
Team Lead Backend Engineer
- IAM
- WebAuthn
- Passkeys
- MySQL
- PostgreSQL
- Redis
- SQL
- CockroachDB
- NATS
- RabbitMQ
- OIDC
- JWT
- CSRF
- XSS
- TLS
- bcrypt
- Docker
- Kubernetes
- NGINX
- Devops
- System Design
- OWASP
- SCIM
- SAML
- LDAP
- Active Directory
- SOC2
- ISO 27001
- PCI DSS
- GDPR
- Claude
- Copilot
- Cursor
- Health insurance
ABOUT US
Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators. Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.
For more information, visitxsolla.com.
ABOUT YOU
We are looking for aTeam Lead Backend Engineer who ispassionate about building secure, high-availability identity systems at scale to join ourXsolla ID team. The best candidate will be someone who thrives in a fast-paced, highly collaborative, and exceptionally dynamic setting and is excited tolead a team developing the next-generation IAM platform that serves as the foundation for all Xsolla B2C products.
Strongbackend development expertise in Go combined with deep knowledge of authentication and authorization protocols are essential, along with experience inleading engineering teams and building mission-critical identity infrastructure. The ability toarchitect highly available systems while growing and mentoring a high-performing team will be key to your success in this role.
If you're passionate aboutidentity and access management at internet scale and loveleading teams that build foundational platforms impacting millions of users, we would love to hear from you!
About the project
Xsolla ID Platform — Core IAM service with Web2 and Web3 authentication
Authentication Widget — Universal login UI supporting multiple auth methods
SDKs — Client libraries for seamless integration across platforms
Migration Services — Zero-downtime migration from legacy Xsolla Login
Email + Password with secure hashing
One-time passwords (OTP) via email and SMS
Social login (Google, Apple, Steam, Discord, etc.)
WebAuthn (passkeys, biometrics)
Web3 wallet authentication
Single Sign-On (SSO) across Xsolla products
Language: Go (idiomatic code, concurrency patterns, performance profiling)
Databases: MySQL, PostgreSQL (schema design, query optimization, migrations at scale), Redis
Distributed SQL: CockroachDB (multi-region deployments, clock skew handling, survivability trade-offs) for geo-distributed data residency
Message Streaming: NATS, Kafka (event-driven patterns, consumer groups, at-least-once delivery), RabbitMQ
Identity Stack: Ory ecosystem (Hydra, Kratos, Keto) with a custom Auth API orchestrator and plugin architecture
Protocols: OAuth 2.0 / OIDC (authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies), WebAuthn, JWT
Web Security: cookie security, CSRF, XSS, secure token storage, TLS, secure session management, bcrypt, PKCE
Infrastructure: Docker, Kubernetes, Nginx
Custom auth methods without forking Ory
SSO without third-party cookies
Zero-downtime migration with bidirectional identity sync
Geo-distributed data residency via CockroachDB
Team of 4-6 backend engineers (target: up to 8)
Ownership of core IAM services and authentication flows
Collaboration with Frontend (widget/SDK), DevOps, and Security teams
Team Scope:
Key Architectural Problems:
Tech Stack:
Auth Methods Supported:
Xsolla ID is a strategic core service — the centralized identity provider for the entire Xsolla ecosystem. It's not just a login form; it's a comprehensive IAM platform enabling authentication and authorization across all B2C products.
Products & Integrations:
Responsibilities
Own the technical strategy and architecture of the Xsolla ID IAM platform, covering authentication, authorization, and session management at scale
Design and evolve OAuth 2.0 / OIDC flows (authorization code + PKCE, client credentials, device flow), token lifecycle (introspection, refresh strategies), and security primitives to meet product and compliance requirements
Lead decisions on the Ory ecosystem (Hydra, Kratos, Keto): extending APIs, custom auth methods without forking Ory, and the custom Auth API orchestrator / plugin architecture
Own web security fundamentals across the platform: cookie security, CSRF, XSS protection, secure token storage, TLS, secure session management
Drive the CockroachDB strategy for geo-distributed data residency (multi-region deployments, clock skew handling, survivability trade-offs)
Review complex security-critical code and ensure best practices
Drive migration strategy from legacy Xsolla Login with zero downtime and bidirectional identity sync
Identify systemic risks and performance bottlenecks; lead initiatives to resolve them before they become incidents
Make key decisions on system design, security architecture, and technology choices
Maintain hands-on contribution to critical security features
Lead and mentor a team of up to 8 backend engineers
Conduct regular 1:1s, performance reviews, and career development conversations
Hire and onboard new team members with IAM/security expertise
Foster a security-first culture with focus on code quality
Manage team workload and delivery commitments
Own team's delivery predictability for this mission-critical platform
Collaborate with Product to define IAM roadmap and priorities
Coordinate with dependent product teams (Xsolla Pay, Wallet, App, Backpack)
Report on security posture, platform reliability, and team progress
5+ years of commercial experience withGo (or 7+ years with other backend languages with Go proficiency): idiomatic code, concurrency patterns, performance profiling
Deep expertise in OAuth 2.0 / OIDC and IAM systems:
Authorization code + PKCE, client credentials, device flow, token introspection, refresh strategies
Understanding of JWT, token refresh flows, session management
Knowledge of password hashing (bcrypt, Argon2) and secure storage
Web security fundamentals: cookie security, CSRF, XSS, TLS, secure session management
Strong knowledge ofMySQL/PostgreSQL (schema design, query optimization, migrations at scale) andRedis
Experience withdistributed systems and their trade-offs (consistency, availability, failure modes)
Experience withhigh-availability system design (99.9%+ uptime requirements)
Understanding ofsecurity best practices and common vulnerabilities (OWASP)
Experience withDocker,Kubernetes, and production deployments
2+ years of experience leading engineering teams
Track record of deliveringmission-critical infrastructure
Proven ability to lead multi-quarter technical initiatives across teams and influence architecture beyond the immediate team
Experience withsecurity-focused code review processes
Strong written and verbal communication — RFCs and design docs that people actually read
Ability to balance security requirements with delivery timelines
Hands-on experience with theOry ecosystem (Hydra, Kratos, Keto) — operating it in production or building on top of its APIs
Experience withCockroachDB or other distributed SQL databases (multi-region deployments, clock skew handling, survivability trade-offs)
Experience withNATS orKafka — event-driven patterns, consumer groups, at-least-once delivery
Experience withWebAuthn/FIDO2 passkey implementations
Knowledge ofWeb3 authentication (wallet signatures, EIP-4361)
Experience building or integrating withSCIM,SAML, or enterprise SSO (LDAP / Active Directory)
Background infintech,payments, orgaming identity systems
Familiarity with compliance requirements relevant to IAM:SOC 2,ISO 27001,PCI DSS, GDPR data minimization, audit logging
Contributions to open-source security or identity projects
Background in platform or infrastructure engineering — building systems other engineers build on top of
Experience withlarge-scale user migrations (millions of accounts)
Practical, up-to-date experience with modern AI tools (e.g. Claude, Copilot, Cursor) for code generation, review, and accelerating day-to-day engineering work
Deep understanding of Xsolla ID architecture and security requirements
Established team rituals and 1:1 cadence
Delivered improvements to at least one critical authentication flow
Team consistently delivers secure, well-tested code
Progress on migration from legacy Xsolla Login
Improved platform reliability metrics
Xsolla ID successfully serving multiple B2C products
Team grown and developed with clear succession planning
Platform achieving target availability (99.9%+) and security posture
First year:
First 6 months:
WHAT SUCCESS LOOKS LIKE
First 3 months:
Preferred:
Leadership Skills:
QUALIFICATIONS
Required:
Technical Skills:
Delivery & Stakeholder Management:
People Management (40%):
Technical Leadership (60%):
We are passionate about fostering a supportive environment for our team, so we prioritize the physical, mental, and emotional well-being of our employees through a comprehensive Benefits Program. This includes:
Unlimited Flexible Time Off for work-life balance
Private health insurance (ДМС) with dental coverage for you and your family
Personalized career roadmap with clear growth paths
Professional development through training, security certifications, and conferences
Annual corporate events and team gatherings
Remote-first culture with flexible working hours (10:00–19:00)
Leadership development programs and executive coaching
Competitive compensation reflecting leadership and security expertise
Together, we're not just building a business; we're cultivating a community that values creativity, collaboration, and the transformative power of play.
EMPLOYMENT DETAILS
Location: Remote (worldwide)
Employment Type: Full-time
Schedule: 10:00–19:00 (flexible)
Contract: Employment agreement (entity or EOR arranged per candidate location)
EQUAL EMPLOYMENT STATEMENT
Xsolla is dedicated to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, language, sexual orientation, national origin, genetics, political beliefs, disability, age, marital status, social background or other characteristics.
We are committed to compliance with all fair employment practices regarding citizenship and immigration status.
CONTACT
If you have questions regarding our hiring practices, please contact careers@xsolla.com.
For more vacancies, visit:xsolla.com/careers
Team Lead Backend Engineer · Xsolla