Staff Software Engineer (Hybrid, Denver Metro Preferred)
- Salary
- $190K–$230K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
509,705 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Job Title: Staff Software Engineer
Location: Hybrid, Denver Metro Preferred
About FusionAuth
FusionAuth is a fast-growing startup and leading provider of customer identity and access management (CIAM) software headquartered in Denver, Colorado. Our mission is to make authentication and authorization simple and secure for every developer. Our product helps businesses securely manage customer identities and access, ensuring a seamless and safe user experience for some of the largest brands in the world. We are committed to delivering exceptional value and satisfaction to our clients through top-notch service and support. With a great team and strong investors, we are expanding our team to help accelerate our growth and take FusionAuth to the next level.
FusionAuth is hiring a Staff Software Engineer to operate as a senior hands-on engineer. This is a deeply hands-on technical role: you solve the most complex problems, and the rest of the job (review, technical design, mentorship) grows out of that credibility rather than sitting apart from it.
The timing matters. AI agents need their own authentication and authorization. Passkeys are displacing passwords. Delegated token exchange is rewriting how services trust each other. FusionAuth ships into self-hosted, on-premise, and dedicated cloud environments across thousands of customer-managed deployments, so every decision here carries real weight. These problems are hard and consequential, and as a Staff engineer you will be one of the people solving them directly in the code, not just reviewing them after the fact.
You will also carry protocol expertise (OAuth 2.x, OpenID Connect, SAML, JWT) and engage directly with enterprise customers on implementation guidance and integration architecture. You drive impact by pairing sound technical judgment with cross-functional consensus-building - guiding senior engineers toward staff-level execution, aligning teams around complex architectural decisions, and sharing expertise through designs, code reviews, and technical discussions.
Responsibilities
- Core Engineering & Ownership: Tackle the most demanding platform and feature initiatives within the FusionAuth core product. Deliver resilient, secure, and thoroughly tested production code to resolve complex, open-ended technical challenges. Lead major end-to-end projects, collaborating with peers to manage everything from scoping and estimation to technical design and general availability.
- Technical Design: Write Technical Design Documents (TDDs) for key initiatives, advocating clear technical directions while remaining receptive to feedback. Provide strategic guidance to senior engineers on architectural plans to ensure alignment with FusionAuth's standards for quality, security, reliability and scalability.
- Quality & Review Standards: Elevate code and architectural review standards across the organization, integrating continuous learnings into the AI software development lifecycle. Define and enforce standards for architectural integrity, and testing quality, while advancing test automation and coverage to satisfy enterprise-grade reliability requirements.
- CIAM protocol expertise: Design advanced OAuth 2.x, OIDC, and SAML flows for enterprise deployments. Handle security edge cases and federation patterns, and guide protocol-correct implementation across the product.
- Customer engagement: Engage directly with enterprise customers and prospects on implementation guidance, integration architecture, and troubleshooting complex auth scenarios.
- Deployment and compatibility: Factor FusionAuth's diverse deployment targets into every decision. Protect backward compatibility, API versioning, and upgrade paths across thousands of customer-managed environments, and apply security and compliance judgment (OWASP, data residency, encryption, audit requirements like GDPR) to how you build.
- Mentorship and technical influence: Mentor senior engineers toward Staff-level thinking and autonomy, and ramp junior engineers through pairing and review. Build consensus on hard technical calls across teams, and communicate technical strategy to stakeholders with business context, representing engineering with Product, Sales Engineering, and Support.
- AI Integration & Workflow Optimization: Evaluate and implement AI-driven solutions and organizational context across the engineering team, embedding AI-augmented development and automated testing into everyday practices as FusionAuth modernizes its software development lifecycle.
Qualifications
Required
- Education: Bachelor's degree in Computer Science or equivalent demonstrable technical depth.
- Experience: 10+ years of professional software engineering, with demonstrated staff-level technical competency.
- Hands-on development: Currently writes and ships production code. This role stays in the code, so recent, active engineering is required.
- CIAM protocol depth: Production-grade experience with OAuth 2.x, OIDC, and SAML, including the ability to identify subtle misimplementations, guide protocol-correct designs, and handle federation and security edge cases.
- Java proficiency: Strong Java skills, including a working understanding of the JVM. FusionAuth's core application is Java-based.
- Database depth: Experience tuning PostgreSQL (or a comparable relational database) at scale.
- Deployment architecture: Experience designing or supporting software deployed across self-hosted, or dedicated cloud environments, including backward compatibility and upgrade paths.
- AI tooling and practices: Uses AI development tools (for example, Claude Code or Codex) as part of everyday workflow, and has experience helping a team adopt AI-augmented development practices. FusionAuth is actively standardizing on AI tooling across the SDLC, and this role helps drive that adoption.
- Pragmatism: Appreciates first-principles thinking, but knows when to stop theorizing and start building.
- Work location: FusionAuth is headquartered in the Denver metro area, and we value the collaboration that comes from working together in person. We strongly prefer candidates local to the Denver metro who can be onsite 1-2 days per week. We are open to candidates in other locations who are willing to travel to our office 2 -3 times per year.
Preferred
- CIAM product experience: Direct experience building or working within a CIAM product or identity platform.
- Emerging standards: Familiarity with emerging identity protocols and standards (FIDO2/passkeys, DPoP, token binding, OAuth 2.x drafts).
- Kubernetes in production: Experience diagnosing container and pod issues and reasoning about K8s networking, storage, and resource limits in production.
- Security and compliance: Familiarity with compliance frameworks (SOC 2, FedRAMP, GDPR) and their impact on architectural decisions.
- Open source and thought leadership: History of contributing to open-source identity or security projects, or publishing technical writing on identity topics.
- Mentoring junior engineers: A track record of ramping early-career engineers to productive, independent contributors.
Compensation
- $190,000 – $230,000 expected base salary range*
*Pursuant to various state laws, we must display the pay range for this job. Since we are willing to hire within a broad spectrum of qualifications, this range is broad. The expected base salary may be adjusted based on individual qualifications, role, level and location.
Onsite Perks & Campus Benefits
When you join FusionAuth’s Denver team, you’ll enjoy a modern campus experience designed for productivity, wellness, and community:
- Newly upgraded amenity spaces including a sleek tenant lounge and café with booth seating and collaborative workspaces.
- Access to a fitness studio, showers, lockers, and secure bike storage.
- Regularly stocked in-suite kitchen with a variety of snacks and beverages to keep you fueled throughout the day.
- Onsite café offering chef-driven menus with fresh, locally sourced, organic, and non-GMO options to suit diverse dietary needs. Easy ordering via app.
- 3-acres of green space, including communal parks and picnic areas, connected to miles of jogging, biking, and recreation trails.
- Yoga in the circle and wellness programs to enhance work-life balance.
- Dedicated outdoor workspaces and patio gathering areas.
- Ample on-site parking, easy freeway access, and high-speed fiber internet.
- Sustainability-minded campus and community initiatives, including support for regenerative agriculture programs.
Enjoy a high-tech business environment that inspires creativity and energizes your workday—all just minutes from the heart of Denver and Boulder.
Benefits
For full-time team members, we offer:
- Comprehensive health insurance including medical, dental, and vision coverage, with the company covering the majority of your medical premiums to keep your costs low
- Fully employer-paid High Deductible Health Plan (HDHP) option paired with a Health Savings Account (HSA), including employer contributions
- Basic life insurance and short- and long-term disability coverage fully paid by the company for essential financial protection
- Voluntary life insurance options to provide additional financial protection for you and your loved ones
- Healthcare and Dependent Care Flexible Spending Accounts (FSAs) to save pre-tax dollars on eligible expenses
- 401(k) plan with company match to help you save for retirement
- Generous paid time off (PTO) plus paid company holidays to support work-life balance
- Employee Assistance Program (EAP) offering confidential counseling and support services
- Professional growth and development opportunities to boost your career journey
- Eligibility for performance-based bonuses or variable compensation tied to individual, team, or company results
Important Details
- Application Submission: We value authentic, thoughtful responses. Copy/pasted or AI-generated answers to application questions that don’t reflect your own experience may disqualify your application.
- In-Person Interview: Please be aware that participating in an in-person interview is encouraged so we can get to know each other. FusionAuth reimburses reasonable travel and lodging expenses associated with onsite interviews.
- Work Authorization: Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or assume sponsorship of an employment Visa at this time.
If you are passionate about technology that solves real-world customer problems, and want to join a company that is moving the industry forward, FusionAuth is a perfect fit for you!
Equal Employment Opportunity
FusionAuth provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
E-Verify | Right to Work
Recruiters
FusionAuth does not accept unsolicited resumes from recruiters or employment agencies. In the absence of a signed agreement, we reserve the right to pursue and hire candidates without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted directly to hiring managers, are deemed to be the property of FusionAuth.