ScoutGet started
XsollaTechnology

Team Lead Backend Engineer

SeniorRemote · RussiaFull time
The role
About the project Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It's not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products. Products & Integrations: * Xsolla ID Platform — Core IAM service with Web2 and Web3 authentication * Authentication Widget — Universal login UI supporting multiple auth methods * SDKs — Client libraries for seamless integration across platforms * Migration Services — Zero-downtime migration from legacy Xsolla Login Auth Methods Supported: * Email + Password with secure hashing * One-time passwords (OTP) via email and SMS * Social login (Google, Apple, Steam, Discord, etc.) * WebAuthn (passkeys, biometrics) * Web3 wallet authentication * Single Sign-On (SSO) across Xsolla products Tech Stack: * Language: Go (idiomatic code, concurrency patterns, performance profiling) * Databases: MySQL, PostgreSQL (schema design, query optimization, migrations at scale), Redis * Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency * Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ * Identity Stack: Ory ecosystem (Hydra, Kratos, Keto) with a custom Auth API orchestrator and plugin architecture * Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn, JWT * Web Security: cookie security, CSRF, XSS, secure token storage, TLS, secure session management, bcrypt, PKCE * Infrastructure: Docker, Kubernetes, Nginx Key Architectural Problems: * Custom auth methods without forking Ory * SSO without third-party cookies * Zero-downtime migration with bidirectional identity sync * Geo-distributed data residency via CockroachDB Team Scope: * Team of 4-6 backend engineers (target: up to 8) * Ownership of core IAM services and authentication flows * Collaboration with Frontend (widget/SDK), DevOps, and Security teams Responsibilities Technical Leadership (60%): * Own the technical strategy and architecture of the Xsolla ID IAM platform, covering authentication, authorization, and session management at scale * Design and evolve OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token lifecycle (introspection, refresh strategies), and security primitives to meet product and compliance requirements * Lead decisions on the Ory ecosystem (Hydra, Kratos, Keto): extending APIs, custom auth methods without forking Ory, and the custom Auth API orchestrator / plugin architecture * Own web security fundamentals across the platform: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management * Drive the CockroachDB strategy for geo-distributed data residency (multi-region deployments, clock skew handling, survivability trade-offs) * Review complex security-critical code and ensure best practices * Drive migration strategy from legacy Xsolla Login with zero downtime and bidirectional identity sync * Identify systemic risks and performance bottlenecks; lead initiatives to resolve them before they become incidents * Make key decisions on system design, security architecture, and technology choices * Maintain hands-on contribution to critical security features People Management (40%): * Lead and mentor a team of up to 8 backend engineers * Conduct regular 1:1s, performance reviews, and career development conversations * Hire and onboard new team members with IAM/security expertise * Foster a security-first culture with focus on code quality * Manage team workload and delivery commitments Delivery & Stakeholder Management: * Own team's delivery predictability for this mission-critical platform * Collaborate with Product to define IAM roadmap and priorities * Coordinate with dependent product teams (Xsolla Pay, Wallet, App, Backpack) * Report on security posture, platform reliability, and team progress QUALIFICATIONS Required: Technical Skills: * 5+ years of commercial experience with Go (or 7+ years with other backend languages with Go proficiency): idiomatic code, concurrency patterns, performance profiling * Deep expertise in OAuth 2.0 / OIDC and IAM systems: * Authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies * Understanding of JWT, token refresh flows, session management * Knowledge of password hashing (bcrypt, Argon2) and secure storage * Web security fundamentals: cookie security, CSRF, XSS, TLS, secure session management * Strong knowledge of MySQL/PostgreSQL (schema design, query optimization, migrations at scale) and Redis * Experience with distributed systems and their trade-offs (consistency, availability, failure modes) * Experience with high-availability system design (99.9%+ uptime requirements) * Understanding of security best practices and common vulnerabilities (OWASP) * Experience with Docker, Kubernetes, and production deployments Leadership Skills: * 2+ years of experience leading engineering teams * Track record of delivering mission-critical infrastructure * Proven ability to lead multi-quarter technical initiatives across teams and influence architecture beyond the immediate team * Experience with security-focused code review processes * Strong written and verbal communication — RFCs and design docs that people actually read * Ability to balance security requirements with delivery timelines Preferred: * Hands-on experience with the Ory ecosystem (Hydra, Kratos, Keto) — operating it in production or building on top of its APIs * Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling, survivability trade-offs) * Experience with NATS or Kafka — event-driven patterns, consumer groups, at-least-once delivery * Experience with WebAuthn/FIDO2 passkey implementations * Knowledge of Web3 authentication (wallet signatures, EIP-4361) * Experience building or integrating with SCIM, SAML, or enterprise SSO (LDAP / Active Directory) * Background in fintech, payments, or gaming identity systems * Familiarity with compliance requirements relevant to IAM: SOC 2, ISO 27001, PCI DSS, GDPR data minimization, audit logging * Contributions to open-source security or identity projects * Background in platform or infrastructure engineering — building systems other engineers build on top of * Experience with large-scale user migrations (millions of accounts) * Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work WHAT SUCCESS LOOKS LIKE First 3 months: * Deep understanding of Xsolla ID architecture and security requirements * Established team rituals and 1:1 cadence * Delivered improvements to at least one critical authentication flow First 6 months: * Team consistently delivers secure, well-tested code * Progress on migration from legacy Xsolla Login * Improved platform reliability metrics First year: * Xsolla ID successfully serving multiple B2C products * Team grown and developed with clear succession planning * Platform achieving target availability (99.9%+) and security posture