Staff Software Engineer — Identity & Access Management
Xsolla is a video game commerce company that provides a suite of tools and services—including merchant of record payment processing, tax management, fraud prevention, compliance, refunds, dispute management, and end-user support—to help game developers and publishers launch, grow, and monetize their games globally. It serves video game developers, publishers, and studios of all sizes across global and regional markets.
About Xsolla
Xsolla connects the tools, systems, payments, and web shops used by the video games industry, positioning itself as a global merchant of record supporting over 1,000 payment methods and a cumulative audience of 50 million, with transaction fees around 5%. Its services include tax management, fraud monitoring and prevention, global and regional regulatory compliance, refund and dispute management, and end-user payment support. Xsolla's product lineup includes the Xsolla SDK for native in-app payments on side-loaded apps and alternative app stores, a Buy Button enabling link-out purchases from iOS mobile games in the U.S., and Web Shop for building customized, direct-to-consumer game storefronts. The company works with major gaming industry partners and clients such as Mytona, Ubisoft, MARVEL SNAP, and others, and highlights partner success stories, industry events, and its own culture and hiring initiatives on its site.
Skills
About the Role
You will own the technical strategy and architecture for authentication, authorization, and session management at scale. You will design and evolve OAuth 2.0 and OIDC flows, token lifecycles, and security primitives. You will drive cross-team technical decisions, identify systemic risks and performance bottlenecks, define engineering standards, and serve as an escalation point for complex IAM production issues.
Requirements
- Deep understanding of OAuth 2.0, OIDC, and related authentication flows, including authorization code with PKCE, client credentials, device flow, token introspection, and refresh strategies.
- Knowledge of cookie security, CSRF, XSS, token storage, TLS, and secure session management.
- Experience designing or operating production-grade IAM or authentication systems.
- Experience in the video game industry or building or operating platforms for game developers, publishers, or players.
- Strong Go engineering skills, including idiomatic code, concurrency patterns, and performance profiling.
- Experience with distributed systems and their trade-offs.
- PostgreSQL schema design, query optimization, and migrations at scale.
- Experience deploying, operating, and debugging services in Kubernetes.
- Experience with Kafka or NATS and event-driven patterns, consumer groups, and at-least-once delivery.
- Git and modern CI/CD practices.
- Ability to lead multi-quarter technical initiatives across teams.
- Experience influencing architecture and standards beyond an immediate team.
- Strong written and verbal communication, including RFCs and design documentation.
Responsibilities
- Own the technical strategy and architecture of the IAM platform, including authentication, authorization, and session management at scale.
- Design and evolve OAuth 2.0 and OIDC flows, token lifecycle, and security primitives to meet product and compliance requirements.
- Drive decisions on protocol design, data modeling, and platform reliability, and build buy-in across engineering and security teams.
- Identify systemic risks and performance bottlenecks and lead initiatives to resolve them before they become incidents.
- Define engineering standards, review critical code and designs, and create leverage through documentation, tooling, and mentorship.
- Collaborate with product, security, and infrastructure teams to align on the roadmap and translate business needs into technical plans.
- Serve as the escalation point for complex production issues in the IAM domain.
