Java Spring Authentication and Notifications Microservices Development -- 2

Job ID: 39922315

Budget: €6 – €12 EUR

What we’re building

A standalone Authentication microservice with event-driven orchestration via Kafka and a separate Notifications microservice for OTP delivery (email/SMS/push). It issues short-lived access tokens and manages MFA, sessions, and security audits for a broader microservices platform.

Why it matters

Secure, reliable identity is the foundation of everything else. We’re building a clean, standards-aligned auth core that’s easy to integrate, scales horizontally, and is pleasant for developers to extend and operate.

Core components

Auth Service (REST APIs): sign-up, login, MFA, token issuance/rotation, session/device management, admin endpoints.

Kafka topics: auth events & commands; notifications commands & delivery events.

Notifications Service: templated OTP and security alerts via pluggable providers (SMTP/SMS/push).

State & cache: SQL DB for identities/sessions; Redis for short-lived artifacts (OTP, rate limiting).

Observability: structured logs, metrics, traces; correlation IDs across services.

Guiding principles

Security first: OWASP ASVS L2+, robust password hashing, strict token scopes, privacy by design.

Event-driven: Everything important emits an event; side effects handled by subscribers.

Stateless where possible: Scale via replicas; state isolated to DB/Redis/Kafka.

Clean contracts: OpenAPI for REST, AsyncAPI for events. Backward-compatible changes.

Tech you’ll touch

APIs: REST (+ webhooks optional), JWT access tokens, opaque refresh tokens with rotation.

MFA: TOTP by default, OTP via email/SMS; WebAuthn/FIDO2 optional.

Platform: Kafka, SQL (PostgreSQL/MySQL), Redis, containerized runtime, CI/CD, Prometheus/Grafana, OpenTelemetry.

Reliability targets

High availability of auth paths; OTP delivery with retries and dead-letter queues.

Clear RTO/RPO objectives, tested restoration runbooks, and immutable audit logs.

What you’ll do

Ship features in auth flows (registration, MFA UX, session management).

Extend event schemas and consumers; improve delivery guarantees.

Harden security controls and observability; reduce p95 latencies.

Evolve admin tooling (search, exports, audits) and RBAC.

What we value

Pragmatic engineering and crisp interfaces.

Testability (unit/integration/contract), measurable SLOs.

Empathy for downstream teams integrating our service.

Nice to have

Experience with identity (OAuth2/OIDC), Kafka, distributed tracing, and secure coding practices.

Familiarity with delivery pipelines, blue/green or canary releases.

Where we are & what’s next

Specs drafted; baseline schemas defined.

Next milestones: finalize contracts (OpenAPI/AsyncAPI), ship MFA flows, productionize notifications, and tighten observability.

If this sounds like your kind of work—high-impact security primitives, clear contracts, and real scale—let’s talk.