Senior Engineer - Identity Platform

 Posted 2 hours ago
     
 $135K - $150K per year
  
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The role serves as the technical anchor for a production Identity and Access Management platform, focusing on Keycloak extension development and modernization of SSO flows. You will manage session architecture, drive major version migrations, and perform deep-diagnosis incident response for the platform.

About DrFirst

For 25 years, DrFirst has empowered providers and patients to achieve better health through intelligent medication management. We improve healthcare workflows and help patients start and stay on therapy with end-to-end solutions that enhance prescription access, affordability, and adherence. Our solutions help 100 million patients a year and are used by more than 420,000 prescribers, 71,000 pharmacies, 270 EHRs and health information systems, and over 2,000 hospitals in the U.S. This is a great opportunity to be a part of a successful Healthcare IT company experiencing significant growth. Here you’ll get to work with some of the smartest and most interesting people around, solving unique and complex challenges in healthcare on a scale matched by few companies. If you get excited about stretching yourself in new ways, developing yourself to your fullest potential, and care about working with smart colleagues, we want to talk to you!

Position Overview

Every day, tens of thousands of clinicians launch into DrFirst applications to prescribe medications and manage patient care, and every launch flows through the identity platform. This role is the technical anchor for a production IAM platform built on Keycloak. It spans custom SPI development in Java, a major-version migration, standards-based modernization of partner SSO, and the session architecture behind a national e-prescribing network.

This is platform ownership, not an integration seat. You will operate a living system with real scale, real incidents, and real migration deadlines, and you will hold the mandate to modernize it. You will regularly be the person who can read a JVM GC log, a Postgres session table, and an OAuth spec in the same afternoon. If you have wanted to be the engineer who both writes the custom grant provider and decides whether it should exist, this is that seat.

What you will work on

  • Keycloak Extension (SPI) Development: Design, build, and refactor custom Keycloak SPIs in Java, including authenticators, grant-type providers, mappers, and just-in-time provisioning. EMR SSO integrations run on custom extension code you will own end to end.
  • Standards-Based Auth Modernization: Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns, including JWT Bearer grants (RFC 7523), Token Exchange (RFC 8693), authorization code plus PKCE, and BFF architectures for web clients, making and defending the architectural calls.
  • Major Version Migration: Drive the Keycloak major-version upgrade, including the shift from external Infinispan session caching with JDBC persistence to persistent user sessions, and validate every downstream integration against the new version.
  • Session and Token Architecture: Own the session lifecycle model across SSO, client, and offline sessions, including idle and max semantics, token lifespans, and refresh rotation, and design per-client TTL policies that balance clinical workflow UX against security posture.
  • Production Ownership and Incident Response: Serve as the deep-diagnosis engineer for JVM tuning (heap, Metaspace, GC), Infinispan cluster behavior, PostgreSQL session-store forensics, and log-driven root-cause analysis on live authentication traffic.
  • Federation and Platform Hygiene: Design integrations with external identity systems (OIDC, SAML, cloud identity platforms), including JWKS trust, key rotation, and audience and issuer validation, and treat realm and client configuration as version-controlled, least-privilege, auditable code.
  • Technical Mentorship: Raise the bar on OAuth and OIDC fluency and secure coding across the team, and represent the platform technical position to application teams and leadership.

Qualifications

Required

  • 6+ years of professional software engineering with strong, production-grade Java, including significant focus on Identity and Access Management.
  • Expert Keycloak experience beyond the admin console, with hands-on SPI and extension development, realm and client architecture for multi-tenant platforms, and running Keycloak (Quarkus) in production on Kubernetes.
  • Deep OAuth 2.0 and OIDC fluency, including authorization code plus PKCE, client credentials, Token Exchange (RFC 8693), JWT Bearer (RFC 7523), and refresh rotation. Working knowledge of SAML 2.0.
  • Session and token architecture depth: stateful SSO sessions versus stateless JWT validation, online versus offline sessions, idle and max semantics, and JWKS validation and key rotation, with the judgment to choose per use case.
  • Hands-on distributed caching and state with Infinispan or comparable technology, including clustering, persistence, expiration, and the failure modes of distributed session state.
  • Production operations skill: JVM performance analysis (GC logs, heap and Metaspace sizing), correlating structured logs, and SQL-level investigation in PostgreSQL against live systems.
  • Security fundamentals and communication: OWASP-aligned secure coding, threat-model thinking around token theft and replay and brute-force protection, MFA and adaptive auth, plus the ability to write a design doc that survives review and translate trade-offs for leadership.

Preferred (Nice to Have)

  • Healthcare integration experience, including EMR and EHR launch patterns, SMART on FHIR, or other regulated-industry SSO work.
  • Identity brokering experience, including Keycloak brokering and first-login flows, or federating with managed platforms such as Google Identity Platform, Azure AD and Entra, or Okta.
  • Observability with Prometheus, Grafana, or ELK, with an eye for authentication anomalies such as login-failure trends, session accumulation, and token-issuance spikes.
  • Cloud security certification (AWS Security Specialty or equivalent) and a Master’s degree in Computer Science or a related field.

Physical Requirements

  • Prolonged periods of sitting at a desk and working on a computer.
  • Ability to operate a computer and other standard office equipment.
  • Ability to communicate clearly through video, phone, and written channels in a remote-first environment.
  • Occasional travel for team or company meetings may be required.

#LI-GF1 #LI-Remote

Benefits

This is a senior individual-contributor engineering role. Compensation is a base salary in the range of $135,000 to $150,000 plus an annual discretionary bonus. 

Salaried employees receive DrFirst’s full standard benefits package, which includes:

  • Medical, dental, and vision coverage.
  • Company-paid life and disability insurance.
  • 401(k) retirement plan with company match.
  • Flexible and generous paid time off, plus company holidays.
  • Remote-first work model with home-office support.
  • Parental leave and family support benefits.
  • Professional development and continuing-education support.
  • Employee wellness and assistance programs.

DrFirst is committed to being a Remote-First company, creating a dynamic and flexible workplace where everyone thrives, no matter where they log in from. Check out our approach to remote work: https://drfirst.com/company/about-us/careers/.

Our recruitment process at DrFirst is straightforward and secure. You will only be contacted by our recruitment team through an official @drfirst.com email address. We will never ask you for payment or sensitive personal information, such as your social security number or banking details, at any stage of the hiring process. Additionally, we will not request that you purchase equipment or accept e-checks or checks for deposit. If you encounter any communications claiming to be from DrFirst that seem suspicious, please contact our recruitment team directly at recruiter@drfirst.com to verify the message’s authenticity. Your security is important to us!

Learn more about our benefits and professional development opportunities: https://drfirst.com/company/about-us/careers/the-perks/.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified