Senior Software Engineer - Identity, Tesla Cloud Platform

Senior Software Engineer - Identity, Tesla Cloud Platform

Tesla

Grünheide (Mark), Germany

What You’ll Do

  • Design and build IAM policies, role-based access control (RBAC), and permission models that govern access across all TCP managed services.
  • Implement fine-grained, resource-level authorization across compute, storage, Kubernetes, DNS, KMS, and bare metal services.
  • Build and enforce tenant isolation boundaries, ensuring strict separation between organizational units and projects.
  • Own TCP's Single Sign-On (SSO) integration, supporting SAML, OIDC, and enterprise identity providers.
  • Build and maintain authentication flows across the TCP portal, API gateway, and service-to-service communication.
  • Build and evolve the group management system - creation, membership, nesting, and synchronization with enterprise directory services.
  • Drive the evolution toward zero trust architecture within TCP, including service-to-service authentication (mTLS, JWT, API keys).
  • Integrate with HashiCorp Vault for secrets management, certificate issuance, and dynamic credentials.
  • Build audit logging and access trail capabilities for compliance and security review.
  • Partner with networking, datacenter operations, compliance, and security teams to align TCP's identity model with Tesla's broader security posture.

What You’ll Bring

  • 3+ years of professional experience in software development with Go, Python, Java, or similar backend languages.
  • Experience designing and building IAM, RBAC, or authorization systems for multi-tenant platforms.
  • Strong understanding of authentication protocols: OAuth 2.0, OIDC, SAML, JWT.
  • Experience with directory services (Active Directory, LDAP) and identity federation.
  • Solid understanding of cryptographic concepts - TLS/mTLS, certificate management, token signing.
  • Experience with relational databases (PostgreSQL) and API design (REST, gRPC).
  • Understanding of distributed systems and how authorization decisions propagate across service boundaries.
  • Familiarity with HashiCorp Vault or similar secrets management platforms is a plus.
  • Frontend experience (React, Next.js) for building identity management interfaces is a plus.

Don't forget to mention EuroTechJobs when applying.

Share this Job

More Job Searches

Germany      Developer      Java Developer      On-site      Python Developer      Tesla     

EuroTechJobs Logo

© EuroJobsites 2026