Staff Backend Engineer - Users

1 month ago
Full-time
Lead
Software Development
HighLevel

HighLevel

HighLevel provides an all-in-one sales and marketing platform that agencies can white label and resell, offering tools and resources designed to help businesses consolidate their marketing efforts and achieve their growth objectives.

Internet Software & Services
251-1K
Founded 2018
$60M raised

Description

  • Design and evolve secure multi-tenant architectures (Agency → Account → App or equivalent hierarchy) to support 100k+ agencies.
  • Define and enforce tenant isolation guarantees at the data, API, and infrastructure levels.
  • Build, review, and evolve authorization models (RBAC, ABAC, or hybrid) and map scopes → permissions → resources consistently.
  • Own token systems including API keys, OAuth flows, JWTs, scoped tokens, rotation, and expiry to prevent over-scoped tokens and privilege escalation.
  • Design fine-grained scopes for internal APIs, public APIs, and partner integrations.
  • Lead security-critical backend designs covering authZ boundaries, impersonation, and auditability.
  • Set patterns and standards for secure-by-default APIs used by internal and external teams.
  • Partner with Infrastructure and Security teams on secrets management, key rotation, rate limiting & abuse prevention, and compliance readiness (SOC2-style thinking).
  • Raise the security bar across engineering through code reviews, RFCs, mentoring, and cross-team collaboration.

Requirements

  • 8+ years of backend engineering experience.
  • Proven experience building secure, multi-tenant SaaS platforms.
  • Deep understanding of authorization models (RBAC, ABAC) and hybrid approaches.
  • Experience with OAuth2, JWT, API key systems, token scoping, rotation, and expiry.
  • Strong system design skills for long-lived, large-scale platforms.
  • Experience with threat modeling and making security tradeoffs.
  • Comfort owning ambiguous, high-impact technical areas and driving cross-team alignment.
  • Nice to have: experience designing platforms used by multiple internal teams.
  • Nice to have: experience with security reviews, incident learnings, or compliance exposure.
  • Nice to have: experience with large-scale auth/identity migrations or background in developer platforms/core infrastructure teams.

Benefits

  • Remote-first work environment (role listed as Remote / India).
  • Opportunity to work on a very large-scale platform processing billions of API hits and message events daily.
  • Membership in a global team (1,500+ team members across 15+ countries) and collaborative culture.
  • High-impact role with ownership over core security and identity primitives used across the product and customers.
  • Chance to influence platform-wide security standards and mentor other engineers.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Backend Engineer - Hosting Services

Airbnb 5K-10K Hotels, Restaurants & Leisure

Staff Software Engineer, Hosting Services at Airbnb leading the design and delivery of scalable hosting and co-hosting systems to elevate the product from regional to global across distributed engineering teams.

Microservices System Design
14 hours, 44 minutes ago

Senior Software Engineer - Java, Spring boot, Microservices

Ivanti 1K-5K Internet Software & Services

Senior Software Engineer at Ivanti working on a globally distributed team to deliver cloud-native device, application, and content security products by driving product releases and ensuring technical and architectural excellence.

Agile Android API Gateway AWS Azure CI/CD Docker Elasticsearch iOS Java Kafka Kubernetes Linux Microservices OAuth SAML Scrum Spring Spring Boot
1 month ago

Staff Backend Developer, Unity Ads / Développeur Backend Principal, Unity Ads

Unity 5K-10K Internet Software & Services

Staff Backend Developer at Unity Ads working on high-scale, low-latency distributed systems to ensure reliable, performant ad delivery and enable new monetization features for game developers worldwide.

Go Kubernetes Microservices MySQL Terraform
1 month ago

Senior Node.js Engineer - APIs & Integrations at Scale-English required

DaCodes 51-250 Internet Software & Services

Senior Integration Engineer at DaCodes collaborating with cross-functional teams to design, build, and maintain API-based integrations between SaaS platforms, third-party applications, and ERPs to ensure reliable, secure data synchronization and integration workflows.

AWS Azure CI/CD Firebase GraphQL JavaScript JWT NetSuite Node.js OAuth PostgreSQL REST API SAML SAP Serverless SOAP SQL
1 month ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers