Senior Engineer And Token Security
Senior engineer - token security in London
Rate: £550 day outside IR35
Start date: ASAP
End date: 18/12/2026
Clearance: Active SC Clearance
Location: Remote/Hybrid (UK-based)
Responsibilities
- Design and implement OAuth 2.0 Token Exchange (RFC 8693) capabilities.
- Develop secure delegation and propagation patterns across distributed services.
- Implement token down-scoping and audience restriction mechanisms aligned to least-privilege principles.
- Design secure service-to-service authentication frameworks within zero-trust environments.
- Build and maintain robust JWT validation and cryptographic trust chains.
- Integrate applications and services using OpenID Connect (OIDC) standards.
Essential
- OAuth 2.0 standards.
- Proven hands-on implementation experience with OAuth 2.0 Token Exchange (RFC 8693).
- Strong understanding of OpenID Connect (OIDC) core specifications.
- Expert-level understanding of JWT (RFC 7519).
- Experience signing, validating, and encrypting tokens using JWS and JWE.
- Strong knowledge of JWKS endpoints and automated key rotation strategies.
- Understanding of secure alternatives to shared-secret authentication mechanisms.
- Experience securing service-to-service communication within distributed microservice architectures.
- Understanding of zero-trust security principles.
- Knowledge of secure transit-layer protection and access controls.
Delegation and token management
- Experience implementing:
- Token down-scoping
- Audience restriction (aud)
- Actor and subject claims handling
- Experience designing secure token lifecycle management strategies including:
- Token caching
- Token renewal
- Revocation patterns
Familiar with
- CDDO Secure by Design principles.
- Experience with cloud security architectures.
- Knowledge of API gateways, service meshes, and federated platforms.