Middle/Senior Backend Engineer
SeniorRemote · RussiaFull time
About the project
Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It is not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products, including Xsolla Wallet, Xsolla App, Web Shops, and partner integrations.
Tech Stack:
* Language: Go (idiomatic code, concurrency patterns, performance profiling)
* Databases: PostgreSQL (schema design, query optimization, migrations at scale), MySQL, Redis
* Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency
* Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ
* Infrastructure: Docker, Kubernetes, Nginx
* Identity Stack: Ory ecosystem (Hydra for OAuth2/OIDC, Kratos for identity management) with a custom Auth API orchestrator and plugin architecture
* Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn
* Web Security: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management
* Architecture: Microservices, High Availability design
Key Technical Challenges:
* Building Web2 & Web3 authentication flows (OTP, passkeys, biometrics, wallet-based login)
* Implementing custom auth methods without forking Ory
* SSO without third-party cookies
* Zero-downtime migration from legacy Xsolla Login with bidirectional identity sync
* Geo-distributed data residency via CockroachDB
* High availability and scaling for millions of concurrent users
* SDK development and integration with multiple Xsolla products
Responsibilities
* Develop and maintain backend services for the Xsolla ID platform using Go
* Design and implement OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token introspection, and refresh strategies
* Work with the Ory ecosystem (Hydra, Kratos) and extend the custom Auth API orchestrator and plugin architecture
* Apply web security fundamentals: cookie security, CSRF/XSS protection, secure token storage, TLS, secure session management
* Optimize database queries and ensure high performance under heavy loads (PostgreSQL, MySQL, Redis, CockroachDB)
* Build and maintain microservices architecture with focus on reliability and scalability
* Contribute to zero-downtime migration from legacy Xsolla Login with bidirectional identity sync
* Write clean, well-tested code with comprehensive unit and integration test coverage
* Collaborate with frontend engineers on SDK and widget integration
* Participate in code reviews and contribute to technical documentation
* Support production systems and troubleshoot issues across the authentication stack
QUALIFICATIONS
Required:
* 2+ years of commercial experience with Go
* Strong understanding of PostgreSQL and Redis (query optimization, indexing strategies)
* Working knowledge of OAuth 2.0 / OIDC auth flows (authorization code, client credentials) or strong motivation to learn
* Understanding of web security fundamentals: CSRF, XSS, cookie security, TLS
* Experience with Docker and docker-compose
* Proficiency with Git and collaborative development workflows
* Understanding of Nginx and web server configuration
* Solid experience writing unit tests and maintaining high code quality
* Good English reading skills (technical documentation)
Preferred:
* Understanding of microservices architecture and distributed systems trade-offs (consistency, availability, failure modes)
* Experience with REST API design and documentation (Swagger/OpenAPI)
* Hands-on experience with CI/CD pipelines
* Familiarity with the Ory ecosystem (Hydra, Kratos, Keto) or similar identity management frameworks
* Knowledge of PKCE, client credentials, device flow, token introspection, and refresh-token strategies
* Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling)
* Experience with NATS, Kafka, or RabbitMQ for event-driven / message-streaming patterns
* Familiarity with Jira for project management
* Understanding of Kubernetes and container orchestration
* Familiarity with compliance requirements relevant to IAM: SOC 2, ISO 27001, GDPR data minimization, audit logging
* Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work
