HighLevel
HighLevel

Staff Backend Engineer - Users

TLDR

Drive the design and evolution of secure identity and access systems for a multi-tenant SaaS platform, ensuring resilience and safety as core principles.

About HighLevel:HighLevel is an AI-powered business operating system that gives agencies, entrepreneurs and SMBs the infrastructure to build, automate and scale. Today, HighLevel supports SMBs across 150+ countries, fueling community-driven growth rooted in real customer outcomes. To date, businesses operating on HighLevel have generated over $7 billion in ecosystem value, demonstrating the impact of shared infrastructure at scale. By centralizing conversations, automation and intelligence into one system, we help businesses move faster, reduce complexity and execute efficiently. Behind the platform, HighLevel powers more than 4 billion API hits and 2.5 billion message events daily. With 250 terabytes of distributed data, 250+ microservices and over 1 million domain names supported, our architecture is built for performance, resilience and long-term scalability. Our people With over 2,000 team members across 10+ countries, HighLevel operates as a global, remote-first organization built for speed and ownership. We value initiative, clarity and execution, creating space for ambitious people to build systems that support millions of businesses worldwide. Here, innovation thrives, ideas are celebrated and people come first, no matter where they call home. Our impact Every month, HighLevel enables more than 1.5 billion messages, 200 million leads and 20 million conversations for the more than 1 million businesses we support. Behind those numbers are real people building independence, expanding opportunity and creating measurable impact. We’re proud to be a part of that. Learn more about us on our YouTube Channel or Blog Posts     Role Summary: As a Staff Engineer on the Users team, you will be the technical anchor for identity, access, auditing, notifications and security foundations across our multi-tenant SaaS platform. This role is not about feature velocity - it’s about building systems that are correct, resilient, and safe by default, and enabling other teams to move fast without breaking trust.   You’ll work closely with EMs, Product, and other engineers to design and evolve core primitives such as users, roles, permissions, tokens, and tenant isolation, auditing, notifications - at scale. Responsibilities:
  • Design and evolve secure multi-tenant architectures (Agency → Account → App or equivalent hierarchy) for 100k+ agencies
  • Define and enforce tenant isolation guarantees at data, API, and infra levels
  • Build and review authorization models (RBAC / ABAC / hybrid)
  • Own token systems (API keys, OAuth flows, JWTs, scoped tokens, rotation, expiry)
  • Design fine-grained scopes for internal APIs, public APIs, and partner integrations
  • Map scopes → permissions → resources consistently
  • Prevent over-scoped tokens and privilege escalation
  • Lead security-critical backend designs (authZ boundaries, impersonation, auditability)
  • Set patterns for secure-by-default APIs used by internal and external teams
  • Partner with Infra/Security teams on Secrets management, Key rotation, Rate limiting & abuse prevention, Compliance readiness (SOC2 style thinking)
  • Act as a multiplier: raise the security bar across engineering via reviews, RFCs, and mentoring
  • Requirements:
  • 8+ years of backend engineering experience
  • Proven experience building secure, multi-tenant SaaS platforms
  • Deep understanding of: Authorization models (RBAC, ABAC), OAuth2 / JWT / API key systems, Threat modeling & security tradeoffs
  • Strong system design skills - especially for long-lived platformsComfort owning ambiguous, high-impact areas
  • Nice to have:
  • Experience designing platforms used by multiple internal teams
  • Security reviews, incident learnings, or compliance exposure
  • Experience with large-scale migrations (auth or identity related)
  • Background in developer platforms or core infrastructure teams
  • EEO Statement:
    The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government recordkeeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.
     
    #LI-Remote #LI-NJ1

    HighLevel is an all-in-one white-label sales and marketing platform that empowers marketing agencies, entrepreneurs, and businesses to enhance their digital presence and drive growth. With a suite of robust tools designed to capture, nurture, and convert leads, HighLevel supports a diverse community of over 2 million clients across various industries.

    Founded
    Founded 2018
    Employees
    201-500 employees
    Industry
    Internet Software & Services
    Total raised
    $60M raised
    View company profile
    Report this job
    Apply for this job