The role
We need a genuine all-rounder to help us execute faster across a broad, fast-moving product. You'll help with extending our pilot products (apps, SDKs and browser extensions), deepening our identity-provider integrations, and bringing fresh cryptography and signal-processing thinking to the protocol. You'll work closely with our CTO, including on offline, air-gapped systems as part of our critical-infrastructure project.
What you'll do
- Build and harden core product across the stack (Node.js/Express services, JavaScript front-ends, Chrome extensions)
- Work on our authentication protocol, including replay/relay resistance and key handling
- Develop SDKs, browser extensions and cross-browser support
- Integrate with identity providers via OIDC and WebAuthn/passkeys. One Identity today, with Okta and Microsoft Entra on the roadmap
- Contribute to our offline peer-to-peer authentication and its cryptographic protocol
- Help keep everything secure and scalable as we grow
What we're looking for
- Strong all-round engineer: excellent full-stack ability (JavaScript/Node.js, browser front-ends and extensions), and the ability to pick up new domains fast. This is the core of the day-to-day.
- Applied cryptography: solid working knowledge of key handling, hashing, replay/relay and protocol basics; you use crypto libraries correctly and think about threat models.
- Mobile development: you've built and shipped mobile apps or SDKs (native or cross-platform); a lot of what we do lives on the device.
- Signal processing: comfortable with the fundamentals (familiar with how audio is sampled and framed).
- Comfortable with IdP/SSO integration (OIDC, WebAuthn/passkeys)
- An eye for scalability and secure-by-design
Nice to have
- Embedded or OT exposure
- A security background or relevant certifications
Can be based in London or Manchester