Jobs and Careers
AM

Senior GraphQL Engineer (Security)

Amplitude
San Francisco, United Statesfull_timeVerifiedPosted 22 May 2025
💰 $266,000/yr($161,000/yr$266,000/yr)

About the role

Amplitude is the leading digital analytics platform that helps companies unlock the power of their products. Over 4,000 customers, including Atlassian, NBCUniversal, Under Armour, Shopify, and Jersey Mike’s, rely on Amplitude to gain self-service visibility into the entire customer journey. Amplitude guides companies every step of the way as they capture data they can trust, uncover clear insights about customer behavior, and take faster action. When teams understand how people are using their products, they can deliver better product experiences that drive growth. Amplitude is the best-in-class analytics solution for product, data, and marketing teams, ranked #1 in multiple categories in G2’s Spring 2025 Report. Learn how to optimize your digital products and business at amplitude.com.

As an organization, we approach challenges with humility, take ownership of our contributions, and embrace a growth mindset that pushes us to constantly improve ourselves, each other, and the value we bring to customers and partners.

Amplitude’s Commitment to Diversity Equity & Inclusion (DEI): Amplitude believes that diversity enables the creation of better products, improves the ability to solve complex problems, and drives more powerful solutions. We strive to create an environment of inclusion—one focused on psychological safety, empathy, and human connection—that will allow employees of all backgrounds to thrive.

About the Role:

We're looking for a Senior Full-Stack Engineer with deep experience in GraphQL development and a strong understanding of API security best practices. You’ll be responsible for designing, building, and securing GraphQL services that power critical features in our platform.

You'll collaborate closely with product, frontend, and backend teams to ensure GraphQL APIs are not only performant and scalable, but also secure by design, incorporating principles such as role-based access control (RBAC), audit logging, input validation, and resolver-level authorization.

You’ll play a key role in evolving our GraphQL infrastructure and setting the standard for secure and maintainable API development across the engineering org.

 

Key Responsibilities:

  • Design, develop, and maintain robust and scalable GraphQL APIs for core features and services
  • Implement security controls within the GraphQL layer, including:
    • RBAC or ABAC models enforced at the resolver level
    • Query complexity and depth limiting to prevent DoS
    • Auditable logging for sensitive GraphQL operations
    • Input validation and type safety for all queries/mutations
  • Work closely with backend and frontend engineers to ensure GraphQL usage patterns are efficient and secure
  • Help define best practices for GraphQL schema design, versioning, and access control
  • Identify and remediate security issues in GraphQL endpoints proactively, collaborating with application security engineers when necessary
  • Partner with engineering to identify and mitigate risks in architecture, design, and implementation stages
  • Identify opportunities to fix systemic gaps, reduce recurring pain points, and avoid reactive “whack-a-mole” cycles
  • Participate in an on-call rotation to resolve critical/high-risk security issues as well as respond to security incidents with urgency and clarity
  • Stay up to date with emerging threats and defensive patterns in GraphQL security

 

What We’re Looking For:

  • 4+ years of experience as a software engineer, with at least 2+ years working with GraphQL in production systems
  • Proven experience building and maintaining secure, large-scale APIs, particularly using GraphQL, TypeScript, Python, or Java
  • Strong understanding of authentication and authorization, especially as it applies to API design (e.g., JWT, OAuth2, resolver-level access control)
  • Familiarity with audit logging, rate limiting, and schema hardening
  • Comfortable collaborating cross-functionally to align API security with product needs and developer experience
  • Willingness to go above and beyond, including submitting fixes and supporting teams directly when needed
  • Experience using AI to automate tasks is a significant plus (e.g. log analysis, code review, alert triage)
  • Familiarity with application security concepts is preferred, but not required

 

Who We Are

The Company: Amplitude is filled with humble, life-long learners who are eager to help one another and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Amplitude

View company profile →