Principal Identity Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: San Francisco, United States; hybrid work model with in-office attendance required on Tuesdays, Wednesdays, and Thursdays. Local Pacific Time hours are expected, with flexibility across time zones when necessary. Relocation support is available based on job level.
Salary: $197,000–$232,000 annual base salary, plus potential equity and annual bonus.
Company
provides focused financial products and mobile-first financial services designed to help millions of Americans make financial progress.
What you will do
- Set technical direction, architecture, and engineering standards for enterprise identity security across governance, authentication, authorization, directory services, privileged access, and non-human identities.
- Design and deliver scalable identity solutions using SailPoint, Okta, Active Directory, AWS, Terraform, and GitHub.
- Own privileged access management on Delinea Secret Server, including vaulting, secret rotation, discovery, session controls, and privileged account lifecycle management.
- Build automation, APIs, Infrastructure-as-Code, and AI-assisted engineering workflows for provisioning, access governance, lifecycle management, and engineering quality.
- Define non-human identity capabilities for service accounts, workload identities, machine identities, secrets integration, ownership, lifecycle governance, and access controls.
- Lead cross-functional identity initiatives, regulatory examinations, control design, remediation, vendor evaluations, design reviews, and proof-of-concept initiatives.
Requirements
- 10+ years of experience in IAM, information security, or security engineering, plus a related bachelor's degree or equivalent experience.
- Deep expertise in identity lifecycle management, identity governance and administration, authentication, authorization, access certification, privileged access, and non-human identity.
- Hands-on experience with SailPoint or another enterprise IGA platform, Okta, Active Directory, AWS identity services, Terraform, GitHub, and identity automation.
- Production experience with enterprise privileged access management, ideally Delinea Secret Server, including vaulting, rotation, discovery, and privileged account lifecycle management.
- Experience designing enterprise-scale identity architectures, leading complex technical initiatives, building automation and Infrastructure-as-Code, and applying AI-assisted development practices.
- Experience in regulated environments, including SOX, FFIEC, OCC, PCI DSS, NIST, least privilege, segregation of duties, control design, audits, and regulatory examinations.
Nice to have
- Experience designing non-human or machine identity programs at scale.
- Experience designing identity, authorization, and governance controls for AI agents.
- Experience with cloud identity and workload identity patterns in AWS or comparable cloud environments.
- Experience evaluating identity technologies and leading vendor selection or proof-of-concept initiatives.
Culture & Benefits
- Hybrid collaboration model with required in-office attendance in San Francisco three days per week.
- Medical, dental, and vision coverage for employees and families.
- 401(k) matching, health and wellness programs, and flexible time off for salaried employees.
- Up to 16 weeks of paid parental leave.
- Travel to offices or other locations as needed.
Hiring process
- Candidate interviews may be recorded, transcribed, and summarized using AI tools for select roles and locations.
- Candidates may opt out of recording, transcription, and summarization before scheduled interviews.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →