Loading this job…
Authentication is the one part of a product that is only noticed when it fails. MailerMen has three kinds of user, candidate, employer and internal admin, and the rules about who can see what have accumulated in places they should never have landed. Six months on this team means untangling that.
You will move our JWT handling onto short lived access tokens with rotating refresh tokens, store those refresh tokens hashed so a database leak is not a session leak, and add per device revocation so a user can log out everywhere. Next comes a middleware based role and permission layer to replace the scattered conditionals in our Express routes, then email verification and password reset flows that survive someone clicking the link twice.
You will not be handed security work and left alone with it. Every change goes through design review before you write code and a second pair of eyes before it merges. You will be in our Delhi NCR office on a hybrid schedule, and you should finish these six months understanding auth better than most engineers with a couple of years behind them.
MailerMen runs a verified job board covering startup and product roles across twelve markets, and takes on interns across engineering, data, design and marketing to build it.