About the role
Join If's Integration Security squad and help development teams implement secure authentication, authorization, and identity integrations.
You will review application architecture, source code, and security configuration to identify weaknesses and recommend practical improvements. You will work with development teams, IAM teams, and Group IT Security to resolve findings and strengthen security controls. Our environment includes C#/.NET, Curity, Microsoft Entra ID, and Azure API Management.
Your main responsibilities will be security assessments and technical guidance. The role does not involve daily application development, but may include small scripts, security tests, and reference examples.
What are you going to do?
Review solution architecture, source code, identity configuration, and relevant gateway and deployment settings against applicable IAM security requirements.
Perform IAM-focused white-box security testing of web applications, native applications, and APIs, covering user and system-to-system flows.
Assess how applications, APIs, gateways, and identity platforms establish trust and enforce authentication and authorization.
Document findings with supporting evidence, explain their impact, recommend corrective actions, and verify fixes with development teams.
Provide technical guidance on secure identity integrations and the implementation of IAM security requirements.
Assess central identity platforms and help the responsible teams define and validate security improvements.
Contribute to security guidelines, assessment checks, reference implementations, and automation that improve assessment quality and efficiency.
Support security approval decisions with clear assessment results, unresolved issues, and remaining risks.
What do we expect from you?
Must have
Experience identifying security weaknesses through source code reviews and practical testing of applications or APIs.
Ability to assess security behavior in C#/.NET applications, including configuration, middleware, and libraries.
Practical knowledge of OAuth 2.0, OpenID Connect, JSON Web Tokens, and single sign-on.
Understanding of authentication, authorization, token handling and validation, session management, logout, and related web security controls.
Strong troubleshooting skills: following HTTP traces, analyzing logs, and connecting observed behavior to code and configuration.
An investigative mindset and the judgment to distinguish confirmed weaknesses, unmet requirements, recommendations, and missing evidence.
Ability to explain technical findings clearly, support conclusions with evidence, and work with developers on practical fixes.
Excellent Latvian and English language skills are required for effective day-to-day communication with colleagues both locally and internationally.
Nice to have
Experience with Curity, Microsoft Entra ID, or Azure API Management.
Experience reviewing applications in additional programming languages and frameworks.
Experience developing applications, writing security tests, or using automation and AI-assisted tools for security assessments.
Our promise to you
Monthly salary: €5500 - €7500 gross depending on your qualifications
Strong company culture: knowledge sharing, company events, interesting speakers, and other inspiring initiatives
Career and development opportunities (e.g. 3 dedicated up-skilling days) in the biggest insurance company in the Nordics
Challenging and exciting projects with autonomy to plan own tasks
Extra vacation days, annual bonus, great insurance benefits, discounts on our products for you and your family, gifts, etc.
Possibility of hybrid work, where office is our primary workplace
A recently renovated office in Riga centre with a 24/7 gym on the premises
Read more about benefits for our employees.
Application deadline: November 1, 2026
Your application will be processed according to our privacy notice.