Blacklight Network

3 jobs near Columbus, OH

Identity Engineer

Columbus, OH · On-site

$130K - $170K/yr

About Us Blacklight is a network that knows and verifies who, or what, is on it. Every machine, AI agent, and person gets a built-in, unforgeable identity, with security baked into the network itself.

Posted today

Conformal Coating Operator

Plano, TX · On-site

$18.50 - $21.50/hr

Inspect quality control using blacklight to identify areas missed by the machine and apply ... Headquartered in Hanover, Md., Aerotek operates a unified network of over 200 offices across North ...

New

Identity Engineer

Blacklight Network

Columbus, OH • On-site

$130K - $170K/yr

Other

Medical, Dental, Vision, Life, Retirement

Posted 11 hours ago

Posted today


Job description

Location: Columbus, OH (in-person preferred, hybrid possible for the right person)


Full-time · Early stage, backed by Drive Capital


Base: $130,000 to $170,000 + potential early-team equity + 100% paid entire-family medical, dental, vision, and life insurance.


About Us


Blacklight is a network that knows and verifies who, or what, is on it. Every machine, AI agent, and person gets a built-in, unforgeable identity, with security baked into the network itself.


We are a small, early-stage company backed by Drive Capital. We are quiet about product specifics right now and will share more as conversations progress. What we can say up front is the shape of the problem.


Almost every system in use today authenticates a connection. Very few authenticate the thing on the other end in a way that holds up to scrutiny after the fact. That was a tolerable gap when the things on the other end were people. It is a serious one now that they are also services, devices, and AI agents acting with real authority.


We are building identity infrastructure where an enrolled human, agent, device, or service is cryptographically attributable before it is allowed to act.


Why This Role


You would be the first identity hire, working directly with the CTO and the founding team. There is no legacy system, no accumulated compromise, and no committee. There is also nowhere to hide, which is the honest version of the pitch.


What You Will Own


- The certificate authority. Root and intermediate design, offline root custody, issuance policy, rotation, revocation, and a recovery path that actually works when someone tries it at 2am.

- Enrollment lifecycles that keep sponsor, human, agent, device, service, and network authorization as distinct concepts rather than collapsing them into one blurry credential.

- Making every protected path attributable to an enrolled identity, with explicit authorization, expiration, revocation, and evidence an auditor can read.

- Key custody design that keeps long-lived private keys out of application and agent reasoning environments while preserving an operable break-glass path.

- Backup, escrow, and cleanroom recovery practices, plus your part of incident response.

- The runbooks, decision records, and reproducible tests that turn all of the above from a design into a system someone else can operate.


What We Need


- You have designed and operated a certificate authority in production, including the unglamorous parts: rotation, revocation, escrow, and recovery.

- Working fluency in mTLS, X.509, and certificate enrollment protocols. You know where the standards are silent and what people do about it.

- Real experience with modern authentication and identity standards: FIDO/WebAuthn, OAuth 2.0, OpenID Connect. You can explain the failure modes, not just the flows.

- Sound judgment on cryptographic keys, credential custody, access control, and auditability. You back security claims with tests and observable evidence rather than assertion.

- You have run production Linux and container infrastructure, and you translate designs into reviewable configuration, automation, and tests.

- You have been on call for something you built. Ideally for a CA, identity, or network incident.


Strong Plus


- SPIFFE/SPIRE, workload identity, or WIMSE.

- NIST SP 800-207 (zero trust architecture) and SP 800-63 (digital identity guidelines).

- Hardware-backed keys: TPMs, HSMs, secure enclaves, or mobile/eSIM/eUICC identity.

- Nostr, secp256k1, or other signed-event cryptographic identity systems.

- Secure device enrollment, transparent egress controls, or privacy-preserving telemetry.


How We Work


We use AI agents heavily in our own engineering. We expect you to direct and review agent output productively, and to design controls that do not depend on agents behaving perfectly. Skepticism about agents is welcome. Refusal to work alongside them is not.


We start with small, testable systems, document their limits honestly, and evolve them. Temporary shortcuts get a written expiration date.


You write clear decision records and runbooks. You are comfortable learning adjacent domains quickly.


Compensation


Base: $130,000 to $170,000, plus potential meaningful early-team equity.


We pay 100% of a top-tier medical, dental, and vision plan for you and your dependents. Not a percentage, not employee-only, not a high-deductible plan we picked because it was cheap. Full coverage for your whole family. We also offer a 401(k).


That benefit is worth real money and we mention it up front because most postings bury it. If you have a family, run the math against what you are paying today before comparing base numbers.


Process


1. 30-minute conversation with our COO and CTO.

2. 60-minute technical conversation with our CTO.

3. A paid half-day design exercise on a real problem, reviewed by the founding team.

4. References and offer.


We aim to go start to finish in under three weeks.


How to Apply


Email careers@blacklight.network with the subject line Identity Engineer. Send a resume or a link to your work. If you want to add a few sentences, tell us about a system you built or operated where identity was the hard part, and what broke.


We read every application and we reply.



Blacklight Network is an equal opportunity employer. We evaluate every applicant on merit and do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by federal, state, or local law. If you need an accommodation at any point in the process, tell us and we will work with you.


Applicants must be authorized to work in the United States. We are not able to sponsor or transfer employment visas at this time.