Software Engineer - OESIS Framework

OPSWAT
OPSWAT

Software Engineering · Full-time

Ho Chi Minh City, Vietnam

Posted on Sep 12, 2026

OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.

About the position

At OPSWAT, we're building cutting-edge solutions that protect the world's critical infrastructure. You will play a pivotal role in shaping the future of our OESIS Framework platform with cloud solution integrations.

This role owns how the SDK authenticates into each customer's own tenant across Endpoint Device Management platforms without OPSWAT ever holding the customer's raw credentials. That passthrough model, plus secure multi-tenant token and credential storage, is the core of the job.

It is a software engineer role with an identity specialization: you will be writing and shipping the auth layer of an embedded SDK, not administering an IAM deployment.

What you will be doing

  • Design and implement OAuth2/OIDC flows per platform. For example the CrowdStrike API client-credentials flow, Microsoft Entra ID (Azure AD) app-registration and Graph API auth flows, and JAMF Pro OAuth2/bearer or client-credentials flows

  • Implement SAML 2.0-based federation for enterprise SSO passthrough scenarios where a customer's identity provider is the source of truth

  • Build secure, multi-tenant credential and token storage with rotation, integrating with secrets managers such as HashiCorp Vault, Azure Key Vault or AWS Secrets Manager

  • Design the passthrough auth architecture so the embedded SDK authenticates to the customer's own device management tenant directly, without OPSWAT storing or proxying raw customer credentials

  • Implement token refresh, expiry handling and re-authentication logic that integrates cleanly with the Data Engineer's long-running query pipelines

  • Define least-privilege scoping per platform and support certificate-based auth and mutual TLS where the vendor API allows it

  • Support customer onboarding: app-registration and consent flows for remote enrollment (Entra ID), API client setup (CrowdStrike), and API role and privilege configuration (JAMF Pro)

What we need from you

  • Strong experience in a systems or compiled language: Rust, Go or similar producing native, cross-platform artifacts for Windows, macOS and Linux

  • 3+ years in identity and access engineering with hands-on OAuth2, OIDC and SAML 2.0, and ideally SCIM

  • Direct experience with Microsoft Entra ID (Azure AD) app registrations and Graph API authentication flows

  • Experience implementing OAuth2 client-credentials flows against third-party enterprise APIs such as CrowdStrike Falcon or JAMF Pro, or comparable

  • Strong grasp of token lifecycle management: refresh tokens, expiry, revocation, scope and claim design

  • Experience with secrets management and secure credential storage in multi-tenant SaaS environments

  • Familiarity with certificate-based authentication: mTLS and client certificates

  • Security-first mindset, with working knowledge of common auth vulnerabilities: token leakage, replay attacks, scope creep

  • Solid general software engineering ability, you own production code in this layer, not configuration alone

  • Professional working proficiency in written and spoken English

It would be nice if you had

  • Prior experience building passthrough or delegated auth architectures for OEM/SDK products embedded in third-party platforms

  • Background in enterprise IAM tooling (Okta, Ping Identity, Entra ID) or CIAM

  • Familiarity with Zero Trust Network Access (ZTNA) and device posture or compliance

  • Security certifications such as CISSP or OSCP

  • Cybersecurity domain knowledge alongside software development experience

  • Familiarity with regulatory compliance frameworks such as PCI-DSS, SOX or HIPAA

Why join us?

At OPSWAT, we believe in empowering our people to do their best work. We encourage you to watch the video of our company's more than 20 years of experience securing critical infrastructure. You'll be part of a mission-driven OESIS Framework team that values innovation, collaboration and continuous development. Together, we're building SDK technology that makes a difference.

OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws.

Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time.