PB✓
PBridge

Full-time jobsthe United States

Software Engineer II - Identity & Access Management

klaviyo · Boston, MA · Full-time

About this role

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you’re a close but not exact match with the description, we hope you’ll still consider applying. Want to learn more about life at Klaviyo? Visit klaviyo.com/careers  to see how we empower creators to own their own destiny.

Team overview

The Core Infrastructure – Identity & Organizations (Core IO) pillar owns the foundational substrate for identity, access, organizations, and platform integrity at Klaviyo. We manage the critical path of the user journey from login, to enforcing permissions, to operating within the correct organization and regional context so that the rest of the platform can move fast and stay secure.

 

Within Core IO, the Identity & Access Management (IAM) team builds and operates Klaviyo’s centralized authentication and authorization platform for both humans and machines. We power login, SSO, MFA, SCIM, internal service auth, and external API auth, and we are in the middle of transforming Klaviyo’s identity stack into a unified, enterprise-grade platform.

Why this role is exciting

• Shape Klaviyo’s identity platform: You’ll help design and build the services that every product team and customer relies on login, sessions, permissions, and secure service APIs are all on your roadmap.

• High-leverage, platform-level impact: Your work will directly affect engineering velocity (auth as a shared service), Enterprise deal wins (SSO/SCIM/RBAC/ReBAC), and Data Residency (region-aware auth flows).

• Deep systems and security learning: You’ll work on distributed systems, modern IdP integration, machine auth, and secure-by-default patterns with strong mentorship and meaningful ownership.

What you’ll do

As a Software Engineer II on the IAM team, you will:

 

• Own features end-to-end across design, implementation, rollout, and observability for core authN/Z capabilities such as login flows, MFA, SSO enhancements, SCIM, sessions, and role/permission enforcement.

• Contribute to auth platform extraction: Help move authentication and authorization paths out of the legacy monolith into dedicated micro services, including token verification, API key services, and internal service auth behind Kong and IdP platform.

• Build and maintain shared SDKs and contracts that let internal teams adopt IAM services quickly (OAuth, machine auth, org-scoped authZ), making “secure by default” the simplest option for new surfaces and agents.

• Collaborate with Organizations & Accounts to support org-scoped identity, multi-account SSO, and flexible org/account models that underpin enterprise experiences and cross-account analytics.

• Partner with Platform Integrity & Protection (PAA) , Security, and Compliance on secu

Tired of applying one by one?

Our Career Success Team finds roles in the United States that fit you, tailors your CV to each, and submits the applications — tracked end to end. You just show up to interviews.

We apply, you interview →