About Cerby
At Cerby, security is everyone's business.
Cerby extends your security perimeter to include your disconnected applications, providing identity automation and eliminating manual processes. It's one of the biggest blind spots in enterprise security, and we're the team closing it. If you want to work alongside the team solving one of the hardest, most overlooked problems in security, you're in the right place.
Founded in 2020, Cerby is backed by leading investors and trusted by enterprises across the globe.
At Cerby, software engineers are at the heart of driving technology and product innovation. As the Staff Software Engineer for frontend on the Access Management team, you set the technical direction for the surfaces our customers touch every day and you are accountable for the decisions that outlive any single project.
Access Management owns the foundations of Cerby's SaaS platform: application password management, secure vault systems, authentication protocol integrations with IdP providers, asynchronous background workers for data synchronization, and graph-based RBAC for fine-grained permission control. The frontend for all of that spans a web application, a browser extension, and a shared component library — one codebase family where a single architectural decision compounds across every product surface, and where a single mistake in how we handle credentials reaches every customer.
In this role, you will collaborate with cross-functional teams while owning the quality, scalability, and security of the platform. You will help lead and drive a security-first engineering culture, enhance the product's user experience, and maintain high standards of software delivery. You are also expected to embrace AI as a core part of how we work, actively exploring and incorporating AI tools and practices into your daily development workflow to improve team efficiency and accelerate impact.
Key Responsibilities- Set Technical Direction: Own the multi-quarter architectural roadmap for the team’s frontend. Decide what we build, what we buy, what we deprecate, and what we deliberately leave alone — and write down the reasoning so the next engineer inherits the decision, not just the code.
- Architect Across Surfaces: Design systems that hold up across the web application, the browser extension, and the shared component library. Draw the boundaries between them, own the contracts, and make cross-surface changes safe to ship incrementally.
- Own Frontend Security: Threat-model anything that touches credentials or session state, and treat third-party dependencies as part of the attack surface, from client-side risks through to CVE patching.
- Raise the Engineering Bar: Define and enforce the standards — architecture review, testing strategy, performance budgets, accessibility, code review norms — and make them stick through tooling and automation rather than good intentions.
- Lead AI Adoption as a Discipline: Establish how the team uses AI in day-to-day development — where it accelerates real work, how output gets reviewed, what guardrails apply to security-sensitive code. Use AI to accelerate documentation (runbooks, ADRs, onboarding guides, post-mortems) so the team spends its time on the deep technical conversations that actually transfer expertise. Share learnings openly, including the failures.
- Own Production Quality: Instrument the frontend with well-designed telemetry and observability — metrics, traces, structured logs — so that regressions in performance, reliability, and user experience are caught by data rather than by customers.
- Finish Migrations: Lead framework upgrades, refactors, and deprecations from proposal through to the last call site removed, with measurable outcomes. Staff engineers are the reason a migration completes instead of leaving the codebase in two states forever.
- Remote Collaboration: Operate effectively in a remote-first environment, defaulting to written, asynchronous, high-signal communication across time zones.
- Experience:
- 8+ years of professional software engineering experience, with deep focus on building and scaling SaaS applications.
- Prior experience at Staff, Principal, or equivalent scope — technical leadership of an area without direct reports.
- Track record of leading multi-quarter architectural efforts to completion, with outcomes you can describe concretely.
- Prior experience developing and maintaining distributed applications.
- Experience mentoring senior engineers and conducting security-first code reviews.
- Technical Expertise:
- Experience with React and TypeScript, including building and scaling Single Page Applications for high-performance production use.
- Experience designing, consuming, and optimizing REST APIs with efficient data fetching, caching, and invalidation strategies.
- Experience owning a design system or component library end to end — API design for components, versioning, adoption, and deprecation across consuming teams.
- Experience with tooling at scale: workspace management (PNPM or equivalent), build orchestration, dependency graphs, and release/versioning strategy.
- Deep knowledge of frontend security best practices and the ability to threat-model a feature before it is built.
- Testing strategy, not just test writing: knowing what belongs in unit, integration, and component tests, and designing suites that catch regressions without becoming a maintenance tax.
- Proven ability to instrument systems with well-designed telemetry and observability — metrics, traces, and log management (OpenTelemetry and Datadog experience a plus).
- Designing responsive, maintainable, and accessible UI, applying WCAG guidelines, ARIA roles, and screen reader optimizations to deliver inclusive and compliant experiences.
- Utility-first CSS frameworks such as TailwindCSS, with a clear view of the tradeoffs against the alternatives.
- Ability to own software delivery end to end — design, development, testing, delivery, and production release — writing maintainable, high-quality, scalable, and secure code.
- Nice to have:
- Prior experience in cybersecurity and/or Identity and Access Management (IAM).
- Prior experience in a venture-funded high-growth SaaS startup.
- Resourceful Achiever: Self-motivated, proactive, and adaptable — able to make progress on complex technical challenges without a defined path.
- Product Minded: Strong ability to understand customer value and translate customer needs into software that delivers it, with the judgment to push back on work that won't.
- Precision Executor: Focused on performance, scalability, and reliability, with the discipline to finish what gets started.
- Force Multiplier: Strong interpersonal skills. Actively mentors and sponsors other engineers, and measures success by the team's output rather than their own.
- Clear Communicator: Able to make a complex technical argument in writing to an audience that includes engineers, product, and executives, and to change their mind when someone else's argument is better.
- Lifelong Learner: Continuous curiosity about emerging technologies and industry trends.
- Innovative Thinker: Open to creative solutions, and comfortable navigating and reducing ambiguity for others.
Similar Jobs
What you need to know about the Seattle Tech Scene
Key Facts About Seattle Tech
- Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Amazon, Microsoft, Meta, Google
- Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Madrona, Fuse, Tola, Maveron
- Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute


