Job Code - DEVMLL2
Senior Auth0 & Kong Developer
We are looking for a highly skilled Auth0 & Kong Developer with 6–8 years of experience to design, implement, and manage secure authentication, authorization, and API gateway solutions. The ideal candidate will have strong expertise in OAuth 2.0, OpenID Connect, SSO, API security, and microservices architecture, along with hands-on experience in Auth0 Identity Platform and Kong API Gateway.
Responsibilities
- Design and implement secure authentication and authorization flows using Auth0.
- Configure and manage Kong API Gateway for routing, rate limiting, authentication, and monitoring.
- Implement OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and RBAC/ABAC security models.
- Develop and maintain custom Auth0 rules, actions, and hooks.
- Integrate Auth0 with web, mobile, and backend applications.
- Configure Kong plugins for authentication, logging, analytics, and traffic control.
- Implement API security best practices including token validation, API keys, and mutual TLS.
- Work closely with frontend, backend, DevOps, and security teams.
- Perform security audits, vulnerability assessments, and penetration testing support.
- Troubleshoot authentication and API gateway issues in production environments.
- Optimize API performance, scalability, and reliability.
- Maintain documentation for IAM and API gateway configurations.
- Mentor junior developers and review code for security and performance best practices.
Required Experience & Qualifications
- 6–8 years of total IT experience, with at least 4–5 years in IAM & API Gateway technologies
- Minimum 3+ years of hands-on experience with Auth0
- Minimum 3+ years of hands-on experience with Kong
- Strong experience in enterprise-scale authentication systems
- Bachelor’s degree in Computer Science, Engineering, or related field
Nice to Have
- Experience with Zero Trust Architecture
- Knowledge of Keycloak, Okta, or Azure AD
- Experience in Healthcare, Banking, or Financial Compliance (HIPAA, PCI-DSS, SOC2)
- Event-driven architecture & API monetization
- Experience with logging & monitoring tools (ELK, Prometheus, Grafana)