You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
Collaborate on projects such as implementing passwordless remote access and designing solutions for cross-platform certificate management. * Help shape our approach to secure access, providing ...
Collaborate on projects such as implementing passwordless remote access and designing solutions for cross-platform certificate management. * Help shape our approach to secure access, providing ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
Collaborate on projects such as implementing passwordless remote access and designing solutions for cross-platform certificate management. * Help shape our approach to secure access, providing ...
Collaborate on projects such as implementing passwordless remote access and designing solutions for cross-platform certificate management. * Help shape our approach to secure access, providing ...
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
Okta Architect
Washington, DC · On-site
Implement advanced security measures, including phishing-resistant MFA (e.g., FIDO2, Okta FastPass) and passwordless authentication. * Ensure compliance with federal security frameworks, including ...
Okta Architect
Washington, DC · On-site
Implement advanced security measures, including phishing-resistant MFA (e.g., FIDO2, Okta FastPass) and passwordless authentication. * Ensure compliance with federal security frameworks, including ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
Regional Channel Lead (Security & Identity) - East
Atlanta, GA · On-site
$175K - $250K/yr
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
Regional Channel Lead (Security & Identity) - East
Atlanta, GA · On-site
$175K - $250K/yr
Help Us Build the Future of Passwordless Security The Opportunity: Build Something That Matters Most "Channel" roles are about managing a declining spreadsheet of legacy partners. This is not that ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
IAM Architect
$135K - $170K/yr
Experience with passkeys/passwordless authentication, external identities, workload Conditional Access policies, and identity automation. * Exposure to SAP or HRIS integrations and joiner/mover ...
IAM Architect
$135K - $170K/yr
Experience with passkeys/passwordless authentication, external identities, workload Conditional Access policies, and identity automation. * Exposure to SAP or HRIS integrations and joiner/mover ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
You'll own and evolve Subway's Customer Identity platform -- built on AWS Cognito -- delivering secure, seamless login experiences including passwordless authentication and social sign-on across ...
Microsoft Entra ID, Duo, Okta, Ping Identity Working knowledge of Zero Trust, FIDO2, passwordless, and phishing-resistant MFA concepts. Experience applying IGA controls for diverse user types ...
Quick apply
Microsoft Entra ID, Duo, Okta, Ping Identity Working knowledge of Zero Trust, FIDO2, passwordless, and phishing-resistant MFA concepts. Experience applying IGA controls for diverse user types ...
ICAM Architect with Security Clearance
$86K - $198K/yr
From single sign-on and federation to privileged access and passwordless authentication, this is an opportunity to architect secure, enterprise-grade identity solutions that protect critical systems ...
ICAM Architect with Security Clearance
$86K - $198K/yr
From single sign-on and federation to privileged access and passwordless authentication, this is an opportunity to architect secure, enterprise-grade identity solutions that protect critical systems ...
Sr IAM Software Engineer
Las Vegas, NV · On-site
$109K - $149K/yr
This hands-on role serves as a technical subject matter expert for identity lifecycle management, RBAC, PIM/PAM, MFA, SSO, and Zero Trust access controls (e.g., Conditional Access and passwordless)
Sr IAM Software Engineer
Las Vegas, NV · On-site
$109K - $149K/yr
This hands-on role serves as a technical subject matter expert for identity lifecycle management, RBAC, PIM/PAM, MFA, SSO, and Zero Trust access controls (e.g., Conditional Access and passwordless)
Strategic Account Executive
Atlanta, GA · On-site
$135K - $155K/yr
Lead the Passwordless Revolution: Create and execute a territory strategy specifically designed to evangelize PingOne Recognize, targeting organizations burdened by legacy MFA and high-friction ...
Quick apply
Strategic Account Executive
Atlanta, GA · On-site
$135K - $155K/yr
Lead the Passwordless Revolution: Create and execute a territory strategy specifically designed to evangelize PingOne Recognize, targeting organizations burdened by legacy MFA and high-friction ...
ICAM Architect
Mclean, VA · On-site
$86K - $198K/yr
From single sign-on and federation to privileged access and passwordless authentication, this is an opportunity to architect secure, enterprise-grade identity solutions that protect critical systems ...
ICAM Architect
Mclean, VA · On-site
$86K - $198K/yr
From single sign-on and federation to privileged access and passwordless authentication, this is an opportunity to architect secure, enterprise-grade identity solutions that protect critical systems ...
Sr API & ID (Senior Software Engineer, Identity & APIs)
Shelton, CT · On-site
$119K - $149K/yr
You'll own and evolve Subway's Customer Identity platform - built on AWS Cognito - delivering secure, seamless login experiences including passwordless authentication and social sign-on across Mobile ...
Sr API & ID (Senior Software Engineer, Identity & APIs)
Shelton, CT · On-site
$119K - $149K/yr
You'll own and evolve Subway's Customer Identity platform - built on AWS Cognito - delivering secure, seamless login experiences including passwordless authentication and social sign-on across Mobile ...
Passwordless information
What are the key skills and qualifications needed to thrive as a Passwordless Authentication Engineer, and why are they important?
What is the difference between Passwordless vs Network Security Specialist?
| Aspect | Passwordless | Network Security Specialist |
|---|---|---|
| Credentials/Certifications | Biometric, token-based, or passwordless authentication certifications | Network security, CISSP, CEH certifications |
| Work Environment | IT security teams, cybersecurity firms, tech companies | IT departments, cybersecurity firms, enterprise networks |
| Industry Usage | Authentication solutions, identity management | Network protection, threat mitigation |
| Search/Comparison Intent | Understanding authentication methods | Securing networks and infrastructure |
While Passwordless focuses on authentication methods that eliminate passwords using biometrics or tokens, Network Security Specialists concentrate on protecting entire networks from threats. Both roles are vital in cybersecurity but serve different functions: one enhances user access security, the other safeguards network infrastructure.
What are the main responsibilities of a Passwordless Authentication Engineer on a security team?
What does 'passwordless' mean in the context of cybersecurity jobs?
$119K - $149K/yr
Other
Medical, Life, Retirement
Posted 8 days ago
Subway rating
4.5
Based on 1,996 frontline employees who took The Breakroom Quiz
89th of 103 rated fast food restaurants
Job description
Senior Software Engineer, Identity & APIs
Ready to build what’s next with one of the world’s most iconic brands?
Why Join Subway?
At Subway, we are not standing still. We are building.
This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.
You will not just do the work. You will shape it.
We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.
If you bring energy, accountability and a bias for action, you will fit right in.
We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.
This is your chance to be part of what’s next.
About the Role:
Subway is on a mission to build a world-class digital platform that serves millions of guests and thousands of franchise locations globally. The Senior Software Engineer, Identity & APIs is a key technical contributor on the team responsible for how guests authenticate and interact with Subway’s digital ecosystem.
You’ll own and evolve Subway’s Customer Identity platform — built on AWS Cognito — delivering secure, seamless login experiences including passwordless authentication and social sign-on across Mobile App, Web, and Kiosk. You’ll bring deep expertise in security engineering and data privacy compliance, ensuring Subway’s identity infrastructure meets CCPA, GDPR, and global regulatory standards. AI-assisted development is a core part of how our team works.
Responsibilities include but not limited to:
- Own the design, development, and operation of Subway’s Customer Identity platform — built on AWS Cognito — supporting passwordless authentication, social sign-on (Google, Apple), and traditional credential flows across Mobile App, Web, and Kiosk channels.
- Enforce security best practices and data privacy compliance (CCPA, GDPR, and evolving global regulations) across all identity and API surfaces. Conduct security design reviews, threat modeling, and privacy-by-design assessments.
- Design, develop, and document APIs and middleware integrations that connect identity services with Subway’s front-end applications and back-end systems.
- Leverage AI-assisted development tools (GitHub Copilot, Claude, and similar) as a core part of daily engineering work. Champion AI tooling adoption across the team.
- Collaborate with product, legal, and security stakeholders to translate regulatory requirements and business needs into scalable, compliant identity architecture.
- Conduct code reviews with a security and privacy lens; provide mentorship to peers on identity patterns and secure coding standards.
Qualifications (some examples listed below):
- 5 or more years of hands-on production software development experience.
- Demonstrated experience designing and operating Customer Identity platforms — AWS Cognito strongly preferred.
- Hands-on experience implementing passwordless authentication (magic links, passkeys/WebAuthn, OTP) and social sign-on (OAuth 2.0 / OIDC with Google, Apple).
- Deep knowledge of identity and authentication standards: OAuth 2.0, OpenID Connect, SAML, JWT, and session management best practices.
- Proven expertise in security engineering: threat modeling, secure SDLC, OWASP Top 10, and identity attack mitigations.
- Hands-on experience with data privacy compliance — CCPA and GDPR at minimum.
- Strong proficiency in one or more of: JavaScript/TypeScript (Node.js), Java, or C#.
- Proficiency with AI-assisted development tools (GitHub Copilot, Claude, or equivalent).
- Bachelor’s degree or higher in Computer Science, Software Engineering, or a related field (or equivalent practical experience).
- People Management: No | Department: Guest Technology | Location: Shelton, CT (USA) | Scope: Global | Travel: Less than 10%.
What do we offer?
- Insurance Plans (Medical, Life)
- Pension/401K/RSP (country specific)
- Competitive Bonus
- Mobility Allowance
- Tuition Reimbursement
- Company Holidays
- Volunteering time
- And More……
Compensation: The base pay range for this role is $119,200 - $149,000 annually
Pay within this range will be determined in good faith based on job-related factors, which may include skills, experience, education/training, location, and internal equity.