Team Lead Backend Engineer
SeniorRemote · RussiaFull time
About the project
Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It's not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products.
Products & Integrations:
* Xsolla ID Platform — Core IAM service with Web2 and Web3 authentication
* Authentication Widget — Universal login UI supporting multiple auth methods
* SDKs — Client libraries for seamless integration across platforms
* Migration Services — Zero-downtime migration from legacy Xsolla Login
Auth Methods Supported:
* Email + Password with secure hashing
* One-time passwords (OTP) via email and SMS
* Social login (Google, Apple, Steam, Discord, etc.)
* WebAuthn (passkeys, biometrics)
* Web3 wallet authentication
* Single Sign-On (SSO) across Xsolla products
Tech Stack:
* Language: Go (idiomatic code, concurrency patterns, performance profiling)
* Databases: MySQL, PostgreSQL (schema design, query optimization, migrations at scale), Redis
* Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency
* Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ
* Identity Stack: Ory ecosystem (Hydra, Kratos, Keto) with a custom Auth API orchestrator and plugin architecture
* Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn, JWT
* Web Security: cookie security, CSRF, XSS, secure token storage, TLS, secure session management, bcrypt, PKCE
* Infrastructure: Docker, Kubernetes, Nginx
Key Architectural Problems:
* Custom auth methods without forking Ory
* SSO without third-party cookies
* Zero-downtime migration with bidirectional identity sync
* Geo-distributed data residency via CockroachDB
Team Scope:
* Team of 4-6 backend engineers (target: up to 8)
* Ownership of core IAM services and authentication flows
* Collaboration with Frontend (widget/SDK), DevOps, and Security teams
Responsibilities
Technical Leadership (60%):
* Own the technical strategy and architecture of the Xsolla ID IAM platform, covering authentication, authorization, and session management at scale
* Design and evolve OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token lifecycle (introspection, refresh strategies), and security primitives to meet product and compliance requirements
* Lead decisions on the Ory ecosystem (Hydra, Kratos, Keto): extending APIs, custom auth methods without forking Ory, and the custom Auth API orchestrator / plugin architecture
* Own web security fundamentals across the platform: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management
* Drive the CockroachDB strategy for geo-distributed data residency (multi-region deployments, clock skew handling, survivability trade-offs)
* Review complex security-critical code and ensure best practices
* Drive migration strategy from legacy Xsolla Login with zero downtime and bidirectional identity sync
* Identify systemic risks and performance bottlenecks; lead initiatives to resolve them before they become incidents
* Make key decisions on system design, security architecture, and technology choices
* Maintain hands-on contribution to critical security features
People Management (40%):
* Lead and mentor a team of up to 8 backend engineers
* Conduct regular 1:1s, performance reviews, and career development conversations
* Hire and onboard new team members with IAM/security expertise
* Foster a security-first culture with focus on code quality
* Manage team workload and delivery commitments
Delivery & Stakeholder Management:
* Own team's delivery predictability for this mission-critical platform
* Collaborate with Product to define IAM roadmap and priorities
* Coordinate with dependent product teams (Xsolla Pay, Wallet, App, Backpack)
* Report on security posture, platform reliability, and team progress
QUALIFICATIONS
Required:
Technical Skills:
* 5+ years of commercial experience with Go (or 7+ years with other backend languages with Go proficiency): idiomatic code, concurrency patterns, performance profiling
* Deep expertise in OAuth 2.0 / OIDC and IAM systems:
* Authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies
* Understanding of JWT, token refresh flows, session management
* Knowledge of password hashing (bcrypt, Argon2) and secure storage
* Web security fundamentals: cookie security, CSRF, XSS, TLS, secure session management
* Strong knowledge of MySQL/PostgreSQL (schema design, query optimization, migrations at scale) and Redis
* Experience with distributed systems and their trade-offs (consistency, availability, failure modes)
* Experience with high-availability system design (99.9%+ uptime requirements)
* Understanding of security best practices and common vulnerabilities (OWASP)
* Experience with Docker, Kubernetes, and production deployments
Leadership Skills:
* 2+ years of experience leading engineering teams
* Track record of delivering mission-critical infrastructure
* Proven ability to lead multi-quarter technical initiatives across teams and influence architecture beyond the immediate team
* Experience with security-focused code review processes
* Strong written and verbal communication — RFCs and design docs that people actually read
* Ability to balance security requirements with delivery timelines
Preferred:
* Hands-on experience with the Ory ecosystem (Hydra, Kratos, Keto) — operating it in production or building on top of its APIs
* Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling, survivability trade-offs)
* Experience with NATS or Kafka — event-driven patterns, consumer groups, at-least-once delivery
* Experience with WebAuthn/FIDO2 passkey implementations
* Knowledge of Web3 authentication (wallet signatures, EIP-4361)
* Experience building or integrating with SCIM, SAML, or enterprise SSO (LDAP / Active Directory)
* Background in fintech, payments, or gaming identity systems
* Familiarity with compliance requirements relevant to IAM: SOC 2, ISO 27001, PCI DSS, GDPR data minimization, audit logging
* Contributions to open-source security or identity projects
* Background in platform or infrastructure engineering — building systems other engineers build on top of
* Experience with large-scale user migrations (millions of accounts)
* Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work
WHAT SUCCESS LOOKS LIKE
First 3 months:
* Deep understanding of Xsolla ID architecture and security requirements
* Established team rituals and 1:1 cadence
* Delivered improvements to at least one critical authentication flow
First 6 months:
* Team consistently delivers secure, well-tested code
* Progress on migration from legacy Xsolla Login
* Improved platform reliability metrics
First year:
* Xsolla ID successfully serving multiple B2C products
* Team grown and developed with clear succession planning
* Platform achieving target availability (99.9%+) and security posture
