Logo for DrFirst, Inc.

Senior Engineer - Identity Platform

Role overview

Qualifications

  • 6+ years of professional software engineering with strong, production-grade Java, including significant focus on Identity and Access Management.
  • Expert Keycloak experience beyond the admin console, with hands-on SPI and extension development.
  • Deep OAuth 2.0 and OIDC fluency, including authorization code plus PKCE, client credentials, and Token Exchange.
  • Production operations skill: JVM performance analysis, correlating structured logs, and SQL-level investigation in PostgreSQL.

Responsibilities

  • Design, build, and refactor custom Keycloak SPIs in Java, including authenticators and grant-type providers.
  • Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns.
  • Drive the Keycloak major-version upgrade, including session caching and validating downstream integrations.
  • Serve as the deep-diagnosis engineer for JVM tuning, Infinispan cluster behavior, and PostgreSQL session-store forensics.

About the company

DrFirst, Inc. logo

DrFirst, Inc.

Digital Health & Health Tech

Since 2000, DrFirst has pioneered healthcare technology solutions and consulting services that securely connect people at touchpoints of care to improve patient outcomes. We create unconventional solutions that solve care collaboration, medication management, price transparency, and adherence challenges in healthcare. We unite the Healthiverse™ by providing our clients with real-time access to the information they need, exactly when and how they need it – so patients get the best care possible.The “Healthiverse” is a term coined by DrFirst to describe our vision of a united healthcare universe where everyone is connected in real-time to each other and to the information they need, so patients get the best care. The vast Healthiverse includes patients, medical professionals and caregivers, hospitals, pharmacies, EHRs, payers, HIEs, pharmaceutical companies, and more. The expansiveness of the Healthiverse means that providers need better access to complete, clean, and consumable information to provide the best care for patients. DrFirst’s mission is to unite the Healthiverse with revolutionary products and services that close the gaps between information and people so that all sectors in healthcare can create better outcomes together. To learn more, visit DrFirst.com.We are always looking for team members who: • Are DDS (driven, disciplined, smart) innovators• Hit the ground running • Look for solutions• Want to revolutionize and transform healthcare• Are passionate about saving lives • Hope to make a difference as part of an extraordinary team doing extraordinary things If this sounds like you, please check out our current opportunities at http://www.drfirst.com/careers.jsp

Company details

IndustryDigital Health & Health Tech
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About DrFirst:

For 25 years, DrFirst has empowered providers and patients to achieve better health through intelligent medication management. We improve healthcare workflows and help patients start and stay on therapy with end-to-end solutions that enhance prescription access, affordability, and adherence. Our solutions help 100 million patients a year and are used by more than 420,000 prescribers, 71,000 pharmacies, 270 EHRs and health information systems, and over 2,000 hospitals in the U.S. This is a great opportunity to be a part of a successful Healthcare IT company experiencing significant growth. Here you’ll get to work with some of the smartest and most interesting people around, solving unique and complex challenges in healthcare on a scale matched by few companies. If you get excited about stretching yourself in new ways, developing yourself to your fullest potential, and care about working with smart colleagues, we want to talk to you!

Position Overview:

Every day, tens of thousands of clinicians launch into DrFirst applications to prescribe medications and manage patient care, and every launch flows through the identity platform. This role is the technical anchor for a production IAM platform built on Keycloak. It spans custom SPI development in Java, a major-version migration, standards-based modernization of partner SSO, and the session architecture behind a national e-prescribing network.

This is platform ownership, not an integration seat. You will operate a living system with real scale, real incidents, and real migration deadlines, and you will hold the mandate to modernize it. You will regularly be the person who can read a JVM GC log, a Postgres session table, and an OAuth spec in the same afternoon. If you have wanted to be the engineer who both writes the custom grant provider and decides whether it should exist, this is that seat.

What you will work on:
  • Keycloak Extension (SPI) Development: Design, build, and refactor custom Keycloak SPIs in Java, including authenticators, grant-type providers, mappers, and just-in-time provisioning. EMR SSO integrations run on custom extension code you will own end to end.
  • Standards-Based Auth Modernization: Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns, including JWT Bearer grants (RFC 7523), Token Exchange (RFC 8693), authorization code plus PKCE, and BFF architectures for web clients, making and defending the architectural calls.
  • Major Version Migration: Drive the Keycloak major-version upgrade, including the shift from external Infinispan session caching with JDBC persistence to persistent user sessions, and validate every downstream integration against the new version.
  • Session and Token Architecture: Own the session lifecycle model across SSO, client, and offline sessions, including idle and max semantics, token lifespans, and refresh rotation, and design per-client TTL policies that balance clinical workflow UX against security posture.
  • Production Ownership and Incident Response: Serve as the deep-diagnosis engineer for JVM tuning (heap, Metaspace, GC), Infinispan cluster behavior, PostgreSQL session-store forensics, and log-driven root-cause analysis on live authentication traffic.
  • Federation and Platform Hygiene: Design integrations with external identity systems (OIDC, SAML, cloud identity platforms), including JWKS trust, key rotation, and audience and issuer validation, and treat realm and client configuration as version-controlled, least-privilege, auditable code.
  • Technical Mentorship: Raise the bar on OAuth and OIDC fluency and secure coding across the team, and represent the platform technical position to application teams and leadership.
Qualifications:

Required

  • 6+ years of professional software engineering with strong, production-grade Java, including significant focus on Identity and Access Management.
  • Expert Keycloak experience beyond the admin console, with hands-on SPI and extension development, realm and client architecture for multi-tenant platforms, and running Keycloak (Quarkus) in production on Kubernetes.
  • Deep OAuth 2.0 and OIDC fluency, including authorization code plus PKCE, client credentials, Token Exchange (RFC 8693), JWT Bearer (RFC 7523), and refresh rotation. Working knowledge of SAML 2.0.
  • Session and token architecture depth: stateful SSO sessions versus stateless JWT validation, online versus offline sessions, idle and max semantics, and JWKS validation and key rotation, with the judgment to choose per use case.
  • Hands-on distributed caching and state with Infinispan or comparable technology, including clustering, persistence, expiration, and the failure modes of distributed session state.
  • Production operations skill: JVM performance analysis (GC logs, heap and Metaspace sizing), correlating structured logs, and SQL-level investigation in PostgreSQL against live systems.
  • Security fundamentals and communication: OWASP-aligned secure coding, threat-model thinking around token theft and replay and brute-force protection, MFA and adaptive auth, plus the ability to write a design doc that survives review and translate trade-offs for leadership.

Preferred (Nice to Have)

  • Healthcare integration experience, including EMR and EHR launch patterns, SMART on FHIR, or other regulated-industry SSO work.
  • Identity brokering experience, including Keycloak brokering and first-login flows, or federating with managed platforms such as Google Identity Platform, Azure AD and Entra, or Okta.
  • Observability with Prometheus, Grafana, or ELK, with an eye for authentication anomalies such as login-failure trends, session accumulation, and token-issuance spikes.
  • Cloud security certification (AWS Security Specialty or equivalent) and a Master’s degree in Computer Science or a related field.
Physical Requirements:
  • Prolonged periods of sitting at a desk and working on a computer.
  • Ability to operate a computer and other standard office equipment.
  • Ability to communicate clearly through video, phone, and written channels in a remote-first environment.
  • Occasional travel for team or company meetings may be required.

#LI-GF1 #LI-Remote

Benefits:

This is a senior individual-contributor engineering role. Compensation is a base salary in the range of $135,000 to $150,000 plus an annual discretionary bonus. 

Salaried employees receive DrFirst’s full standard benefits package, which includes:

  • Medical, dental, and vision coverage.
  • Company-paid life and disability insurance.
  • 401(k) retirement plan with company match.
  • Flexible and generous paid time off, plus company holidays.
  • Remote-first work model with home-office support.
  • Parental leave and family support benefits.
  • Professional development and continuing-education support.
  • Employee wellness and assistance programs.

DrFirst is committed to being a Remote-First company, creating a dynamic and flexible workplace where everyone thrives, no matter where they log in from. Check out our approach to remote work: https://drfirst.com/company/about-us/careers/.

Our recruitment process at DrFirst is straightforward and secure. You will only be contacted by our recruitment team through an official @drfirst.com email address. We will never ask you for payment or sensitive personal information, such as your social security number or banking details, at any stage of the hiring process. Additionally, we will not request that you purchase equipment or accept e-checks or checks for deposit. If you encounter any communications claiming to be from DrFirst that seem suspicious, please contact our recruitment team directly at recruiter@drfirst.com to verify the message’s authenticity. Your security is important to us!

Learn more about our benefits and professional development opportunities: https://drfirst.com/company/about-us/careers/the-perks/.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at DrFirst, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.