Zürich Versicherungs-Gesellschaft AG
Senior Platform Engineer - Identity & Security
📍 Zürich
Rolle und Verantwortlichkeiten
Set the technical direction for how our team engineers identity and security in an era where coding shifts toward becoming a commodity, through concepts, principles, and reference architectures that others in the team and beyond will build on and bring the team along on that journey. Shape the evolution and operations of our Enterprise Identity Platform (strategic focus: Keycloak), including OAuth 2.0, OIDC, SAML, and PKCE, while steering the phase out of our legacy federation and extend our security posture into event-driven and AI-augmented workflows. Develop and articulate the target picture for identity and security in the age of Agentic AI, from access management and security concepts for AI agents, agentic workflows, and workload identity, to fine-grained authorization (OpenFGA, OPA, Cedar) and Zero Trust. Set engineering standards, reviews, and quality gates across internal teams, partners, and AI-augmented workflows - ensuring quality, security, and knowledge transfer. Partner with business domains and Digital Products to translate insurance requirements into robust identity and security outcomes.
Team / Beschreibung
In the Engineering and Integration team, we connect what's separated, secure what matters, and reveal what's hidden, while shaping how integration, identity, and security work in a world of Agentic AI, hybrid delivery, and Zero Trust. We're modernising our identity platform around Keycloak, embedding Zero Trust and fine-grained authorization as the default, and building the identity foundations for an AI-augmented enterprise. We're an agile, collaborative team with a strong network across Business Unit Switzerland. Together with all IT departments, we combine deep technical expertise with a clear focus on delivery and outstanding service to our stakeholders.
Qualifikationen und Fähigkeiten
7+ years in software or security engineering - ideally in insurance, banking, or a related financial services industry - with deep expertise in modern authentication (OAuth 2.0, OIDC, SAML, PKCE, token lifecycle, federation, LDAP) and hands-on Keycloak experience
Hands-on experience with Agentic AI access management and security concepts (agent identity, agent-to-agent auth, MCP security, prompt injection defense, supply chain security for AI components) and a critical eye for the limitations of AI-augmented development (Copilot, Claude, agentic workflows)
Solid understanding of fine-grained authorization (OpenFGA, OPA, Cedar), Zero Trust, and cloud-native engineering (Azure and/or AWS, containers, event streaming)
Strong sense of E2E ownership, business curiosity, ability to translate business intent into technical specifications, critical thinking and reflection, and ability to apply principles, name risks, surface trade-offs and manage ambiguity, paired with strong communication skills that earn trust and bring senior engineers along
Fluent in English, both spoken and written, German is a plus