Principal Identity Security Engineer

LendingClub Bank

$197K — $232K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in identity & access management, information security or security engineering; related bachelor's degree or equivalent experience
  • Expertise in identity security principles, such as lifecycle management and access governance
  • Strong hands-on experience with IAM platforms like SailPoint and Okta, along with AWS and Terraform
  • Production experience in privileged access management, particularly with Delinea Secret Server
  • Proven ability to design enterprise-scale identity architectures and manage cross-functional technical projects
  • Experience in automation, scripting, and Infrastructure-as-Code practices
  • Familiarity with regulatory requirements (SOX, PCI DSS, etc.) and conducting audits

Responsibilities

  • Set technical direction and engineering standards for identity security at Happen Bank
  • Design scalable identity solutions using various IAM and cloud technologies
  • Manage privileged access design and operations across the bank
  • Implement automation and APIs to enhance identity service operations
  • Develop non-human identity capabilities, including service accounts and lifecycle governance
  • Lead identity initiatives and partner with security teams to address compliance
  • Evaluate and establish standards for emerging identity technologies and responsible AI adoption

Benefits

  • Comprehensive medical, dental, and vision plans for employees and families
  • 401(k) matching program
  • Health and wellness programs
  • Flexible time off for salaried employees
  • Up to 16 weeks paid parental leave
  • Relocation assistance available when needed
Full Job Description
About the Role

The Principal Identity Security Engineer will lead the design and evolution of Happen Bank's enterprise identity security capabilities, helping ensure secure, scalable, and compliant access for employees, contractors, applications, cloud platforms, and non-human identities. This role will set technical direction, drive complex cross-functional initiatives, establish engineering standards, champion the responsible adoption of AI across identity engineering, and continuously improve how identity services are designed, governed, and operated across the bank.

What You'll Do

  • Set the technical direction, architecture, and engineering standards for Happen Bank's identity security ecosystem across identity governance, authentication, authorization, directory services, privileged access, and non-human identity, establishing reference architectures and reusable patterns that improve security, reliability, and scalability
  • Design and deliver scalable identity solutions across SailPoint, Okta, Active Directory, AWS, Terraform, and GitHub, staying hands-on in architecture, automation, integrations, and troubleshooting when needed
  • Own the design and operation of privileged access management on Delinea (Thycotic) Secret Server, including vaulting, secret rotation, discovery, session controls, and privileged account lifecycle across the enterprise
  • Build automation, APIs, and Infrastructure-as-Code - and establish AI-assisted engineering workflows - that improve provisioning, access governance, lifecycle management, and engineering quality while maintaining appropriate security, governance, and regulatory controls
  • Define and mature non-human identity (NHI) capabilities, including service accounts, workload identities, machine identities, secrets integrations, ownership, lifecycle governance, and access controls
  • Lead complex identity initiatives from strategy through implementation, partnering with Security, Infrastructure, Risk and Internal Audit to support examinations, control design, remediation, and sustainable resolution of identity-related findings
  • Evaluate emerging identity security capabilities - including phishing-resistant authentication, Zero Trust, and identity threat detection and response - and set standards for the responsible adoption of AI across identity engineering
  • Raise the technical bar of the identity function through mentorship, design reviews, vendor evaluations, and proof-of-concept initiatives


About You

  • 10+ years of experience in identity and access management (IAM), Information Security or Security Engineering; bachelor's degree in a related field; or equivalent work experience
  • Deep expertise in identity security principles, including identity lifecycle management, identity governance and administration, authentication, authorization, access certification, privileged access, and non-human identity
  • Strong hands-on experience with SailPoint or another enterprise IGA platform, Okta, Active Directory, AWS identity services, Terraform, GitHub, and identity automation
  • Hands-on production experience with enterprise privileged access management, ideally Delinea (Thycotic) Secret Server - including vaulting, rotation, discovery, and privileged account lifecycle
  • Proven experience designing enterprise-scale identity architectures and leading complex technical initiatives through ambiguity, competing priorities, and cross-functional dependencies
  • Experience building automation through scripting, Infrastructure-as-Code, AI-assisted development practices, and sound software engineering principles
  • Experience working in a highly regulated environment and supporting regulatory examinations, audits, control assessments, and remediation activities
  • Strong understanding of SOX, FFIEC, OCC, PCI DSS, NIST, least privilege, segregation of duties, control design, and audit evidence requirements
  • Ability to make and defend sound technical decisions when security, regulatory, operational, and business requirements compete
  • Demonstrated ability to mentor engineers, improve technical standards, influence senior stakeholders, and drive organizational change without direct authority
  • You take ownership of outcomes, not just deliverables, and proactively identify opportunities to improve identity security, engineering quality, and operational resilience
  • You understand how to apply AI to complex, high-stakes identity security work-not just to improve efficiency, but to improve engineering quality, accelerate delivery, and unlock better business outcomes. You establish a high bar for responsible AI adoption by considering data integrity, security, model limitations, privacy, and regulatory requirements, and you continuously evolve engineering practices by building new AI-enabled workflows rather than simply automating existing ones


Nice to Have
  • Experience designing non-human identity or machine identity programs at scale
  • Experience designing identity, authorization, and governance controls for AI agents, including identity guardrails, least-privilege access, and policy enforcement
  • Experience with cloud identity and workload identity patterns in AWS or comparable cloud environments
  • Experience evaluating identity technologies and leading vendor selection or proof-of-concept initiatives


Work Location
San Francisco

The above locations are eligible offices for this role. The locations have been determined to foster in-person collaboration with this role's team or the related business lines. We utilize a hybrid work model, and our teams are in-office Tuesdays, Wednesdays, and Thursdays. In-person attendance is essential for this role's success, and remote placement will not be considered. Happen Bank offers relocation, based on actual job level.

Time Zone Requirements
Local hours (PT)

While the position will primarily work local hours, Happen Bank is headquartered in Pacific Time and our ideal candidate will be flexible working across time zones when necessary.

Travel Requirements
As needed travel to Happen Bank offices and/or other locations, as needed.

Compensation
The target base salary range for this position is 197,000-232,000. The base salary of the role will be determined by job-related knowledge, experience, education, skills, and location. Base salary is just one part of Happen Bank's Total Rewards package. You may also be eligible for long-term awards (equity) and an annual bonus (which is based on company performance, employee performance and eligible earnings).

We're creating new financial services solutions for our members based on fairness, simplicity, and heart, and we treat our employees the same way. We offer a competitive benefits package that includes medical, dental and vision plans for employees and their families, 401(k) match, health and wellness programs, flexible time off policies for salaried employees, up to 16 weeks paid parental leave and more.

#LI-Hybrid
#LI-JH1

Similar Jobs

More Jobs at LendingClub Bank

More Information Technology Jobs

Find similar Principal Identity Security Engineer jobs: