Rodeo
Get started

eTeam

Policy-as-Code & Authorisation Engineer

Northampton
£402/day
Posted about 13 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Policy-as-Code & Authorisation Engineer

Location: Northampton
Duration: Until 31/05/2027
Pay Rate: £402 per day all inc. (PAYE through Umbrella)
Days on site: 2-3 days onsite/week
Sector: Banking

Role Description

We are seeking an experienced Policy-as-Code & Authorisation Engineer to design, implement, and operate the policy decision capabilities that sit at the core of a modern authorization platform.

The successful candidate will be responsible for developing scalable and maintainable authorization policies using Open Policy Agent (OPA) and Rego, enabling fine-grained access control through centralized, auditable, and high-performance policy decisions.

This role combines expertise in authorization architecture, policy engineering, event-driven systems, and platform integration to deliver secure, explainable, and resilient access control solutions.

Key Responsibilities

  • Design, develop, test, and optimize Rego policies using advanced capabilities such as comprehensions, data references, defaults, partial evaluation, and policy modularization.
  • Implement and manage authorization models including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Relationship-Based Access Control (ReBAC).
  • Translate business, compliance, and security requirements into scalable and maintainable policy-as-code solutions.
  • Build, sign, distribute, version, and manage OPA policy bundles, ensuring secure deployment, rollback, and hot-reload capabilities.
  • Integrate OPA with enterprise platforms including Kafka, HTTP services, Vault, identity platforms, and other authorization ecosystem components.
  • Design and implement authorization decision evidence, ensuring decisions are traceable to specific policy versions, entitlement data, and access-control states.
  • Develop scope-based authorization models that return restriction identifiers for downstream enforcement rather than overexposing data.
  • Optimize policy decision performance, latency, and memory utilization for high-volume, real-time authorization workloads.
  • Build supporting Java/Spring Boot services, adapters, APIs, and integration components for policy evaluation platforms.
  • Develop and maintain automated testing frameworks, CI/CD pipelines, and operational dashboards for policy lifecycle management.
  • Collaborate with security, engineering, platform, and product teams to ensure consistent, enterprise-wide authorization standards.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Required Skills & Experience

  • Strong hands-on experience with Open Policy Agent (OPA) and Rego in production or enterprise-scale environments.
  • Deep understanding of authorization architectures, including Policy Decision Points (PDP), Policy Enforcement Points (PEP), Policy Information Points (PIP), and fail-closed security models.
  • Practical experience designing and implementing RBAC, ABAC, and ReBAC authorization frameworks.
  • Expertise in creating, testing, deploying, and governing policy lifecycles through Policy-as-Code methodologies.
  • Strong proficiency in Java and Spring Boot for integration development and supporting authorization services.
  • Experience developing automated policy testing, performance testing, and CI/CD quality-gate controls.
  • Hands-on experience with Apache Kafka, event-driven architectures, and authorization event processing.
  • Experience with Docker, GitLab CI/CD, and containerized application deployment.
  • Strong analytical and troubleshooting skills across complex access-control and identity ecosystems.
  • Proven commitment to Test-Driven Development (TDD) and engineering best practices.
  • Experience using AI-assisted engineering tools such as Claude Code, GitHub Copilot, or equivalent technologies while applying robust validation and governance controls.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Skills

  • Deep knowledge of OPA plugin architecture, bundle signing, and advanced policy distribution patterns.
  • Experience with policy caching, distributed authorization architectures, and high-performance decision optimization.
  • Familiarity with Envoy ext_authz, Spring Cloud Gateway, or API gateway authorization integrations.
  • Experience in Access Governance, Identity & Access Management (IAM), Entitlement Management, and Audit Controls.
  • Strong understanding of regulated environments such as Banking, Financial Services, Insurance, or Government sectors.
  • Knowledge of observability solutions including OpenTelemetry, Prometheus, Grafana, and distributed tracing frameworks.

If you are interested in this position and would like to learn more, please send through your CV and we will get in touch with you as soon as possible. Please note, candidates are often Shortlisted within 48 hours.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Northampton, England, United Kingdom

Sign up to applySee more jobs like this