Principal IAM Engineer

3 weeks ago


San Francisco, United States Northwestern Mutual Full time

What's the role?The Principal IAM Engineer is the senior technical authority for identity services, responsible for designing, implementing, and governing enterprise-wide IAM capabilities across workforce, partner, and customer identities. This role combines deep hands-on engineering with architecture and leadership, driving the modernization of authentication, authorization, identity lifecycle, and privileged access controls across our cloud and on-prem environments.Key Responsibilities:Own the end to end technical design of IAM services, including identity lifecycle management, authentication, authorization, SSO, and privileged access controls, ensuring they are secure, scalable, and highly available.Lead design and implementation of IAM integrations for SaaS, on prem, and AWS cloud platforms, including federation (SAML, OIDC, OAuth), MFA, and Passwordless capabilities.Serve as the primary escalation point for complex IAM engineering issues; perform root cause analysis and drive long term remediation and hardening of IAM platforms and related services.Partner with security architecture, infrastructure, application, and HR/IT teams to align IAM solutions with enterprise security strategy, compliance obligations, and business objectives.Define IAM engineering standards, patterns, and reference architectures; guide other engineers in implementing secure onboarding patterns for applications into IGA, PAM, and SSO platforms.Lead modernization initiatives.Contribute to audits, risk assessments, and regulatory reviews by providing technical evidence, designing compensating controls, and closing identified IAM control gaps.Mentor and coach IAM engineers and analysts, promoting engineering excellence, documentation discipline, and a culture of continuous learning and improvement.Bring your best What this role needs:10+ years of experience in information security or infrastructure engineering, with at least 5 years of hands-on-keyboard experience with core IAM platforms.Deep expertise with the majority of our IAM stackStrong hands-on experience with Microsoft Entra ID and Active Directory as foundational directory services, and extensive experience implementing federation protocols (SAML, OIDC, OAuth2).Proven track record designing and implementing IAM solutions in hybrid multi-cloud environments, including the automation of provisioning, access reviews, and RBAC/ABAC models.Experience with secrets management solutions.Proficiency in at least one scripting or programming language (such as PowerShell, Python, or Java) to automate tasks and build custom connectors for our IAM tools.Excellent communication skills with the ability to translate complex technical concepts related to our IAM ecosystem for both technical and non-technical stakeholders.Exceptional sense of ownership and the ability to work with a limited set of requirements.Highly advanced ability to breakdown work to deliver value incrementally.Experience leading large-scale IAM programs.Prior responsibility as a technical lead or architect for IAM, including mentoring teams and influencing roadmaps beyond direct reporting lines.Demonstrated ability to balance security, usability, and operational efficiency, with a strong bias toward automation and measurable risk reduction. Compensation Range:Pay Range - Start:$135,800.00Pay Range - End:$252,200.00Geographic Specific Pay Structure:Structure 110:$149,380.00 USD - $277,420.00 USD Structure 115: $156,170.00 USD - $290,030.00 USDWe believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started nowNorthwestern Mutual is an equal opportunity employer who welcomes and encourages diversity in the workforce. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives. Skills Talent Development & Planning (NM) - Beginner, Learning Agility & Critical Thinking (NM) - Expert, Cross Functional Partnering & Planning (NM) - Expert, Business Automation (NM) - Expert, Accountability (NM) - Beginner, Customer Centricity (NM) - Expert, Access Management Tools & Technologies (NM) - Expert, Cloud Deployment Models (NM) - Expert, Identity Protocols (NM) - Expert, Security Practices (NM) - Expert, Continuous Improvement (NM) - Expert, Analytical Thinking (NM) - Expert, Technical Problem Solving (NM) - Expert, Compliance (NM) - Expert, DevSecOps (NM) - Advanced, Strategic Vision & Planning (NM) - Intermediate, Stakeholder Relationship (NM) - Expert, Strategic Thinking (NM) - Expert, Adaptive Communication (NM) - Expert, Business Influence (NM) - Beginner, Identity & Access Management Industry Standards (NM) - Expert FIND YOUR FUTURE We're excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging. Flexible work schedules Concierge service Comprehensive benefits Employee resource groupsPandoLogic. Category:Technology,



  • San Francisco, CA, United States Autodesk Full time

    Job Requisition ID # 25WD93285 Position Overview Autodesk's Cyber Defense team is looking for a Sr. Principal IAM Security Engineer to lead the strategy, design, and execution of secure, scalable identity solutions across the enterprise. This is a pivotal role for a hands-on leader with deep expertise in identity architecture, a security-first mindset, and...


  • San Francisco, United States City and County of San Francisco Full time

    Amended: PRINCIPAL IDENTITY AND ACCESS MANAGEMENT (IAM) ENGINEER (9976) - Department of Technology Full-time Job Code and Title: 9976-Technology Expert I Fill Type: Permanent Exempt Department:DT/CybersecurityJob class: 9976Salary range:$167,804 - $211,094 annuallyHours:Full-timeRole type: Permanent Exempt (PEX), Full Time position is excluded by the Charter...


  • San Francisco, United States Mozilla Full time

    Staff Software Engineer, IAM at Mozilla Corporation Team: Security Locations: Remote US, Remote Canada To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu. To learn more about our Hiring Range System, please click this Why Mozilla? Mozilla Corporation is the non-profit-backed technology company that has...


  • San Francisco, United States Mozilla Full time

    Staff Software Engineer, IAM at Mozilla Corporation Team: Infrastructure Locations: Remote Canada, Remote US To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu. To learn more about our Hiring Range System, please click this Why Mozilla? Mozilla Corporation is the non-profit-backed technology company...

  • IAM Solutions Engineer

    13 hours ago


    San Francisco, United States Alignerr Full time

    Role OverviewThe IAM Solutions Engineer evaluates identity workflows, access-control policies, authentication mechanisms, and permission models. This role focuses on identifying misconfigurations, inconsistencies, and improvements across identity systems.What You'll Do- Review identity workflows for authentication and authorization- Analyze access policies,...


  • San Francisco, California, United States Gemini Full time

    About The CompanyGemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to...


  • San Francisco, United States Lambda Full time

    Lambda Identity And Access Management Engineer We're here to help the smartest minds on the planet build Superintelligence. The labs pushing the edge? They run on Lambda. Our gear trains and serves their models, our infrastructure scales with them, and we move fast to keep up. If you want to work on massive, world-changing AI deployments with people who love...


  • San Francisco, United States Autodesk Full time

    A leading software company is seeking a Sr. Principal IAM Security Engineer to guide secure identity solutions across the enterprise. This pivotal role requires expertise in identity architecture, implementing Zero Trust principles, and influencing teams. The candidate will perform responsibilities like managing identity governance and enhancing security...


  • San Francisco, United States Cloudflare Full time

    Position Title: IAM Security Engineer About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the worlds largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any...

  • Senior Director

    4 weeks ago


    San Francisco, United States Northwestern Mutual Full time

    What's the Role? As the Senior Director of Identity Management, you will lead the strategic development and implementation of identity management (IM) solutions across the organization. This role is pivotal in setting strategic direction to support IT and organizational strategies. The Senior Director will focus on ensuring secure, efficient, and scalable...