[Skip To Content]
Laptop

Principal Engineer - IAM

  • Technology
  • Full time
  • R-576449

About this role:

Wells Fargo is seeking a Principal Engineer within Identity and Access Management (IAM) Learn more about career areas and business divisions at wellsfargojobs.com

This role will establish engineering strategy, reference architectures, and reusable patterns across identity lifecycle management, access governance, privileged access, cloud-native platforms, and emerging AI capabilities. The Principal Engineer will remain hands-on while partnering with Cybersecurity, Product, Risk, Architecture, Infrastructure, and Application teams to deliver secure, scalable, resilient, and compliant identity services.

In this role, you will:

  • Serve as a principal technical advisor for enterprise IAM, identity governance, privileged access, authentication, authorization, and cloud-native security initiatives.
  • Define technical strategy, reference architectures, engineering standards, and reusable patterns for enterprise identity platforms.
  • Lead the design and modernization of highly complex IAM and PAM platforms using Java, Spring Boot, microservices, APIs, Kubernetes, and cloud technologies.
  • Design identity lifecycle, application onboarding, access governance, role-based access, least-privilege, segregation-of-duties, and access recertification capabilities.
  • Develop secure integrations across IAM, IGA, PAM, cloud, application, and enterprise service-management platforms.
  • Provide engineering leadership for privileged access solutions, including time-bound access, session provisioning, secrets management, auditing, and access monitoring.
  • Establish fine-grained authorization patterns for applications, APIs, workload identities, AI agents, and machine-to-machine interactions.
  • Evaluate and implement secure Generative AI capabilities, including AI agents, MCP servers, RAG solutions, identity propagation, and authorization controls.
  • Establish observability, resiliency, testing, deployment, and production-support practices for security-critical identity platforms.
  • Partner with senior leaders and stakeholders to define platform roadmaps, prioritize investments, and translate business and regulatory requirements into engineering solutions.
  • Mentor engineers and technical leads while promoting software engineering, security, automation, and operational best practices.
  • Evaluate emerging identity, security, cloud, and AI technologies and recommend innovations that strengthen security and improve engineering efficiency.
  • Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents)
  • Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
  • Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions
  • Understand and account for model limitations, security risks, and operational considerations
  • Apply AI responsibly in development and production environments
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards

Required Qualifications:

  • 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 7+ years of Experience designing and engineering enterprise Identity and Access Management, Identity Governance and Administration, or Privileged Access Management platforms

Desired Qualifications:

  • Advanced development experience with Java, Spring Boot, Spring Security, REST APIs, microservices, and event-driven architectures.
  • Experience with IAM or PAM platforms such as Saviynt, Oracle Identity Manager, CyberArk, BeyondTrust, or comparable technologies.
  • Experience developing identity lifecycle, Joiner-Mover-Leaver, access recertification, role management, segregation-of-duties, and least-privilege solutions.
  • Experience designing privileged access capabilities, including session provisioning, credential management, access monitoring, audit controls, and time-bound access.
  • Experience modernizing enterprise platforms using Kubernetes, EKS, Docker, Helm, Terraform, GitOps, and cloud-native engineering patterns.
  • Experience developing CI/CD pipelines and automated delivery practices using GitHub Actions, Argo CD, Bamboo, Bitbucket, or similar technologies.
  • Knowledge of authentication, authorization, RBAC, policy-based access control, workload identity, secrets management, and fine-grained entitlement models.
  • Experience designing secure AI platforms involving Generative AI, AI agents, MCP servers, RAG, LLM integrations, or AI authorization controls.
  • Experience establishing enterprise reference architectures, engineering standards, design-review practices, and platform roadmaps.
  • Experience supporting security-critical platforms in regulated environments, including audit readiness, risk management, monitoring, and production support.
  • Strong executive communication, stakeholder management, technical leadership, and engineering mentorship skills.

Locations: 

  • 150 E 42nd Street, New York, NY 10017

Posting Statements:

  • Job posting may come down early due to volume of applicants. 
  • Required location(s) listed above. Relocation assistance is not available for this position 
  • Salary range is determined by location of the job.  May be considered for a discretionary bonus, Restricted Share Rights, or other long – term incentive awards. 
  • This role is NOT available for 100% remote work

Pay Range
 


Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$191,000.00 - $305,000.00

Benefits

Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Posting End Date:

22 Sep 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.

Drug and Alcohol Policy

 

Wells Fargo maintains a drug free workplace.  Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


Rejoignez notre communauté de talents

En savoir plus sur les événements à venir et les opportunités de carrière chez Wells Fargo.

Rejoignez vous
JK 1212 1236 B 4MP