Staff CIAM Software Engineer

Affirm
Canada
Remote

Who this role is best for

Aimed at mid-level backend engineers with CIAM expertise who can work remotely in Canada and collaborate across B2C and B2B teams.

Best fit for

  • Mid-level engineers with 7+ years of backend experience and deep knowledge of CIAM protocols.
    — “You have 7+ years of experience designing, developing and launching backend systems at scale using languages like Python or Kotlin.
  • Candidates with strong cloud-native development skills and a history of working with AWS.
    — “Experience with cloud-native development, preferably AWS
  • Individuals who have built and maintained CIAM integrations with custom code and hooks.
    — “Hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C using custom code, hooks, and APIs.

Things to consider

  • The role may require occasional in-office work despite being remote-first.
    — “you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office.
  • Candidates must be prepared to work in a highly secure environment with strict access control models.
    — “Strong security fundamentals applied through engineering, including access control models, token handling, encryption, MFA, and privacy by design.

How to stand out

  • Highlight experience with OAuth 2.0, OIDC, SAML, and SCIM in your resume and interview responses.
    — “Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code, ensuring correctness, scalability, and clean integration patterns.
  • Demonstrate your ability to design and operate highly available distributed systems.
    — “You have an extensive track record of developing highly available distributed systems using technologies like AWS, MySQL, Spark and Kubernetes.
  • Showcase your contributions to CI/CD pipeline development and infrastructure automation.
    — “Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines, treating identity as a core platform service.
Pace · SteadyCollaboration · HighAutonomy · MediumDecision Impact · TeamLevel · Mid Level

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • designing and implementing CIAM systems
  • building backend services
  • integrating CIAM platforms
Typical background
backend software engineeringCIAM systems

Skills & requirements

Required

Backend DevelopmentDistributed SystemsCIAM SystemsOauth 2.0OIDCSAMLSCIM

Preferred

Cloud-native DevelopmentInfrastructure As Code

Stack & domain

PythonKotlinAWSMySQLSparkKubernetesOauth 2.0OIDCSAMLSCIMAPI DesignData ModelingLatencyError HandlingObservabilityInfrastructure As CodeTerraformCi/cd Pipelines

About the role

Original posting from Affirm via Greenhouse

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

Affirm is building the next generation of customer identity and authentication. This role is a hands-on engineering position inside Information Security, focused on designing and shipping core CIAM capabilities that protect customers and support growth.

You will build and operate backend services that power registration, login, authorization, and account lifecycle flows across B2C and B2B experiences. You will work closely with partner engineering teams and ensure identity features are delivered with strong security fundamentals, reliability, and operational rigor.

  • What you'll do 

You have 7+ years of experience designing, developing and launching backend systems at scale using languages like Python or Kotlin.

You have an extensive track record of developing highly available distributed systems using technologies like AWS, MySQL, Spark and Kubernetes.

You have strong verbal and written communication skills that support effective collaboration with our global engineering team.

You have experience delivering major features, system components or deprecating existing functionality in a system through the definition of a technical and execution plan. You write high quality code that is easily understood and used by others.

Design, build, and operate core CIAM backend services that support customer registration, authentication, authorization, account lifecycle, and profile management for B2C and B2B platforms.

Implement and extend identity standards such as OAuth 2.0, OIDC, SAML, and SCIM in code, ensuring correctness, scalability, and clean integration patterns.

Develop backend APIs and services in Python and Kotlin that expose identity capabilities to web, mobile, and partner applications.

Integrate CIAM platforms with internal systems, including user data stores, messaging, fraud signals, and downstream customer platforms.

Own secure authentication and account flows end to end, including MFA, step-up authentication, device binding, consent, and adaptive authentication logic.

Automate CIAM infrastructure and deployments using Infrastructure as Code and CI/CD pipelines, treating identity as a core platform service.

Monitor, debug, and optimize CIAM services for performance, resilience, and abuse detection in high-scale environments.

  • What we look for 

Strong experience designing and implementing CIAM systems, with deep, hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM beyond basic configuration.

5+ years of professional backend software engineering experience

Strong production experience in Python or a similar backend language

Experience designing APIs, automation frameworks, and distributed systems

Hands-on experience building and maintaining CI/CD pipelines

Experience with GitHub-based development workflows and Buildkite or similar build systems

Experience with cloud-native development, preferably AWS

Hands-on experience extending and integrating CIAM platforms such as Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C using custom code, hooks, and APIs.

Solid understanding of backend and distributed systems fundamentals, including API design, data modeling, latency, error handling, and observability.

Experience with Infrastructure as Code and automation tools such as Terraform, plus CI/CD pipelines for deploying backend services.

Strong security fundamentals applied through engineering, including access control models, token handling, encryption, MFA, and privacy by design.

Clear communication skills and the ability to work closely with product, frontend, mobile, and security teams while owning backend identity services.

Familiarity with tools such as Cursor and other AI-augmented development environments

Base Pay Grade - P

Equity Grade - USA 7

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

CAN base pay range per year: $181,000 - $241,000

This posting is for an existing vacancy

 #LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include: 

Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents 

Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses

Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge

ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Source: Affirm careers (Greenhouse)

Similar roles