HighLevel
Staff Backend Engineer - Users
TLDR
Drive the design and evolution of secure identity and access systems for a multi-tenant SaaS platform, ensuring resilience and safety as core principles.
About HighLevel:HighLevel is an AI-powered business operating system that gives agencies, entrepreneurs and SMBs the infrastructure to build, automate and scale. Today, HighLevel supports SMBs across 150+ countries, fueling community-driven growth rooted in real customer outcomes.
To date, businesses operating on HighLevel have generated over $7 billion in ecosystem value, demonstrating the impact of shared infrastructure at scale. By centralizing conversations, automation and intelligence into one system, we help businesses move faster, reduce complexity and execute efficiently.
Behind the platform, HighLevel powers more than 4 billion API hits and 2.5 billion message events daily. With 250 terabytes of distributed data, 250+ microservices and over 1 million domain names supported, our architecture is built for performance, resilience and long-term scalability.
Our people
With over 2,000 team members across 10+ countries, HighLevel operates as a global, remote-first organization built for speed and ownership. We value initiative, clarity and execution, creating space for ambitious people to build systems that support millions of businesses worldwide. Here, innovation thrives, ideas are celebrated and people come first, no matter where they call home.
Our impact
Every month, HighLevel enables more than 1.5 billion messages, 200 million leads and 20 million conversations for the more than 1 million businesses we support. Behind those numbers are real people building independence, expanding opportunity and creating measurable impact. We’re proud to be a part of that.
Learn more about us on our YouTube Channel or Blog Posts
Role Summary:
As a Staff Engineer on the Users team, you will be the technical anchor for identity, access, auditing, notifications and security foundations across our multi-tenant SaaS platform. This role is not about feature velocity - it’s about building systems that are correct, resilient, and safe by default, and enabling other teams to move fast without breaking trust.
You’ll work closely with EMs, Product, and other engineers to design and evolve core primitives such as users, roles, permissions, tokens, and tenant isolation, auditing, notifications - at scale.
Responsibilities:
Design and evolve secure multi-tenant architectures (Agency → Account → App or equivalent hierarchy) for 100k+ agencies
Define and enforce tenant isolation guarantees at data, API, and infra levels
Build and review authorization models (RBAC / ABAC / hybrid)
Own token systems (API keys, OAuth flows, JWTs, scoped tokens, rotation, expiry)
Design fine-grained scopes for internal APIs, public APIs, and partner integrations
Map scopes → permissions → resources consistently
Prevent over-scoped tokens and privilege escalation
Lead security-critical backend designs (authZ boundaries, impersonation, auditability)
Set patterns for secure-by-default APIs used by internal and external teams
Partner with Infra/Security teams on Secrets management, Key rotation, Rate limiting & abuse prevention, Compliance readiness (SOC2 style thinking)
Act as a multiplier: raise the security bar across engineering via reviews, RFCs, and mentoring
Requirements:
8+ years of backend engineering experience
Proven experience building secure, multi-tenant SaaS platforms
Deep understanding of: Authorization models (RBAC, ABAC), OAuth2 / JWT / API key systems, Threat modeling & security tradeoffs
Strong system design skills - especially for long-lived platformsComfort owning ambiguous, high-impact areas
Nice to have:
Experience designing platforms used by multiple internal teams
Security reviews, incident learnings, or compliance exposure
Experience with large-scale migrations (auth or identity related)
Background in developer platforms or core infrastructure teams
EEO Statement:
The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government recordkeeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.
#LI-Remote #LI-NJ1
HighLevel is an all-in-one white-label sales and marketing platform that empowers marketing agencies, entrepreneurs, and businesses to enhance their digital presence and drive growth. With a suite of robust tools designed to capture, nurture, and convert leads, HighLevel supports a diverse community of over 2 million clients across various industries.
- Founded
- Founded 2018
- Employees
- 201-500 employees
- Industry
- Internet Software & Services
- Total raised
- $60M raised
Backend Engineer