ForgeApply · Job listing
Principal Software Engineer - Identity & Access Management
Sezzle
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
The salary range for this role is negotiable, the range being $6,000-$11,000 per month (Gross in USD), based on location and experience level.
About Sezzle:
With a mission to financially empower the next generation, Sezzle is revolutionizing the shopping experience beyond payments, blending cutting-edge tech with seamless, interest-free installment plans that make shopping smarter and more accessible. We’re not just transforming payments; we’re redefining how people discover, interact with, and purchase the things they love while driving real impact on merchant sales through increased conversions and higher order values. As we continue to shape the future of fintech and retail, we’re building an innovative, dynamic team passionate about creating more than just a transaction but a truly unique shopping journey. If you’re excited about pushing boundaries in tech and delivering a game-changing experience for consumers and merchants alike, come join us at Sezzle and help create the future of shopping!
Compensation :
For this principal development role, with 12+ years of experience, the compensation range is $6000 - $11000 per month, negotiable based on the skills and experience being brought to the table. This range acknowledges the extensive expertise, leadership capabilities, and significant contributions expected at this level.
This is a fully remote role . We believe the best engineers can do world-class work from anywhere, and we hire accordingly. You get principal-level scope and ownership at a growing fintech, competitive compensation, and no relocation or commute attached to it. Work from where you do your best work.
About the Role:
We are seeking a talented and motivated best-in-class Principal Software Engineer to own and lead the evolution of authentication and authorization at Sezzle. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement.
Sezzle is investing in the next generation of its authentication and authorization platform, centered on a purpose-built API auth gateway and a clean set of identity and access management services. As the Principal Software Engineer leading this effort, you will own the technical vision, architecture, and migration strategy for this transformation.
In this backend focused role, you will work closely with stakeholders from Product, Security, Support and the business. You’ll also partner with engineering teams across the organization to deliver auth capabilities that are safe, incremental to adopt, and invisible to customers. Your day-to-day responsibilities will include designing, developing, and delivering gateway and identity services, as well as unblocking and mentoring your teammates. Your work will generally focus on foundational platform capabilities, security-critical paths, and performance at the edge.
At Sezzle, AI-assisted development is a standard part of how we build, paired with the rigorous review and security discipline the auth-critical path demands. As a principal engineer, you will help set the pattern for how AI tooling is used well on security-sensitive systems.
Key Responsibilities
• Own the technical vision and roadmap for Sezzle’s authentication and authorization platform, including a dedicated API auth gateway and supporting identity services.
• Architect, design, and build scalable, highly-available auth services and gateway components primarily in Golang , leveraging AWS , RDS (MySQL/Postgres) , and modern distributed patterns.
• Design and lead phased, zero-downtime migrations of auth traffic and functionality, with clear rollback and safety mechanisms at every step.
• Establish and evolve authentication and authorization standards across the platform: OAuth2/OIDC flows, token strategy (JWT, opaque, refresh), service-to-service auth (mTLS, workload identity), and fine-grained authorization models (RBAC/ABAC/policy engines).
• Drive consistency and scalability across a distributed microservices architecture while maintaining the performance, reliability, and latency budgets expected of an edge gateway.
• Partner with Security and Compliance to ensure the new platform meets fintech-grade security and regulatory requirements , and champion secure-by-default patterns across engineering.
• Establish and evolve engineering best practices for observability, security, and CI/CD across teams, with particular rigor on the auth-critical path.
• Participate in the on-call rotation for the services you own, and help lead incident response and postmortems on the auth-critical path.
• Mentor engineers and champion a culture of learning, innovation, and operational excellence.
• Collaborate cross-functionally to translate business goals into technical roadmaps and deliver results that matter.
Minimum Requirements:
• 12+ years of professional software engineering experience, including significant backend experience.
• Deployed significant changes to a production application in the past 30 days.
• Deep, hands-on expertise in authentication and authorization systems : OAuth2, OpenID Connect, SAML, JWT and session-based auth, token lifecycle management, and modern authorization patterns (RBAC, ABAC, policy-as-code).
• Experience designing, building, or operating an API gateway or auth proxy at scale : whether a commercial/open-source gateway (e.g., Kong, Envoy, AWS API Gateway, Traefik) or an in-house edge service.
• Proven track record leading a large-scale service extraction or migration : decomposing a monolith or large legacy service into well-bounded services with zero or minimal customer impact.
• Strong proficiency in Golang , with experience building and maintaining RESTful APIs .
• Expertise with SQL-based RDBMS (MySQL, PostgreSQL) and experience optimizing schema and queries for performance at scale.
• Solid understanding of distributed systems design patterns (e.g., transactional outbox,
Ready to apply to Sezzle?
Apply in about a minuteSimilar jobs
- Senior Software Engineer - Identity & Access Management — Snowflake · US-WA-Bellevue
- Senior Software Engineer, Identity & Access Management — Digitalocean98 · Remote
- Senior Software Engineer, Identity & Access Management — Digitalocean98 · Seattle
- Senior Staff Software Engineer (Identity & Access Management) — Gofundme · San Francisco, CA
- Software Engineer, Identity & Access Management — Hadrian-automation · Los Angeles, CA
- Staff Software Engineer, Identity & Access Management — Reddit · Remote
- Staff Software Engineer, Identity & Access Management — Snowflake · US-WA-Bellevue
- Senior Software Engineer - Identity Infrastructure — Rubrik · Palo Alto, CA
More like this: Software Engineer Jobs · Remote Software Engineer Jobs · More jobs at Sezzle · Browse all jobs