Description
About the project
- Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It is not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products, including Xsolla Wallet, Xsolla App, Web Shops, and partner integrations. Tech Stack: Language: Go (idiomatic code, concurrency patterns, performance profiling)
- Databases: PostgreSQL (schema design, query optimization, migrations at scale), MySQL, Redis
- Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency
- Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ
- Infrastructure: Docker, Kubernetes, Nginx
- Identity Stack: Ory ecosystem (Hydra for OAuth2/OIDC, Kratos for identity management) with a custom Auth API orchestrator and plugin architecture
- Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn
- Web Security: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management
- Architecture: Microservices, High Availability design
- Key Technical Challenges: Building Web2 & Web3 authentication flows (OTP, passkeys, biometrics, wallet-based login)
- Implementing custom auth methods without forking Ory
- SSO without third-party cookies
- Zero-downtime migration from legacy Xsolla Login with bidirectional identity sync
- Geo-distributed data residency via CockroachDB
- High availability and scaling for millions of concurrent users
- SDK development and integration with multiple Xsolla products
Responsibilities
- Develop and maintain backend services for the Xsolla ID platform using Go
- Design and implement OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token introspection, and refresh strategies
- Work with the Ory ecosystem (Hydra, Kratos) and extend the custom Auth API orchestrator and plugin architecture
- Apply web security fundamentals: cookie security, CSRF/XSS protection, secure token storage, TLS, secure session management
- Optimize database queries and ensure high performance under heavy loads (PostgreSQL, MySQL, Redis, CockroachDB)
- Build and maintain microservices architecture with focus on reliability and scalability
- Contribute to zero-downtime migration from legacy Xsolla Login with bidirectional identity sync
- Write clean, well-tested code with comprehensive unit and integration test coverage
- Collaborate with frontend engineers on SDK and widget integration
- Participate in code reviews and contribute to technical documentation
- Support production systems and troubleshoot issues across the authentication stack
- QUALIFICATIONS Required: 2+ years of commercial experience with Go
- Strong understanding of PostgreSQL and Redis (query optimization, indexing strategies)
- Working knowledge of OAuth 2.0 / OIDC auth flows (authorization code, client credentials) or strong motivation to learn
- Understanding of web security fundamentals : CSRF, XSS, cookie security, TLS
- Experience with Docker and docker-compose
- Proficiency with Git and collaborative development workflows
- Understanding of Nginx and web server configuration
- Solid experience writing unit tests and maintaining high code quality
- Good English reading skills (technical documentation)
- Preferred: Understanding of microservices architecture and distributed systems trade-offs (consistency, availability, failure modes)
- Experience with REST API design and documentation ( Swagger/OpenAPI )
- Hands-on experience with CI/CD pipelines
- Familiarity with the Ory ecosystem (Hydra, Kratos, Keto) or similar identity management frameworks
- Knowledge of PKCE , client credentials, device flow, token introspection, and refresh-token strategies
- Experience with CockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling)
- Experience with NATS , Kafka , or RabbitMQ for event-driven / message-streaming patterns
- Familiarity with Jira for project management
- Understanding of Kubernetes and container orchestration
- Familiarity with compliance requirements relevant to IAM: SOC 2 , ISO 27001 , GDPR data minimization, audit logging
- Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work
Employer contacts (email/phone/telegram) are hidden from the public preview —
send your CV, and we will connect you directly.