I’m an IAM engineer at a 10,000+ employee tech company. What would you like to hear about?
Hey everyone! I’m a Senior Backend/IAM Engineer at a large tech company with 10,000+ employees. I’ve been working with Golang for 8+ years, and for the last few years I’ve been focused mostly on IAM and security.
Our team builds and operates most of our internal IAM infrastructure, and all of our services are written in Go.
Some of the things we work on:
- employee identity lifecycle: onboarding, transfers, offboarding;
- automated access provisioning and revocation;
Active Directory and OpenLDAP;
- access reviews and least-privilege processes;
- Keycloak and Ory Hydra;
- OAuth 2.0, OIDC, SSO and 2FA;
- migrating our internal apps from Hydra to Keycloak.
I’m thinking about writing a few technical articles or maybe preparing a conference talk about real-world IAM engineering.
So I’m curious: what would you actually like to hear about? What IAM/security problems do you think aren’t discussed enough?
Happy to answer questions here too, as long as I can do so without sharing anything sensitive or company-specific.