Software Engineer II, Identity and Access Management

Brex · São Paulo, São Paulo, Brazil · Engineering · listed October 1, 2026

The shape of it

Seniority
Mid level
Where
Hybrid
Requirements listed
7
Length
822 words

In the posting’s own words

As a Software Engineer II on IAM, you will build product and platform capabilities that make access to Brex secure, reliable, and easy to use for customers, partners, and internal systems. You will own well-scoped projects with clear impact, contribute to the team’s technical quality and operational excellence, and help evolve the identity platform as Brex invests in signed identity propagation, delegated and agent identity, fine-grained authorization, stronger auditability, and enterprise-ready customer authentication experiences.

What it asks for · 7

  • You have strong software engineering fundamentals and experience building reliable production backend systems.
  • You have experience owning well-scoped technical projects and driving them to completion with limited support.
  • You have experience building APIs, services, or platform infrastructure with strong engineering rigor around testing, code quality, and documentation.
  • You communicate clearly, collaborate well across teams, and are effective in cross-functional technical discussions.
  • You care about operational excellence and know how to improve system reliability, reduce toil, and maintain high-quality services over time.
  • You have strong product and engineering judgment and can balance security, usability, and developer experience.
  • Strong written and verbal English communication and interpersonal abilities.

Also a plus

  • You have worked on identity and access management, authentication, authorization, or audit systems in a production environment.
  • You have hands-on experience with Okta, Oso, SSO, SAML, OIDC, OAuth, passkeys, or WebAuthn.
  • You have experience building enterprise-facing admin controls, custom roles, delegated access flows, or audit trails.
  • You have worked on platform teams that provide shared infrastructure, paved roads, or secure-by-default frameworks for other engineering teams.

What the job covers

  • Design, build, and operate backend systems and APIs for authentication, authorization, identity context, and audit-related workflows.
  • Deliver well-scoped projects end to end, from technical design and implementation through rollout, measurement, and operational support.
  • Improve login and access experiences across SSO, MFA, step-up authentication, delegated access, and enterprise identity flows.
  • Build and extend authorization systems that support custom roles, resource-aware access control, and secure defaults for product teams.
  • Help create durable, identity-aware audit trails and attribution for user, service, delegated, and agent-driven actions.
  • Partner closely with engineers across Brex to make IAM integrations secure by default and easier to adopt through clear patterns, tooling, and shared libraries.
  • Contribute high-quality code, design reviews, documentation, and operational improvements that raise the bar for reliability and maintainability across the team’s systems.

Tools and skills named

Security & compliance
  • Audit4×
  • IAM4×
  • Security2×
Ways of working
  • Technical writing2×
  • Cross-functional
  • Testing
Go to market
  • Partnerships

Words the posting leans on

  • access10×
  • systems10×
  • experience9×
  • identity8×
  • authentication7×
  • engineering7×
  • authorization6×
  • platform6×
  • build5×
  • secure5×
  • technical5×
  • delegated4×
  • operational4×
  • custom3×
  • design3×
  • engineers3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Brex

every open role at Brex →

How this page was made

An automated read of a public job posting, fetched October 2, 2026 and last changed by Brex on October 1, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.