Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Tech Lead FullStack based in Brazil.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Tech Lead FullStack based in Brazil. This role offers the opportunity to lead the development and evolution of critical authentication, authorization, and observability capabilities within a modern multi-tenant platform. You will work across frontend and backend technologies while helping shape secure and scalable identity solutions. The position combines hands-on engineering with technical discovery, architecture, and integration work. You will contribute to OAuth2/OIDC-based authentication, enterprise federation, role management, and identity provider integrations. The role also involves supporting legacy services during a gradual modernization journey, ensuring continuity for existing customers. You will collaborate closely with infrastructure and product teams in a remote-first environment where AI-assisted development and engineering excellence are encouraged.
Develop and evolve the Authentication & Authorization module using OAuth2, including centralized login, product-level role definitions, and enterprise OIDC federation within a multi-tenant architecture. Maintain and support existing authentication flows and services, ensuring compatibility for customers who have not yet migrated to the new architecture. Maintain user and role management services while ensuring stability during the transition to the new platform model. Integrate users and roles from the selected identity provider, such as Keycloak or Auth0, into new services and support identity-data synchronization and migration between legacy and modern models. Implement observability across the modules, including metrics, logging, dashboards, and monitoring capabilities. Evaluate and prototype integrations with identity providers such as Auth0, Keycloak, Okta, Entra ID, and Azure B2C to support the selection of a centralized identity platform. Integrate delivered modules with the central portal and identity platform in collaboration with infrastructure teams. Participate in technical discovery, refinement, and planning for upcoming platform capabilities and improvements. Document architectural and technical decisions while ensuring services remain aligned with a shared-ownership model across cloud infrastructure and individual products. Requirements: Demonstrated experience in full-stack development, with strong frontend skills in React, TypeScript, and Next.js and backend experience with Node.js, Java, or Kotlin. Practical knowledge of authentication and authorization concepts, including OAuth2, OIDC, and RBAC. Hands-on experience with identity providers such as Auth0, Keycloak, Okta, Entra ID, or Azure B2C. Experience working with messaging and event-driven systems, particularly Kafka or an equivalent technology. Comfortable working within codebases where legacy and modern versions coexist, supporting gradual migrations without disrupting existing customers. Familiarity with observability technologies such as SigNoz, Prometheus, and Grafana. Experience with at least one public cloud provider, such as AWS or Azure, as well as practical Docker experience. Proficiency with Git and CI/CD pipelines, particularly GitHub Actions. Comfortable using AI-powered development tools, such as Claude Code, custom skills, and agents, to support technical refinement, documentation, feature development, and coding. Strong problem-solving, technical communication, collaboration, and documentation skills, with the ability to contribute to technical discovery and make informed engineering decisions. Knowledge of Segregation of Duties (SoD) and/or OpenFGA for fine-grained authorization is considered an advantage. Experience with Kubernetes, GitOps concepts, Anticorruption Layer patterns, and Factory/Strategy patterns for interchangeable identity providers is a plus. If you reside in the Campinas Metropolitan Region, availability to work from the local offices is required in accordance with the applicable attendance policy. Benefits: Health and dental insurance. Meal and food allowances. Childcare assistance. Extended parental leave. Access to fitness, wellness, and healthcare professionals through Wellhub and TotalPass partnerships. Profit Sharing and Results (PLR). Life insurance. Continuous learning opportunities through an internal learning platform. Access to online courses and language-learning platforms. Discounts through partner programs. Online resources dedicated to physical health, mental health, and overall well-being. Pregnancy and responsible-parenthood support and courses. Opportunities to work with modern technologies, AI-assisted development, cloud platforms, identity management, and large-scale platform modernization. Remote work environment, subject to the applicable office attendance requirements for employees in the Campinas Metropolitan Region.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →