Principal Software Engineer (Identity & Access Management) (Madrid)

Principal Software Engineer (Identity & Access Management) (Madrid)

22 sep
|
Sezzle
|
Madrid

22 sep

Sezzle

Madrid

- We are seeking a talented and motivated best-in-class Principal Software Engineer to own and lead the evolution of authentication and authorization at Sezzle. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement
- Sezzle is investing in the next generation of its authentication and authorization platform, centered on a purpose-built API auth gateway and a clean set of identity and access management services. As the Principal Software Engineer leading this effort, you will own the technical vision, architecture, and migration strategy for this transformation
- In this backend focused role, you will work closely with stakeholders from Product, Security, Support and the business
- You’ll also partner with engineering teams across the organization to deliver auth capabilities that are safe, incremental to adopt, and invisible to customers
- Your day-to-day responsibilities will include designing, developing, and delivering gateway and identity services, as well as unblocking and mentoring your teammates
- Your work will generally focus on foundational platform capabilities, security-critical paths, and performance at the edge
- At Sezzle, AI-assisted development is a standard part of how we build, paired with the rigorous review and security discipline the auth-critical path demands. As a principal engineer, you will help set the pattern for how AI tooling is used well on security-sensitive systems
- Own the technical vision and roadmap for Sezzle’s authentication and authorization platform, including a dedicated API auth gateway and supporting identity services
- Architect, design, and build scalable, highly-available auth services and gateway components primarily in Golang, leveraging AWS, RDS (MySQL/Postgres), and modern distributed patterns
- Design and lead phased, zero-downtime migrations of auth traffic and functionality, with clear rollback and safety mechanisms at every step
- Establish and evolve authentication and authorization standards across the platform: OAuth2/OIDC flows, token strategy (JWT, opaque, refresh), service-to-service auth (mTLS, workload identity), and fine-grained authorization models (RBAC/ABAC/policy engines)
- Drive consistency and scalability across a distributed microservices architecture while maintaining the performance, reliability, and latency budgets expected of an edge gateway
- Partner with Security and Compliance to ensure the new platform meets fintech-grade security and regulatory requirements,



and champion secure-by-default patterns across engineering
- Establish and evolve engineering best practices for observability, security, and CI/CD across teams, with particular rigor on the auth-critical path
- Participate in the on-call rotation for the services you own, and help lead incident response and postmortems on the auth-critical path
- Mentor engineers and champion a culture of learning, innovation, and operational excellence
- Collaborate cross-functionally to translate business goals into technical roadmaps and deliver results that matter

Benefits

- Comprehensive Benefit Plans
- Generous Parental & Family Leave
- Competitive 401k Match
- Paid Time Off & Volunteer Time Off
- Ownership Through Equity
- 100% of Donations to Charity Matched
- Remote Friendly Company
- Highly Discounted Fitness Membership

Deployed significant changes to a production application in the past 30 days12+ years of professional software engineering experience, including significant backend experienceDeep, hands-on expertise in authentication and authorization systems: OAuth2, OpenID Connect, SAML, JWT and session-based auth, token lifecycle management, and modern authorization patterns (RBAC, ABAC, policy-as-code)Expertise with SQL-based RDBMS (MySQL, PostgreSQL) and experience optimizing schema and queries for performance at scaleDemonstrated AI-forward engineering: you actively use AI tooling (e.g., Claude Code, Codex, Cursor, or custom LLM integrations) in your development work today, have opinions grounded in practice about where it helps and where it doesn’t, and help teammates adopt AI-assisted workflowsBachelor’s degree in Computer Science or a similar technical field (required)Demonstrated ability to bring new ideas forward, influence decisions, and lead complex technical initiatives across many teamsSolid understanding of distributed systems design patterns (e.g., transactional outbox, event-driven architecture, queues) and the specific challenges of high-throughput, low-latency edge servicesStrong proficiency in Golang, with experience building and maintaining RESTful APIsExperience designing, building, or operating an API gateway or auth proxy at scale: whether a commercial/open-source gateway (e.g., Kong, Envoy, AWS API Gateway,



Traefik) or an in-house edge serviceProven track record leading a large-scale service extraction or migration: decomposing a monolith or large legacy service into well-bounded services with zero or minimal customer impactYou have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixedYou need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-takingYou’re not bound by convention - your success—and much of the fun—lies in developing new ways to do thingsYou earn trust - you listen attentively, speak candidly, and treat others respectfullyYou deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settleYou have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit whollyExperience with identity platforms and standards implementations (e.g., Keycloak, Auth0, Okta, Ory, or in-house IdPs), and familiarity with fine-grained authorization approaches (policy-as-code, relationship-based access control) as we centralize authorization over timeExperience with service mesh and edge technologies (Envoy, Istio, mTLS, rate limiting, WAF integration)Familiarity with threat modeling, secure design review, and common auth attack vectors (token theft, replay, CSRF, session fixation, privilege escalation)Proficiency in observability tools (Prometheus, Grafana, Datadog, New Relic), especially for latency-sensitive edge servicesExperience with AWS cloud infrastructure, mainly AWS Aurora RDS, both MySQL and PostgresExperience in fintech, payments, BNPL, or consumer lending - familiarity with financial compliance (PCI-DSS, SOC 2), credit decisioning, or transaction processing systemsExperience with CI/CD pipelines and containerized microservices (Docker, Kubernetes)Track record of shipping commercial APIs and platform infrastructure in high-growth environmentsProven leadership in guiding technical direction, improving system reliability, and scaling engineering organizations #J-18808-Ljbffr

📌 Principal Software Engineer (Identity & Access Management) (Madrid)
🏢 Sezzle
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal software engineer (identity & access management) (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal software engineer (identity & access management) (madrid) / madrid