ScoutGet started
XsollaTechnology

Middle/Senior Backend Engineer

SeniorRemote · RussiaFull time
The role
About the project Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It is not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products, including Xsolla Wallet, Xsolla App, Web Shops, and partner integrations. Tech Stack: * Language: Go (idiomatic code, concurrency patterns, performance profiling) * Databases: PostgreSQL (schema design, query optimization, migrations at scale), MySQL, Redis * Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency * Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ * Infrastructure: Docker, Kubernetes, Nginx * Identity Stack: Ory ecosystem (Hydra for OAuth2/OIDC, Kratos for identity management) with a custom Auth API orchestrator and plugin architecture * Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn * Web Security: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management * Architecture: Microservices, High Availability design Key Technical Challenges: * Building Web2 & Web3 authentication flows (OTP, passkeys, biometrics, wallet-based login) * Implementing custom auth methods without forking Ory * SSO without third-party cookies * Zero-downtime migration from legacy Xsolla Login with bidirectional identity sync * Geo-distributed data residency via CockroachDB * High availability and scaling for millions of concurrent users * SDK development and integration with multiple Xsolla products Responsibilities * Develop and maintain backend services for the Xsolla ID platform using Go * Design and implement OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token introspection, and refresh strategies * Work with the Ory ecosystem (Hydra, Kratos) and extend the custom Auth API orchestrator and plugin architecture * Apply web security fundamentals: cookie security, CSRF/XSS protection, secure token storage, TLS, secure session management * Optimize database queries and ensure high performance under heavy loads (PostgreSQL, MySQL, Redis, CockroachDB) * Build and maintain microservices architecture with focus on reliability and scalability * Contribute to zero-downtime migration from legacy Xsolla Login with bidirectional identity sync * Write clean, well-tested code with comprehensive unit and integration test coverage * Collaborate with frontend engineers on SDK and widget integration * Participate in code reviews and contribute to technical documentation * Support production systems and troubleshoot issues across the authentication stack QUALIFICATIONS Required: * 2+ years of commercial experience with Go * Strong understanding of PostgreSQL and Redis (query optimization, indexing strategies) * Working knowledge of OAuth 2.0 / OIDC auth flows (authorization code, client credentials) or strong motivation to learn * Understanding of web security fundamentals: CSRF, XSS, cookie security, TLS * Experience with Docker and docker-compose * Proficiency with Git and collaborative development workflows * Understanding of Nginx and web server configuration * Solid experience writing unit tests and maintaining high code quality * Good English reading skills (technical documentation) Preferred: * Understanding of microservices architecture and distributed systems trade-offs (consistency, availability, failure modes) * Experience with REST API design and documentation (Swagger/OpenAPI) * Hands-on experience with CI/CD pipelines * Familiarity with the Ory ecosystem (Hydra, Kratos, Keto) or similar identity management frameworks * Knowledge of PKCE, client credentials, device flow, token introspection, and refresh-token strategies * Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling) * Experience with NATS, Kafka, or RabbitMQ for event-driven / message-streaming patterns * Familiarity with Jira for project management * Understanding of Kubernetes and container orchestration * Familiarity with compliance requirements relevant to IAM: SOC 2, ISO 27001, GDPR data minimization, audit logging * Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work