Implements the AAA subsystem — RADIUS and TACACS+ — and user access control, under the Principal Engineer's guidance.
Key Responsibilities
- Implement the AAA framework — authentication, authorization, and accounting flows — and the local user database with privilege levels
- Implement the RADIUS client (RFC 2865/2866) — Access-Request/Accept/Reject, PAP/CHAP authentication, and accounting
- Implement the TACACS+ client (RFC 8907) — authentication, command authorization, and command/connection accounting
- Write comprehensive unit tests for authentication, authorization, and accounting flows, including error and fallback scenarios
- Debug AAA issues by tracing authentication flow and analyzing RADIUS/TACACS+ packets with Wireshark
Requirements
- 0-3 years of software development experience (fresh graduates with strong security/networking skills welcome)
- Strong understanding of authentication and access control concepts
- Hands-on experience with C or Python programming (coursework or personal projects)
- Basic knowledge of network security and user management systems
Nice to Have
- Personal projects involving authentication systems or security protocols
- Open-source contributions to AAA systems (FreeRADIUS, tac_plus, PAM modules)
- Familiarity with 802.1X and EAP protocols
- Understanding of multi-factor authentication (MFA) systems
Key Skills
What You’ll Gain
- Hands-on experience with production-grade AAA and access control systems
- Mentorship from experienced Principal Engineers and Security Architects
- Deep technical skills in authentication protocols and network security
- Career growth path to Senior Engineer and Security Specialist roles