Staff Software Engineer — Identity & Access Management

Xsolla is a global video game commerce company providing tools and services to launch, monetize, and scale games. Its offerings include payments, web shops, publishing, distribution, LiveOps, anti-fraud, subscriptions, SDKs, and creator solutions for developers, publishers, payment providers, creators, and other gaming businesses.

Maintainer signals as of 8/23/2026

Distributed
About Xsolla (USA), Inc.

Xsolla operates as a global merchant of record and video game commerce platform serving developers, publishers, resellers, payment providers, creators, and retailers. It provides payment processing across more than 200 countries and regions, 1,000+ payment methods, and 130+ currencies, alongside tax management, compliance, fraud prevention, refunds, dispute management, and end-user support. Its product portfolio includes Web Shop, Publishing Suite, Payments, Xsolla Pay, Mobile Buy Button, SDKs, Subscriptions, game distribution, Partner Network, Offerwall, LiveOps, Anti-Fraud, Login, Site Builder, cloud gaming, and related gaming commerce tools.

View jobs by Xsolla (USA), Inc.

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will own the technical strategy and architecture for authentication, authorization, and session management at scale. You will design and evolve OAuth 2.0 and OIDC flows, token lifecycles, and security primitives. You will drive cross-team technical decisions, identify systemic risks and performance bottlenecks, define engineering standards, and serve as an escalation point for complex IAM production issues.

Requirements

  • Deep understanding of OAuth 2.0, OIDC, and related authentication flows, including authorization code with PKCE, client credentials, device flow, token introspection, and refresh strategies.
  • Knowledge of cookie security, CSRF, XSS, token storage, TLS, and secure session management.
  • Experience designing or operating production-grade IAM or authentication systems.
  • Experience in the video game industry or building or operating platforms for game developers, publishers, or players.
  • Strong Go engineering skills, including idiomatic code, concurrency patterns, and performance profiling.
  • Experience with distributed systems and their trade-offs.
  • PostgreSQL schema design, query optimization, and migrations at scale.
  • Experience deploying, operating, and debugging services in Kubernetes.
  • Experience with Kafka or NATS and event-driven patterns, consumer groups, and at-least-once delivery.
  • Git and modern CI/CD practices.
  • Ability to lead multi-quarter technical initiatives across teams.
  • Experience influencing architecture and standards beyond an immediate team.
  • Strong written and verbal communication, including RFCs and design documentation.

Responsibilities

  • Own the technical strategy and architecture of the IAM platform, including authentication, authorization, and session management at scale.
  • Design and evolve OAuth 2.0 and OIDC flows, token lifecycle, and security primitives to meet product and compliance requirements.
  • Drive decisions on protocol design, data modeling, and platform reliability, and build buy-in across engineering and security teams.
  • Identify systemic risks and performance bottlenecks and lead initiatives to resolve them before they become incidents.
  • Define engineering standards, review critical code and designs, and create leverage through documentation, tooling, and mentorship.
  • Collaborate with product, security, and infrastructure teams to align on the roadmap and translate business needs into technical plans.
  • Serve as the escalation point for complex production issues in the IAM domain.