Descrição da vaga
<div class="content-intro"><p><strong>Why join us</strong></p>
<p>Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.</p>
<p>Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.</p></div><p><strong>Engineering at Brex</strong></p>
<p>Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders.</p>
<p><strong>What you'll do</strong></p>
<p>The Identity and Access Management team builds and maintains secure, user-friendly authentication and authorization systems that protect users, safeguard company assets, and provide a seamless access experience for developers. The team owns critical platform capabilities including login methods, step-up authentication, our custom authorization platform, account delegation flows like Copilot, Pro Access login, embedded partnerships authentication, and core vendor integrations such as Okta and Oso.</p>
<p>As a Software Engineer II on IAM, you will build product and platform capabilities that make access to Brex secure, reliable, and easy to use for customers, partners, and internal systems. You will own well-scoped projects with clear impact, contribute to the team’s technical quality and operational excellence, and help evolve the identity platform as Brex invests in signed identity propagation, delegated and agent identity, fine-grained authorization, stronger auditability, and enterprise-ready customer authentication experiences.</p>
<p><strong>Where you'll work</strong></p>
<p>This role will be based in our São Paulo office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of 3 days per week in the office - Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Design, build, and operate backend systems and APIs for authentication, authorization, identity context, and audit-related workflows.</li>
<li>Deliver well-scoped projects end to end, from technical design and implementation through rollout, measurement, and operational support.</li>
<li>Improve login and access experiences across SSO, MFA, step-up authentication, delegated access, and enterprise identity flows.</li>
<li>Build and extend authorization systems that support custom roles, resource-aware access control, and secure defaults for product teams.</li>
<li>Help create durable, identity-aware audit trails and attribution for user, service, delegated, and agent-driven actions.</li>
<li>Partner closely with engineers across Brex to make IAM integrations secure by default and easier to adopt through clear patterns, tooling, and shared libraries.</li>
<li>Contribute high-quality code, design reviews, documentation, and operational improvements that raise the bar for reliability and maintainability across the team’s systems.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>You have strong software engineering fundamentals and experience building reliable production backend systems.</li>
<li>You have experience owning well-scoped technical projects and driving them to completion with limited support.</li>
<li>You have experience building APIs, services, or platform infrastructure with strong engineering rigor around testing, code quality, and documentation.</li>
<li>You communicate clearly, collaborate well across teams, and are effective in cross-functional technical discussions.</li>
<li>You care about operational excellence and know how to improve system reliability, reduce toil, and maintain high-quality services over time.</li>
<li>You have strong product and engineering judgment and can balance security, usability, and developer experience.</li>
<li>Strong written and verbal English communication and interpersonal abilities.</li>
</ul>
<p><strong>Bonus points</strong></p>
<ul>
<li>You have worked on identity and access management, authentication, authorization, or audit systems in a production environment.</li>
<li>You have hands-on experience with Okta, Oso, SSO, SAML, OIDC, OAuth, passkeys, or WebAuthn.</li>
<li>You have experience building enterprise-facing admin controls, custom roles, delegated access flows, or audit trails.</li>
<li>You have worked on platform teams that provide shared infrastructure, paved roads, or secure-by-default frameworks for other engineering teams.</li>
</ul>
<p>If you don’t meet every qualification listed above, we still encourage you to apply. We’re looking for thoughtful engineers who want to build secure, scalable access systems and help shape how identity works across Brex.</p><div class="content-conclusion"><p><em>Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a <a class="c-link" href="http://brex.com/" target="_blank" data-stringify-link="http://brex.com" data-sk="tooltip_parent">brex.com</a> domain. Any outreach claiming to be from Brex via other sources should be ignored.</em></p></div>