We are seeking a senior software engineer to lead the design and implementation of a production-grade Role-Based Access Control (RBAC) system for an open-source ML infrastructure stack using MLRun and Nuclio. This greenfield project will replace a commercial RBAC system with a custom authorization layer that is functionally equivalent, operationally simple, and aligned with enterprise security expectations. The successful candidate will architect and deliver a complete authorization system integrated with our identity provider, MLRun API, and Nuclio API, supporting 75+ active users across multi-cluster, multi-AWS-account deployments.
Project Scope & Deliverables
This is a six-month engagement. The contractor will deliver a production-ready, fully functional RBAC stack, including the following components:
1. Authorization Service — Python/FastAPI Backend
- Multi-tenant permission management and policy evaluation
- Integration with external identity provider, such as Azure Entra
- OPA/Rego-compatible API endpoints for MLRun and Nuclio
- Session verification and identity resolution through access keys and cookies
2. User, Group, and Access Key Management API
- Full CRUD operations for users, groups, and role assignments
- Audit logging and compliance-ready change tracking
- Cascading delete logic and data integrity safeguards
3. Admin UI — React/TypeScript
- Clean dashboard for user, group, and permission management
- Bulk import and export support using YAML
- Real-time permission visibility
4. Data Persistence and High Availability
- Multi-AZ and multi-region deployment design for high availability
- Persistent storage layer for audit logs, user state, and configuration
- Performance optimization to minimize authorization-check latency
5. MLRun and Nuclio Integration
- Native integration with the MLRun API for authorization decisions on projects, runs, and artifacts
- Seamless login flow and UI authentication for MLRun and Nuclio
- Token and session management compatible with MLRun request flows
6. Documentation and Handoff
- Operator runbooks and support documentation
- Knowledge transfer sessions with the internal development team
Required Skills and Experience
- 5+ years of backend software engineering experience, preferably with Python
- Demonstrable experience designing and implementing authentication, authorization, or other security-critical infrastructure
- Demonstrable experience with Kubernetes production deployments, including multi-cluster architecture, configuration management, and high-availability patterns
- Proficiency with at least one external identity provider, such as Azure Entra, AWS Cognito, Okta, or OIDC
- Proficiency in policy-as-code concepts, with OPA/Rego strongly preferred
- Proficiency with AI-assisted coding tools
- Operational mindfulness, including the ability to design for simplicity, monitoring, and debuggability
- Clear communication, including the ability to explain architecture decisions to both technical and non-technical stakeholders
Preferred Qualifications
- Experience with MLRun or Nuclio
- Experience with multi-cluster deployment patterns across AWS accounts
Pay: $70.76 - $80.72 per hour
Work Location: Remote