yoinka

Principal Engineer - IAM

Wells Fargo

NEW YORK, NYPrincipal
Sign in to applyVerified 1h ago
Location
NEW YORK, NY
Work model
On-Site
Level
Principal
Posted
Sep 18, 2026

Skills

CybersecurityGenAIGitJavaKubernetesRESTSpring

About this role

About this role: Wells Fargo is seeking a Principal Engineer within Identity and Access Management (IAM) Learn more about career areas and business divisions at wellsfargojobs.com This role will establish engineering strategy, reference architectures, and reusable patterns across identity lifecycle management, access governance, privileged access, cloud-native platforms, and emerging AI capabilities. The Principal Engineer will remain hands-on while partnering with Cybersecurity, Product, Risk, Architecture, Infrastructure, and Application teams to deliver secure, scalable, resilient, and compliant identity services. In this role, you will: Serve as a principal technical advisor for enterprise IAM, identity governance, privileged access, authentication, authorization, and cloud-native security initiatives. Define technical strategy, reference architectures, engineering standards, and reusable patterns for enterprise identity platforms. Lead the design and modernization of highly complex IAM and PAM platforms using Java, Spring Boot, microservices, APIs, Kubernetes, and cloud technologies. Design identity lifecycle, application onboarding, access governance, role-based access, least-privilege, segregation-of-duties, and access recertification capabilities. Develop secure integrations across IAM, IGA, PAM, cloud, application, and enterprise service-management platforms. Provide engineering leadership for privileged access solutions, including time-bound access, session provisioning, secrets management, auditing, and access monitoring. Establish fine-grained authorization patterns for applications, APIs, workload identities, AI agents, and machine-to-machine interactions. Evaluate and implement secure Generative AI capabilities, including AI agents, MCP servers, RAG solutions, identity propagation, and authorization controls. Establish observability, resiliency, testing, deployment, and production-support practices for security-critical identity platforms. Partner with senior leaders and stakeholders to define platform roadmaps, prioritize investments, and translate business and regulatory requirements into engineering solutions. Mentor engineers and technical leads while promoting software engineering, security, automation, and operational best practices. Evaluate emerging identity, security, cloud, and AI technologies and recommend innovations that strengthen security and improve engineering efficiency. Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents) Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions Understand and account for model limitations, security risks, and operational considerations Apply AI responsibly in development and production environments Ensure AI usage aligns with security, compliance, privacy, and ethical standards Required Qualifications: 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education 7+ years of Experience designing and engineering enterprise Identity and Access Management, Identity Governance and Administration, or Privileged Access Management platforms Desired Qualifications: Advanced development experience with Java, Spring Boot, Spring Security, REST APIs, microservices, and event-driven architectures. Experience with IAM or PAM platforms such as Saviynt, Oracle Identity Manager, CyberArk, BeyondTrust, or comparable technologies. Experience developing identity lifecycle, Joiner-Mover-Leaver, access recertification, role management, segregation-of-duties, and least-privilege solutions. Experience designing privileged access capabilities, including session provisioning, credential management, access monitoring, audit controls, and time-bound access.

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Principal Engineer - IAM at Wells Fargo, NEW YORK, NY | Yoinka