Abbeal

Careers

Tokyo · Full-time · Senior (6-9 yrs)

Senior Backend Engineer — Authentication & Security Platform (Digital Bank) — Tokyo

Through Abbeal, join the authentication & authorization platform of an FSA-regulated digital bank in Japan. You'll build OAuth2/OIDC flows, FIDO2/passkeys, mTLS and full token lifecycle in Java/Kotlin + Spring Boot. Distributed team (Japan, Vietnam, India), English working language, Japanese not required.

  • Java / Kotlin · Spring Boot
  • Spring Security · OAuth2 / OIDC
  • FIDO2 / WebAuthn · DPoP · mTLS
  • JWT · PKCE · OWASP Top 10
  • Redis · PostgreSQL
  • AWS (ECS/Fargate) · Terraform
Apply¥8M–17M / year depending on experience (indicative)

Location requirement

You must already be living in Japan with valid work authorization. We are not sponsoring relocation or visa transfers from overseas for this role. Applications from outside Japan will not be considered.

The context

We support an FSA-regulated digital bank launching its platform in Japan. You'll join the team building the Authentication & Authorization foundation: OAuth 2.0/OIDC login, token lifecycle and identity management across four banking channels (officer dashboards, customer-facing apps, BaaS APIs, third-party integrations). The team is distributed across Japan, Vietnam and India; the role is anchored on Tokyo with a remote-friendly setup. English is the working language — Japanese is not required.

What you'll build

  • Token lifecycle — DPoP-bound access tokens (RFC 8693), silent refresh, session management
  • Passkey / FIDO2 — WebAuthn registration & login flows, step-up authentication
  • mTLS integrations — certificate-based service-to-service auth with external financial platforms
  • Shared security library — Spring Boot starter providing standardized auth filters
  • Integration testing — Karate-based suites covering all auth flows at scale
  • Monitoring — auth event observability, anomaly detection, audit trail completeness

What we're looking for (must-have)

  • Currently based in Japan with valid work authorization — no relocation or visa sponsorship from overseas for this role
  • 10+ years in server-side backend engineering, including 5 to 7 years in Kotlin or Java + Spring Boot
  • Spring Security (filter chains, OAuth2 Resource Server) and strong OAuth 2.0 / OIDC knowledge
  • At least one of DPoP (RFC 9449), mTLS (RFC 8705), PKCE, FIDO2 / WebAuthn — plus JWT (claims, JWKS, key rotation)
  • Redis (sessions, distributed locking, caching) and PostgreSQL (schema design, migrations)
  • AWS (ECS/Fargate, Secrets Manager) and Terraform or equivalent IaC
  • Strong understanding of the OWASP Top 10 and secure web application development
  • Professional English (reading, writing, verbal) — the working language. Japanese not required

Nice to have

  • Authlete ; FAPI 2.0 Security Profile
  • Microsoft Entra ID (SAML/OIDC federation, FIDO2)
  • Cloudflare / Akamai (mTLS termination, WAF, client certificate forwarding)
  • Fintech / regulated banking background (FSA, maker-checker, audit logging)
  • Japanese language ability (reading / basic communication)

Why this role

  • A real regulated bank (FSA-supervised) — not a startup, not a toy project
  • Cutting-edge security standards: FAPI 2.0, DPoP, WebAuthn/FIDO2
  • High ownership — you own entire authentication channels, end-to-end
  • Global collaboration (Japan, Vietnam, India) on a greenfield platform

The setup

Permanent role. Anchored on Tokyo, distributed team, remote-friendly. Relocation support possible depending on profile.

Apply

Senior Backend Engineer — Authentication & Security Platform (Digital Bank) — Tokyo