Software Engineer - Auth0/AuthZ (Java)
About the role
We are a global team of innovators and pioneers dedicated to shaping the future of observability. At New Relic, we build an intelligent platform that empowers companies to thrive in an AI-first world by giving them unparalleled insight into their complex systems. As we continue to expand our global footprint, we're looking for passionate people to join our mission. If you're ready to help the world's best companies optimize their digital applications, we invite you to explore a career with us!
Your opportunity
New Relic's whole platform runs on an assumption: by the time a request reaches any service, someone has already answered two questions, who is this, and what are they allowed to do. The Access & Governance Platform team builds and runs the systems that answer both. On the authentication side, that means login, session and token management, and enterprise SSO integrations (SAML, OIDC, OAuth2) for customers who need to plug New Relic into their own identity provider. On the authorization side, it means the roles, capabilities, and grants model that every other team at New Relic checks against before letting a user touch anything.
Because these services sit underneath everything else, the problems here are rarely simple CRUD. You're modeling access at the scale of every account and organization on the platform, keeping login working through traffic spikes and identity-provider outages, and building the self-service tooling other engineering teams use to adopt fine-grained authorization for their own services. You'll also carry on-call for these systems, because when they have a bad day, so does the rest of New Relic.
What you'll do
- Build and operate authentication services, including SSO (SAML, OIDC), OAuth2/OIDC token issuance, session and token lifecycle, SCIM-based user provisioning, and bot/fraud defense, for both direct login and enterprise SSO customers.
- Build APIs and internal tooling that let other engineering teams and internal stakeholders manage and troubleshoot user data and access controls.
- Collaborate closely with product management, product design, and your engineering team to solve complex use cases.
- Participate in the team's on-call/hero rotation: triage production incidents, investigate access, authentication, and authorization issues reported by other teams and customers, and turn resolutions into runbooks.
- Investigate and fix reliability, data-integrity, and security issues in production systems, including routine dependency and container vulnerability remediation.
This role requires
- 1+ years of experience building and shipping reliable software services.
- Expertise in backend languages; our services span Ruby, Java, and others, with Ruby or Java preferred.
- Experience working with data models and managing data at scale, including comfort writing and reasoning about SQL against relational databases.
- Strong collaboration and communication skills, especially explaining technical tradeoffs to non-technical stakeholders.
Bonus points if you have
- Experience with Identity and Access Management protocols (SCIM, OAuth2, SAML, or OIDC).
- Experience with GraphQL APIs.
- Experience with observability tools and platforms.
- Experience working in the public cloud (AWS, Azure, and/or GCP).
- Experience with container technologies such as Kubernetes and Docker.
Please note that visa sponsorship is not available for this position.
#LI-Gk1 #LI-Remote
The pay range below represents a reasonable estimate of the salary for the listed position. This role is eligible for a corporate bonus plan. Pay within this range varies by work location and may also depend on job-related factors such as an applicant’s skills, qualifications, and experience.
New Relic provides a variety of benefits for this role, including healthcare, dental, vision, parental leave and planning, and mental health benefits, a 401(k) plan and match, flex time-off, 11 paid holidays, volunteer time-off, and other competitive benefits designed to improve the lives of our employees.
Estimated Base Pay Range$114,000—$142,000 USDFostering a diverse, welcoming and inclusive environment is important to us. We work hard to make everyone feel comfortable bringing their best, most authentic selves to work every day. We celebrate our talented Relics’ different backgrounds and abilities, and recognize the different paths they took to reach us – including nontraditional ones. Their experiences and perspectives inspire us to make our products and company the best they can be. We’re looking for people who feel connected to our mission and values, not just candidates who check off all the boxes.
If you require a reasonable accommodation to complete any part of the application or recruiting process, please reach out to resume@newrelic.com.
We believe in empowering all Relics to achieve professional and business success through a flexible workforce model. This model allows us to work in a variety of workplaces that best support our success, including fully office-based, fully remote, or hybrid.
Our hiring process
In compliance with applicable law, all persons hired will be required to verify identity and eligibility to work and to complete employment eligibility verification. Note: Our stewardship of the data of thousands of customers means that a criminal background check is required to join New Relic.
We will consider qualified applicants with arrest and conviction records based on individual circumstances and in accordance with applicable law including, but not limited to, the San Francisco Fair Chance Ordinance.
Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. New Relic does not accept unsolicited headhunter and agency resumes, and will not pay fees to any third-party agency or company that does not have a signed agreement with New Relic.
New Relic develops and distributes encryption software and technology that complies with U.S. export controls and licensing requirements. Certain New Relic roles require candidates to pass an export compliance assessment as a condition of employment in any global location. If relevant, we will provide more information later in the application process.
Candidates are evaluated based on qualifications, regardless of race, religion, ethnicity, national origin, sex, sexual orientation, gender expression or identity, age, disability, neurodiversity, veteran or marital status, political viewpoint, or other legally protected characteristics.
Review our Applicant Privacy Notice at https://newrelic.com/termsandconditions/applicant-privacy-policy