused AI-first innovation and market expansion.
Our capabilities span end-to-end technology services, including IT Service Management, Software Development, Database Administration, Information Security, Business Intelligence, Computer Networking, and Systems Administration.
Work Policy
This position is 100% remote. The Software Engineer PAM is expected to be available and responsive during established working hours, with flexibility based on project and operational requirements. Team members must maintain a secure home-working environment and protect company and client information from unauthorized access, insecure networks, bystanders, cameras, or other data-exposure risks.
Position Overview
We are seeking a Senior Software Engineer to build and support a Privileged Access Management platform: desktop agents, browser extensions, admin tooling, backend services, and zero trust access controls with a strong focus on identity/account integrations (automated provisioning, deprovisioning, and suspension). Ideal candidate combines application security expertise with solid networking and IAM knowledge and real-world enterprise IT experience.
Key Responsibilities
- Design, develop, test, and maintain desktop agent software that runs on endpoint operating systems to broker, monitor, and secure privileged sessions
- Build and maintain browser extensions for secure credential injection, session recording, and web-based privileged access workflows
- Implement zero trust access controls, including continuous verification, least-privilege enforcement, just-in-time access, and policy-based session gating
- Prioritize building and maintaining integrations with identity providers, directory services, and account-management systems — including automated account creation, modification, and suspension/deprovisioning workflows
- Develop backend services, APIs, and data models supporting credential vaulting, password rotation, session brokering, approval workflows, and audit logging
- Build secure, responsive administrative interfaces and dashboards for IT administrators to manage privileged accounts, policies, and access requests
- Integrate with identity providers, directory services, operating systems, cloud platforms, and network infrastructure to discover and manage privileged access
- Apply strong application security practices across the stack: secure authentication, authorization, encryption, secrets management, input validation, and defense against common attack vectors
- Investigate and resolve security defects, agent/extension failures, integration issues, and production incidents across desktop, browser, and server components
- Produce technical documentation, architecture diagrams, and runbooks for agents, extensions, and integration points
Primary Responsibilities
- Develop and maintain desktop agents (Windows/macOS/Linux) responsible for privileged session establishment, credential handling, and local policy enforcement
- Develop browser extensions integrated with the vaulting and session-brokering backend for secure web-based privileged access
- Build zero trust access workflows: device posture checks, network-aware access decisions, session approval, step-up authentication, and continuous session monitoring
- Design, build, and maintain identity and account-management integrations as a core priority — including account creation, attribute updates, suspension, and deprovisioning across directories, cloud IAM, SaaS platforms, and client systems
- Ensure account lifecycle actions (creation, suspension, and deletion) are reliable, auditable, and reversible where required, with clear error handling and reconciliation across connected systems
- Design and optimize backend services, relational/non-relational data stores, and APIs supporting secure, auditable access-management workflows
- Implement integrations with SSO, MFA, directory services (Active Directory/LDAP), cloud IAM, network devices, and endpoint platforms
- Write clean, modular, testable, well-documented code across backend, agent, and extension codebases
- Participate in threat modeling, architecture reviews, secure code review, and security testing for all new capabilities
- Apply secure development practices around encryption, secrets management, least-privilege access, and secure inter-process/network communication (agent-to-backend, extension-to-backend)
- Communicate technical tradeoffs, risks, and security implications clearly to stakeholders and IT administrator end users
Secondary Responsibilities
- Support enterprise IT administration use cases: agent deployment at scale, endpoint policy configuration, and administrator onboarding
- Monitor agents, extensions, backend services, and identity/account integrations for reliability, performance, and security anomalies
- Conduct root-cause analysis on recurring agent, extension, network, or account-integration issues
- Contribute to CI/CD, packaging/distribution pipelines for desktop agents and browser extensions, containerization, and observability
- Assist with technical discovery, architecture planning, and roadmap input for zero trust, PAM, and identity-integration features
- Mentor engineers and help establish standards for secure agent/extension and integration development
Required Qualifications
- Strong professional English communication skills, written and verbal
- 8+ years of professional software engineering experience, including senior-level ownership of production systems
- Strong proficiency in one or more general-purpose languages (Python, JavaScript/TypeScript, Go, or Rust), including experience building native desktop or agent-based software
- Experience building or maintaining browser extensions (Chrome/Edge/Firefox extension APIs, content scripts, background/service workers)
- Hands-on experience designing and consuming REST APIs and integrating third-party systems
- Direct experience building integrations for identity and account management, including account provisioning, attribute synchronization, and suspension/deprovisioning workflows (e.g., SCIM or equivalent)
- Strong understanding of IAM principles: authentication, authorization, RBAC/ABAC, least privilege, session management, and audit logging
- Practical experience with PAM concepts: privileged accounts, credential vaulting, password rotation, privileged sessions, access approval workflows, and auditing
- Solid understanding of networking technology: TCP/IP, DNS, TLS, VPNs, proxies, firewalls, and network segmentation as they relate to access control
- Strong application security fundamentals: secure coding practices, encryption, secrets management, vulnerability remediation, and secure handling of sensitive credentials in memory and transit
- Strong SQL skills and practical experience with relational databases (PostgreSQL, SQL Server, or MySQL)
- Experience with cloud platforms, Linux and/or Windows systems administration, and directory services such as Active Directory or LDAP
- Familiarity with Git, code review, automated testing, CI/CD, and secure release practices
- Ability to independently troubleshoot complex issues spanning desktop agents, browser extensions, backend services, and network/identity integrations
Preferred Qualifications
- Experience building or working on PAM, identity governance (IGA), or secure remote access products
- Experience with zero trust architectures (e.g., continuous authorization, device trust, network micro-segmentation)
- Experience integrating SSO/identity providers via SAML, OAuth 2.0, OpenID Connect, or SCIM, particularly for automated account lifecycle management
- Experience with Docker, Kubernetes, infrastructure-as-code, and observability tooling
- Experience with JavaScript/TypeScript frameworks (React, Vue, or Angular) for admin dashboards and web UIs
- Familiarity with SIEM, SOAR, endpoint management, and security operations workflows
- Knowledge of secure SDLC, threat modeling, and application-security testing (SAST/DAST, penetration testing exposure)
- Prior experience mentoring developers or leading small technical initiatives
Schedule
The hours are flexible, but the candidate must be able to respond to issues during the following time: Monday to Friday, 8:00 - 17:00 (Vietnam Time).
Compensation
The salary offered is 45.000.000 - 60.000.000 VND/month
Important Note: We will not hire a candidate who receives a “low” assessment in English proficiency.
Perks & Benefits
- End of Year Bonus: Standard bonus is valued at least one month’s salary. If the company is successful and staff have performed well, highly performing staff may receive larger bonuses. Vietnamese staff will receive bonuses before Tết.
- Health Insurance: Health insurance will be provided to all staff.
- Dental Insurance: Dental insurance will be provided to all staff.
- Vision Insurance: Vision insurance will be provided to all staff.
- Remote Work: The position is 100% remote.
- Paid Time Off (PTO): We offer a base of 15 days of paid time off in addition to 12 national holidays, for a total of 27 paid days off. Additional time off can be requested as needed.
- Mentorship: We offer on-the-job training, continuing education, code review, and technical assistance when required.