Sezzle Principal Software Engineer at Sezzle leading the evolution of authentication and authorization platform. Own technical vision, architecture, and migration strategy while collaborating with stakeholders and mentoring teammates.
Responsibilities
We are seeking a talented and motivated best-in-class Principal Software Engineer to own and lead the evolution of authentication and authorization at Sezzle. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement.
Sezzle is investing in the next generation of its authentication and authorization platform, centered on a purpose-built API auth gateway and a clean set of identity and access management services. As the Principal Software Engineer leading this effort, you will own the technical vision, architecture, and migration strategy for this transformation.
In this backend focused role, you will work closely with stakeholders from Product, Security, Support and the business. You’ll also partner with engineering teams across the organization to deliver auth capabilities that are safe, incremental to adopt, and invisible to customers. Your day-to-day responsibilities will include designing, developing, and delivering gateway and identity services, as well as unblocking and mentoring your teammates. Your work will generally focus on foundational platform capabilities, security-critical paths, and performance at the edge.
At Sezzle, AI-assisted development is a standard part of how we build, paired with the rigorous review and security discipline the auth-critical path demands. As a principal engineer, you will help set the pattern for how AI tooling is used well on security-sensitive systems.
Own the technical vision and roadmap for Sezzle’s authentication and authorization platform, including a dedicated API auth gateway and supporting identity services.
Architect, design, and build scalable, highly-available auth services and gateway components primarily in Golang, leveraging AWS, RDS (MySQL/Postgres), and modern distributed patterns.
Design and lead phased, zero-downtime migrations of auth traffic and functionality, with clear rollback and safety mechanisms at every step.
Establish and evolve authentication and authorization standards across the platform: OAuth2/OIDC flows, token strategy (JWT, opaque, refresh), service-to-service auth (mTLS, workload identity), and fine-grained authorization models (RBAC/ABAC/policy engines).
Drive consistency and scalability across a distributed microservices architecture while maintaining the performance, reliability, and latency budgets expected of an edge gateway.
Partner with Security and Compliance to ensure the new platform meets fintech-grade security and regulatory requirements, and champion secure-by-default patterns across engineering.
Establish and evolve engineering best practices for observability, security, and CI/CD across teams, with particular rigor on the auth-critical path.
Participate in the on-call rotation for the services you own, and help lead incident response and postmortems on the auth-critical path.
Qualification
You earn trust - you listen attentivelyYou have backboneSezzle’s Technology StackLanguagesFrontendBackendDatabaseDevOps & CloudFamiliarity with threat modelingExperience in fintech
Required
You have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixed.
You’re not bound by convention - your success—and much of the fun—lies in developing new ways to do things.
You need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-taking.
You earn trust - you listen attentively, speak candidly, and treat others respectfully.
You have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit wholly.
You deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settle.
Sezzle’s Technology Stack:
Languages: Golang, Typescript, Python
Frontend: Typescript - React and React Native
Backend: Golang
Database: MySQL, Postgres, Elasticsearch
DevOps & Cloud: AWS, Kubernetes
Preferred
Experience with identity platforms and standards implementations (e.g., Keycloak, Auth0, Okta, Ory, or in-house IdPs), and familiarity with fine-grained authorization approaches (policy-as-code, relationship-based access control) as we centralize authorization over time.
Experience with service mesh and edge technologies (Envoy, Istio, mTLS, rate limiting, WAF integration).
Familiarity with threat modeling, secure design review, and common auth attack vectors (token theft, replay, CSRF, session fixation, privilege escalation).
Proficiency in observability tools (Prometheus, Grafana, Datadog, New Relic), especially for latency-sensitive edge services.
Experience with AWS cloud infrastructure, mainly AWS Aurora RDS, both MySQL and Postgres.
Experience in fintech, payments, BNPL, or consumer lending - familiarity with financial compliance (PCI-DSS, SOC 2), credit decisioning, or transaction processing systems.
Experience with CI/CD pipelines and containerized microservices (Docker, Kubernetes).
Track record of shipping commercial APIs and platform infrastructure in high-growth environments.