DrFirst, Inc.

Senior Engineer - Identity Platform

DrFirst, Inc.  •  $135k - $150k/yr  •  United States (Remote)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About DrFirst

For 25 years, DrFirst has empowered providers and patients to achieve better health through intelligent medication management. We improve healthcare workflows and help patients start and stay on therapy with end-to-end solutions that enhance prescription access, affordability, and adherence. Our solutions help 100 million patients a year and are used by more than 420,000 prescribers, 71,000 pharmacies, 270 EHRs and health information systems, and over 2,000 hospitals in the U.S. This is a great opportunity to be a part of a successful Healthcare IT company experiencing significant growth. Here you’ll get to work with some of the smartest and most interesting people around, solving unique and complex challenges in healthcare on a scale matched by few companies. If you get excited about stretching yourself in new ways, developing yourself to your fullest potential, and care about working with smart colleagues, we want to talk to you!

Every day, tens of thousands of clinicians launch into DrFirst applications to prescribe medications and manage patient care, and every launch flows through the identity platform. This role is the technical anchor for a production IAM platform built on Keycloak. It spans custom SPI development in Java, a major-version migration, standards-based modernization of partner SSO, and the session architecture behind a national e-prescribing network.

This is platform ownership, not an integration seat. You will operate a living system with real scale, real incidents, and real migration deadlines, and you will hold the mandate to modernize it. You will regularly be the person who can read a JVM GC log, a Postgres session table, and an OAuth spec in the same afternoon. If you have wanted to be the engineer who both writes the custom grant provider and decides whether it should exist, this is that seat.

What you will work on

  • Keycloak Extension (SPI) Development: Design, build, and refactor custom Keycloak SPIs in Java, including authenticators, grant-type providers, mappers, and just-in-time provisioning. EMR SSO integrations run on custom extension code you will own end to end.
  • Standards-Based Auth Modernization: Lead the migration of proprietary partner SSO flows to modern OAuth 2.0 and OIDC patterns, including JWT Bearer grants (RFC 7523), Token Exchange (RFC 8693), authorization code plus PKCE, and BFF architectures for web clients, making and defending the architectural calls.
  • Major Version Migration: Drive the Keycloak major-version upgrade, including the shift from external Infinispan session caching with JDBC persistence to persistent user sessions, and validate every downstream integration against the new version.
  • Session and Token Architecture: Own the session lifecycle model across SSO, client, and offline sessions, including idle and max semantics, token lifespans, and refresh rotation, and design per-client TTL policies that balance clinical workflow UX against security posture.
  • Production Ownership and Incident Response: Serve as the deep-diagnosis engineer for JVM tuning (heap, Metaspace, GC), Infinispan cluster behavior, PostgreSQL session-store forensics, and log-driven root-cause analysis on live authentication traffic.
  • Federation and Platform Hygiene: Design integrations with external identity systems (OIDC, SAML, cloud identity platforms), including JWKS trust, key rotation, and audience and issuer validation, and treat realm and client configuration as version-controlled, least-privilege, auditable code.
  • Technical Mentorship: Raise the bar on OAuth and OIDC fluency and secure coding across the team, and represent the platform technical position to application teams and leadership.

Qualifications

Required

  • 6+ years of professional software engineering with strong, production-grade Java, including significant focus on Identity and Access Management.
  • Expert Keycloak experience beyond the admin console, with hands-on SPI and extension development, realm and client architecture for multi-tenant platforms, and running Keycloak (Quarkus) in production on Kubernetes.
  • Deep OAuth 2.0 and OIDC fluency, including authorization code plus PKCE, client credentials, Token Exchange (RFC 8693), JWT Bearer (RFC 7523), and refresh rotation. Working knowledge of SAML 2.0.
  • Session and token architecture depth: stateful SSO sessions versus stateless JWT validation, online versus offline sessions, idle and max semantics, and JWKS validation and key rotation, with the judgment to choose per use case.
  • Hands-on distributed caching and state with Infinispan or comparable technology, including clustering, persistence, expiration, and the failure modes of distributed session state.
  • Production operations skill: JVM performance analysis (GC logs, heap and Metaspace sizing), correlating structured logs, and SQL-level investigation in PostgreSQL against live systems.
  • Security fundamentals and communication: OWASP-aligned secure coding, threat-model thinking around token theft and replay and brute-force protection, MFA and adaptive auth, plus the ability to write a design doc that survives review and translate trade-offs for leadership.

Preferred (Nice to Have)

  • Healthcare integration experience, including EMR and EHR launch patterns, SMART on FHIR, or other regulated-industry SSO work.
  • Identity brokering experience, including Keycloak brokering and first-login flows, or federating with managed platforms such as Google Identity Platform, Azure AD and Entra, or Okta.
  • Observability with Prometheus, Grafana, or ELK, with an eye for authentication anomalies such as login-failure trends, session accumulation, and token-issuance spikes.
  • Cloud security certification (AWS Security Specialty or equivalent) and a Master’s degree in Computer Science or a related field.

Physical Requirements

  • Prolonged periods of sitting at a desk and working on a computer.
  • Ability to operate a computer and other standard office equipment.
  • Ability to communicate clearly through video, phone, and written channels in a remote-first environment.
  • Occasional travel for team or company meetings may be required.

#LI-GF1 #LI-Remote

Benefits

This is a senior individual-contributor engineering role. Compensation is a base salary in the range of $135,000 to $150,000 plus an annual discretionary bonus.

Salaried employees receive DrFirst’s full standard benefits package, which includes:

  • Medical, dental, and vision coverage.
  • Company-paid life and disability insurance.
  • 401(k) retirement plan with company match.
  • Flexible and generous paid time off, plus company holidays.
  • Remote-first work model with home-office support.
  • Parental leave and family support benefits.
  • Professional development and continuing-education support.
  • Employee wellness and assistance programs.

DrFirst is committed to being a Remote-First company, creating a dynamic and flexible workplace where everyone thrives, no matter where they log in from. Check out our approach to remote work: https://drfirst.com/company/about-us/careers/.

Our recruitment process at DrFirst is straightforward and secure. You will only be contacted by our recruitment team through an official @drfirst.com email address. We will never ask you for payment or sensitive personal information, such as your social security number or banking details, at any stage of the hiring process. Additionally, we will not request that you purchase equipment or accept e-checks or checks for deposit. If you encounter any communications claiming to be from DrFirst that seem suspicious, please contact our recruitment team directly at recruiter@drfirst.com to verify the message’s authenticity. Your security is important to us!

Learn more about our benefits and professional development opportunities: https://drfirst.com/company/about-us/careers/the-perks/.

DrFirst, Inc.

About DrFirst, Inc.

DrFirst has been transforming medication management for 25 years, helping providers and patients navigate a complex and often fragmented healthcare system.

After all, “first” isn’t just in our name—it’s a fundamental part of who we are as a company.

We were first to bring real-time price transparency into prescribing workflows and first to enable e-prescribing for controlled substances—solutions that are now standard across the industry.

DrFirst has won over 25 awards for excellence and innovation, including winning Gold in the prestigious Edison Awards in 2023, recognizing our game-changing use of clinical-grade AI to streamline time-consuming healthcare workflows and prevent medication errors.

Why It Matters: Medication management is full of roadblocks such as friction-filled workflows, outdated systems, regulatory complexity, and disconnected stakeholders. The result? Delays in care, high medication abandonment rates, and poor adherence that negatively impact patient outcomes.

DrFirst tackles these challenges with end-to-end solutions that support:

Prescribing: Adaptable workflows that deliver the right information at the right time to boost efficiency and improve outcomes.

Adherence: Innovative solutions that inform patients and providers to increase medication access and affordability.

Optimization: Clinical-grade AI that aggregates fragmented data from multiple sources and fills-in gaps to deliver clean, complete, and consumable information at the point of care.

Industry
Healthcare & Social Services
Company Size
201-500 employees
Headquarters
Rockville, MD
Year Founded
2000
Social Media