Principal Software Engineer (Identity & Access Management) (Madrid)

Principal Software Engineer (Identity & Access Management) (Madrid)

23 sep
|
Sezzle
|
Madrid

23 sep

Sezzle

Madrid

We are seeking a talented and motivated best-in-class Principal Software Engineer to own and lead the evolution of authentication and authorization at Sezzle. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancementSezzle is investing in the next generation of its authentication and authorization platform, centered on a purpose-built API auth gateway and a clean set of identity and access management services. As the Principal Software Engineer leading this effort, you will own the technical vision, architecture, and migration strategy for this transformationIn this backend focused role, you will work closely with stakeholders from Product, Security, Support and the businessYou’ll also partner with engineering teams across the organization to deliver auth capabilities that are safe, incremental to adopt, and invisible to customersYour day-to-day responsibilities will include designing, developing, and delivering gateway and identity services, as well as unblocking and mentoring your teammatesYour work will generally focus on foundational platform capabilities, security-critical paths, and performance at the edgeAt Sezzle, AI-assisted development is a standard part of how we build, paired with the rigorous review and security discipline the auth-critical path demands. As a principal engineer, you will help set the pattern for how AI tooling is used well on security-sensitive systemsOwn the technical vision and roadmap for Sezzle’s authentication and authorization platform, including a dedicated API auth gateway and supporting identity servicesArchitect, design, and build scalable, highly-available auth services and gateway components primarily in Golang, leveraging AWS, RDS (MySQL/Postgres), and modern distributed patternsDesign and lead phased, zero-downtime migrations of auth traffic and functionality, with clear rollback and safety mechanisms at every stepEstablish and evolve authentication and authorization standards across the platform: OAuth2/OIDC flows, token strategy (JWT, opaque, refresh), service-to-service auth (mTLS, workload identity), and fine-grained authorization models (RBAC/ABAC/policy engines)Drive consistency and scalability across a distributed microservices architecture while maintaining the performance, reliability, and latency budgets expected of an edge gatewayPartner with Security and Compliance to ensure the new platform meets fintech-grade security and regulatory requirements,



and champion secure-by-default patterns across engineeringEstablish and evolve engineering best practices for observability, security, and CI/CD across teams, with particular rigor on the auth-critical pathParticipate in the on-call rotation for the services you own, and help lead incident response and postmortems on the auth-critical pathMentor engineers and champion a culture of learning, innovation, and operational excellenceCollaborate cross-functionally to translate business goals into technical roadmaps and deliver results that matterBenefits Comprehensive Benefit PlansGenerous Parental & Family LeaveCompetitive 401k MatchPaid Time Off & Volunteer Time OffOwnership Through Equity100% of Donations to Charity MatchedRemote Friendly CompanyHighly Discounted Fitness MembershipDeployed significant changes to a production application in the past 30 days12+ years of professional software engineering experience, including significant backend experienceDeep, hands-on expertise in authentication and authorization systems: OAuth2, OpenID Connect, SAML, JWT and session-based auth, token lifecycle management, and modern authorization patterns (RBAC, ABAC, policy-as-code)Expertise with SQL-based RDBMS (MySQL, PostgreSQL) and experience optimizing schema and queries for performance at scaleDemonstrated AI-forward engineering: you actively use AI tooling (e.G., Claude Code, Codex, Cursor, or custom LLM integrations) in your development work today, have opinions grounded in practice about where it helps and where it doesn’t, and help teammates adopt AI-assisted workflowsBachelor’s degree in Computer Science or a similar technical field (required)Demonstrated ability to bring new ideas forward, influence decisions, and lead complex technical initiatives across many teamsSolid understanding of distributed systems design patterns (e.G., transactional outbox, event-driven architecture, queues) and the specific challenges of high-throughput, low-latency edge servicesStrong proficiency in Golang, with experience building and maintaining RESTful APIsExperience designing, building, or operating an API gateway or auth proxy at scale: whether a commercial/open-source gateway (e.G., Kong, Envoy, AWS API Gateway, Traefik)



or an in-house edge serviceProven track record leading a large-scale service extraction or migration: decomposing a monolith or large legacy service into well-bounded services with zero or minimal customer impactYou have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixedYou need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-takingYou’re not bound by convention - your success—and much of the fun—lies in developing new ways to do thingsYou earn trust - you listen attentively, speak candidly, and treat others respectfullyYou deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settleYou have backbone; disagree, then commit -you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit whollyExperience with identity platforms and standards implementations (e.G., Keycloak, Auth0, Okta, Ory, or in-house IdPs), and familiarity with fine-grained authorization approaches (policy-as-code, relationship-based access control) as we centralize authorization over timeExperience with service mesh and edge technologies (Envoy, Istio, mTLS, rate limiting, WAF integration)Familiarity with threat modeling, secure design review, and common auth attack vectors (token theft, replay, CSRF, session fixation, privilege escalation)Proficiency in observability tools (Prometheus, Grafana, Datadog, New Relic), especially for latency-sensitive edge servicesExperience with AWS cloud infrastructure, mainly AWS Aurora RDS, both MySQL and PostgresExperience in fintech, payments, BNPL, or consumer lending - familiarity with financial compliance (PCI-DSS, SOC 2), credit decisioning, or transaction processing systemsExperience with CI/CD pipelines and containerized microservices (Docker, Kubernetes)Track record of shipping commercial APIs and platform infrastructure in high-growth environmentsProven leadership in guiding technical direction, improving system reliability, and scaling engineering organizations#J-18808-Ljbffr

📌 Principal Software Engineer (Identity & Access Management) (Madrid)
🏢 Sezzle
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal software engineer (identity & access management) (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal software engineer (identity & access management) (madrid) / madrid