Senior Engineer And Token Security
Senior engineer - token security in London
Rate: £550 day outside IR35
Start date: ASAP
End date: 18/12/2026
Clearance: Active SC Clearance
Location: Remote/Hybrid (UK-based)
Responsibilities
Design and implement OAuth 2.0 Token Exchange (RFC 8693) capabilities.
Develop secure delegation and propagation patterns across distributed services.
Implement token down-scoping and audience restriction mechanisms aligned to least-privilege principles.
Design secure service-to-service authentication frameworks within zero-trust environments.
Build and maintain robust JWT validation and cryptographic trust chains.
Integrate applications and services using OpenID Connect (OIDC) standards.
Essential
OAuth 2.0 standards.
Proven hands-on implementation experience with OAuth 2.0 Token Exchange (RFC 8693).
Strong understanding of OpenID Connect (OIDC) core specifications.
Expert-level understanding of JWT (RFC 7519).
Experience signing, validating, and encrypting tokens using JWS and JWE.
Strong knowledge of JWKS endpoints and automated key rotation strategies.
Understanding of secure alternatives to shared-secret authentication mechanisms.
Experience securing service-to-service communication within distributed microservice architectures.
Understanding of zero-trust security principles.
Knowledge of secure transit-layer protection and access controls.
Delegation and token management
Experience implementing:
Token down-scoping
Audience restriction (aud)
Actor and subject claims handling
Experience designing secure token lifecycle management strategies including:
Token caching
Token renewal
Revocation patterns
Familiar with
CDDO Secure by Design principles.
Experience with cloud security architectures.
Knowledge of API gateways, service meshes, and federated platforms.