Post Job Free
Sign in

Senior Authentication & Cloud Security Engineer

Location:
Dallas, TX
Salary:
150000
Posted:
October 04, 2026

Contact this candidate

Resume:

Stephen Anderson

214-***-**** *******************@*******.*** https://www.linkedin.com/in/stephen-anderson-732861440 Dallas, TX SUMMARY

Senior software engineer with 10+ years building and hardening full-stack products, specializing in authentication, session security, and scalable cloud services for consumer platforms. Experienced leading cross-functional security initiatives, shipping user-facing controls (MFA, device trust, risk-based challenges), and operating high-availability systems with strong observability and CI/CD. Applies AI/ML for anomaly detection and fraud/risk scoring to reduce account compromise while improving user experience. SKILLS

Backend: Go, Python, Java, Rust, gRPC, REST APIs, OAuth 2.0, OIDC, JWT, WebAuthn, FIDO2, Passkeys, MFA, Session management, Rate limiting, Idempotency, Distributed systems

Frontend: TypeScript, React, Next.js, WebAuthn browser APIs, SPA security, Secure UX for authentication flows Cloud: Google Cloud, Kubernetes, Cloud Run, GKE, Cloud Load Balancing, Cloud IAM, Secret Manager, Cloud KMS Data: PostgreSQL, MySQL, Redis, DynamoDB, Elasticsearch, Kafka DevOps/IaC: Terraform, Helm, Docker, GitHub Actions, Buildkite, CI/CD pipelines, Blue/green deployments, Canary releases Observability: OpenTelemetry, Prometheus, Grafana, Datadog, Structured logging, Distributed tracing, SLOs/SLIs, On-call operations, Incident response

AI/ML: Risk scoring, Anomaly detection, Fraud/abuse detection, Feature engineering, Model evaluation, Python ML tooling, Online inference patterns

Testing: Go test, pytest, JUnit, Contract testing, Integration testing, Load testing, Fuzz testing Security: Threat modeling, Secure design reviews, OWASP Top 10, CSRF/XSS mitigations, CSP, Secrets management, Encryption at rest/in transit, mTLS, Supply chain security, SAST/DAST, Dependency scanning EMPLOYMENT HISTORY

Rec Room Seattle, WA

Lead Software Engineer 10/2023 - 06/2026

Led end-to-end delivery of account security features across Go services and TypeScript/React clients, strengthening session integrity and reducing account-takeover vectors in high-traffic consumer flows Designed and implemented a hardened authentication gateway in Go (gRPC/REST) with OIDC/OAuth2, JWT rotation, and device-bound session tokens; improved suspicious-session detection and reduced auth-related incidents through safer defaults Shipped WebAuthn/passkeys (FIDO2) enrollment and step-up authentication UX in React, partnering with Product to optimize conversion while maintaining strong security guarantees and clear recovery paths Built a risk-based challenge system using Python feature pipelines and online scoring to adapt MFA prompts based on login context (IP reputation, device signals, velocity), improving protection while minimizing user friction Implemented automated abuse/anomaly detection for session theft patterns using Python models and Kafka event streams; decreased time- to-detect for emerging threats via real-time alerting and playbooks Operationalized security-critical services on Google Cloud with GKE/Cloud Run, Terraform, and Secret Manager/KMS; established SLOs, dashboards, and runbooks using OpenTelemetry, Prometheus, and Grafana Introduced defense-in-depth controls including rate limiting, replay protection, and idempotent auth endpoints backed by Redis and PostgreSQL, improving resilience under burst traffic and credential-stuffing attempts Drove cross-functional secure design reviews and threat modeling for auth/session changes, providing clear implementation guidance and raising the security bar through reusable libraries and CI checks Disney Streaming San Francisco, CA

Senior Software Engineer 08/2019 - 09/2023

Owned security-sensitive identity and session components for consumer applications, delivering Java and Go services that supported MFA, device trust, and session lifecycle management at scale Implemented session hardening patterns (token binding, refresh-token rotation, revocation lists) using Redis and PostgreSQL, improving containment for compromised credentials and reducing long-lived session risk Built self-service security controls and internal tooling in Python to automate account recovery workflows and reduce manual operations load while improving auditability

Partnered with Product and client engineers to ship user-facing authentication flows in TypeScript/React, aligning UX with security requirements (step-up auth, re-auth for sensitive actions) Improved reliability and performance of authentication services with Kubernetes, canary releases, and targeted load testing; reduced tail latency through caching strategies and query optimization Established observability standards for auth and session services using OpenTelemetry tracing and structured logs, accelerating incident triage and enabling proactive detection of anomalous login patterns American Public Media Group Los Angeles, CA

Software Engineer 01/2017 - 05/2019

Developed and maintained backend APIs in Python and Java for subscription and account experiences, including secure session handling and permissioned access to user data

Implemented secure-by-default patterns (input validation, CSRF protections, secure cookies, least-privilege service access) across web applications and services

Built data pipelines and search experiences using Elasticsearch and PostgreSQL, improving content discovery while maintaining privacy and access controls

Added CI quality gates with automated tests (pytest/JUnit) and dependency scanning to reduce regressions and improve release confidence CVS Health Woonsocket, RI

Software Engineer 02/2015 - 11/2016

Built and supported enterprise web services in Java with REST APIs and SQL persistence, focusing on correctness, reliability, and secure handling of sensitive data

Implemented authentication/authorization integrations and strengthened transport security with TLS configuration and secure secret handling practices

Improved system stability through monitoring, log standardization, and automated regression testing with JUnit, reducing production defects EDUCATION

University of Southern California Los Angeles, CA

Bachelor of Science, Computer Science 2012 - 2016



Contact this candidate