Principal Software Engineer - Identity & Access Management

Sezzle Remote, Mexico Publicerat 31 augusti 2026
full_timeremotesenior
Key Responsibilities Own the technical vision and roadmap for Sezzle’s authentication and authorization platform, including a dedicated API auth gateway and supporting identity services. Architect, design, and build scalable, highly-available auth services and gateway components primarily in Golang , leveraging AWS , RDS (MySQL/Postgres) , and modern distributed patterns. Design and lead phased, zero-downtime migrations of auth traffic and functionality, with clear rollback and safety mechanisms at every step. Establish and evolve authentication and authorization standards across the platform: OAuth2/OIDC flows, token strategy (JWT, opaque, refresh), service-to-service auth (mTLS, workload identity), and fine-grained authorization models (RBAC/ABAC/policy engines). Drive consistency and scalability across a distributed microservices architecture while maintaining the performance, reliability, and latency budgets expected of an edge gateway. Partner with Security and Compliance to ensure the new platform meets fintech-grade security and regulatory requirements , and champion secure-by-default patterns across engineering. Establish and evolve engineering best practices for observability, security, and CI/CD across teams, with particular rigor on the auth-critical path. Participate in the on-call rotation for the services you own, and help lead incident response and postmortems on the auth-critical path. Mentor engineers and champion a culture of learning, innovation, and operational excellence. Collaborate cross-functionally to translate business goals into technical roadmaps and deliver results that matter. Minimum Requirements: 12+ years of professional software engineering experience, including significant backend experience. Deployed significant changes to a production application in the past 30 days. Deep, hands-on expertise in authentication and authorization systems : OAuth2, OpenID Connect, SAML, JWT and session-based auth, token lifecycle management, and modern authorization patterns (RBAC, ABAC, policy-as-code). Experience designing, building, or operating an API gateway or auth proxy at scale : whether a commercial/open-source gateway (e.g., Kong, Envoy, AWS API Gateway, Traefik) or an in-house edge service. Proven track record leading a large-scale service extraction or migration : decomposing a monolith or large legacy service into well-bounded services with zero or minimal customer impact. Strong proficiency in Golang , with experience building and maintaining RESTful APIs . Expertise with SQL-based RDBMS (MySQL, PostgreSQL) and experience optimizing schema and queries for performance at scale. Solid understanding of distributed systems design patterns (e.g., transactional outbox, event-driven architecture, queues) and the specific challenges of high-throughput, low-latency edge services. Demonstrated ability to bring new ideas forward , influence decisions, and lead complex technical initiatives across many teams. Demonstrated AI-forward engineering : you actively use AI tooling (e.g., Claude Code, Codex, Cursor, or custom LLM integrations) in your development work today, have opinions grounded in practice about where it helps and where it doesn't, and help teammates adopt AI-assisted workflows. Bachelor’s degree in Computer Science or a similar technical field (required). Preferred Knowledge and Skills: Experience with identity platforms and standards implementations (e.g., Keycloak, Auth0, Okta, Ory, or in-house IdPs), and familiarity with fine-grained authorization approaches (policy-as-code, relationship-based access control) as we centralize authorization over time. Experience with service mesh and edge technologies (Envoy, Istio, mTLS, rate limiting, WAF integration). Familiarity with threat modeling, secure design review, and common auth attack vectors (token theft, replay, CSRF, session fixation, privilege escalation). Proficiency in observability tools (Prometheus, Grafana, Datadog, New Relic), especially for latency-sensitive edge services. Experience with AWS cloud infrastructure , mainly AWS Aurora RDS, both MySQL and Postgres. Experience in fintech , payments, BNPL, or consumer lending - familiarity with financial compliance (PCI-DSS, SOC 2), credit decisioning, or transaction processing systems. Experience with CI/CD pipelines and containerized microservices (Docker, Kubernetes). Track record of shipping commercial APIs and platform infrastructure in high-growth environments. Proven leadership in guiding technical direction, improving system reliability, and scaling engineering organizations. About You: You have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixed. You’re not bound by convention - your success—and much of the fun—lies in developing new ways to do things. You need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-taking. You earn trust - you listen attentively, speak candidly, and treat others respectfully. You have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit wholly. You deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settle. Sezzle’s Technology Stack: Languages: Golang, Typescript, Python Frontend: Typescript - React and React Native Backend: Golang Database: MySQL, Postgres, Elasticsearch DevOps & Cloud: AWS, Kubernetes Version Control: Git CI/CD: Gitlab Testing: Developer and AI-drive

Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.

Visa jobbet och ansök

Ursprunglig annons: job-boards.greenhouse.io