Principal Identity Security Engineer

LendingClub

San Francisco (CA)

Hybrid

USD 197,000 - 232,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401(k) match
Parental leave

Job summary

Happen Bank in San Francisco is seeking a Principal Identity Security Engineer to lead the design and evolution of the bank's enterprise identity security capabilities, ensuring secure, scalable access for employees, contractors, applications, cloud platforms, and non-human identities.

You will set the technical direction, drive cross-functional initiatives, establish engineering standards, and champion AI adoption across identity engineering, while improving governance and operational

Qualifications

  • 10+ years in IAM, Information Security, or Security Engineering.
  • Deep expertise in identity lifecycle, governance, authentication, and authorization.
  • Hands-on with enterprise IGA platforms like SailPoint or Okta.
  • Experience with privileged access management and Delinea Secret Server.
  • Ability to design scalable enterprise IAM architectures.
  • Experience in regulated environments and audits.
  • Strong scripting and IaC capabilities; AI-assisted development is a plus.

Responsibilities

  • Set the technical direction and engineering standards for the identity security ecosystem.
  • Design scalable identity solutions across SailPoint, Okta, AD, AWS, Terraform, and GitHub.
  • Own the design and operation of Delinea Secret Server privileged access management.
  • Build automation, APIs, and Infrastructure-as-Code with AI-assisted workflows.
  • Define and mature non-human identity capabilities and governance.
  • Lead complex initiatives with cross-functional partners and audits.
  • Evaluate emerging identity security capabilities and AI adoption standards.

Skills

IAM expertise
Identity lifecycle management
Identity governance and administration
Authentication & authorization
Privileged access management
Automation & IaC
AI in identity security
Regulatory compliance

Education

Bachelor's degree in a related field

Tools

SailPoint
Okta
Active Directory
AWS identity services
Terraform
GitHub
Delinea Secret Server

Job description

About the Role

The Principal Identity Security Engineer will lead the design and evolution of Happen Bank's enterprise identity security capabilities, helping ensure secure, scalable, and compliant access for employees, contractors, applications, cloud platforms, and non-human identities. This role will set technical direction, drive complex cross‑functional initiatives, establish engineering standards, champion the responsible adoption of AI across identity engineering, and continuously improve how identity services are designed, governed, and operated across the bank.

What You'll Do
  • Set the technical direction, architecture, and engineering standards for Happen Bank’s identity security ecosystem across identity governance, authentication, authorization, directory services, privileged access, and non‑human identity, establishing reference architectures and reusable patterns that improve security, reliability, and scalability
  • Design and deliver scalable identity solutions across SailPoint, Okta, Active Directory, AWS, Terraform, and GitHub, staying hands‑on in architecture, automation, integrations, and troubleshooting when needed
  • Own the design and operation of privileged access management on Delinea (Thycotic) Secret Server, including vaulting, secret rotation, discovery, session controls, and privileged account lifecycle across the enterprise
  • Build automation, APIs, and Infrastructure‑as‑Code — and establish AI‑assisted engineering workflows — that improve provisioning, access governance, lifecycle management, and engineering quality while maintaining appropriate security, governance, and regulatory controls
  • Define and mature non‑human identity (NHI) capabilities, including service accounts, workload identities, machine identities, secrets integrations, ownership, lifecycle governance, and access controls
  • Lead complex identity initiatives from strategy through implementation, partnering with Security, Infrastructure, Risk and Internal Audit to support examinations, control design, remediation, and sustainable resolution of identity‑related findings
  • Evaluate emerging identity security capabilities — including phishing‑resistant authentication, Zero Trust, and identity threat detection and response — and set standards for the responsible adoption of AI across identity engineering
  • Raise the technical bar of the identity function through mentorship, design reviews, vendor evaluations and proof‑of‑concept initiatives
About You
  • 10+ years of experience in identity and access management (IAM), Information Security or Security Engineering; bachelor's degree in a related field; or equivalent work experience
  • Deep expertise in identity security principles, including identity lifecycle management, identity governance and administration, authentication, authorization, access certification, privileged access, and non‑human identity
  • Strong hands‑on experience with SailPoint or another enterprise IGA platform, Okta, Active Directory, AWS identity services, Terraform, GitHub, and identity automation
  • Hands‑on production experience with enterprise privileged access management, ideally Delinea (Thycotic) Secret Server — including vaulting, rotation, discovery, and privileged account lifecycle
  • Proven experience designing enterprise‑scale identity architectures and leading complex technical initiatives through ambiguity, competing priorities, and cross‑functional dependencies
  • Experience building automation through scripting, Infrastructure‑as‑Code, AI‑assisted development practices, and sound software engineering principles
  • Experience working in a highly regulated environment and supporting regulatory examinations, audits, control assessments, and remediation activities
  • Strong understanding of SOX, FFIEC, OCC, PCI DSS, NIST, least privilege, segregation of duties, control design, and audit evidence requirements
  • Ability to make and defend sound technical decisions when security, regulatory, operational, and business requirements compete
  • Demonstrated ability to mentor engineers, improve technical standards, influence senior stakeholders, and drive organizational change without direct authority
  • You take ownership of outcomes, not just deliverables, and proactively identify opportunities to improve identity security, engineering quality, and operational resilience
  • You understand how to apply AI to complex, high‑stakes identity security work—not just to improve efficiency, but to improve engineering quality, accelerate delivery, and unlock better business outcomes. You establish a high bar for responsible AI adoption by considering data integrity, security, model limitations, privacy, and regulatory requirements, and you continuously evolve engineering practices by building new AI‑enabled workflows rather than simply automating existing ones
Nice to Have
  • Experience designing non‑human identity or machine identity programs at scale
  • Experience designing identity, authorization, and governance controls for AI agents, including identity guardrails, least‑privilege access, and policy enforcement
  • Experience with cloud identity and workload identity patterns in AWS or comparable cloud environments
  • Experience evaluating identity technologies and leading vendor selection or proof‑of‑concept initiatives
Work Location

San Francisco The above locations are eligible offices for this role. The locations have been determined to foster in‑person collaboration with this role’s team or the related business lines. We utilize a hybrid work model, and our teams are in‑office Tuesdays, Wednesdays, and Thursdays. In‑person attendance is essential for this role’s success, and remote placement will not be considered.

Time Zone Requirements

Local hours (PT) While the position will primarily work local hours, Happen Bank is headquartered in Pacific Time and our ideal candidate will be flexible working across time zones when necessary.

Travel Requirements

As needed travel to Happen Bank offices and/or other locations, as needed.

Compensation

The target base salary range for this position is 197,000-232,000. The base salary of the role will be determined by job‑related knowledge, experience, education, skills, and location. Base salary is just one part of Happen Bank's Total Rewards package. You may also be eligible for long‑term awards (equity) and an annual bonus (which is based on company performance, employee performance and eligible earnings).

Benefits

We’re creating new financial services solutions for our members based on fairness, simplicity, and heart, and we treat our employees the same way. We offer a competitive benefits package that includes medical, dental and vision plans for employees and their families, 401(k) match, health and wellness programs, flexible time off policies for salaried employees, up to 16 weeks paid parental leave and more.

Equal Opportunity

Happen Bank is an equal opportunity employer and dedicated to diversity, equity, and inclusion in the workplace. We do not discriminate on the basis of race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), gender, gender identity, gender expression, sexual orientation, age, marital status, veteran status, disability status, political views or activity, or other applicable legally protected characteristics. We believe that a variety of perspectives will make our teams and business stronger as we work together to transform the traditional banking system. We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. If you need assistance or an accommodation due to a disability, please contact us at interviewaccommodations@happen.com.

Notice on AI Tool Use

For select roles and locations, candidate interviews may be recorded, transcribed and summarized by tools such as artificial intelligence (AI) to assist our hiring managers with the application process. You will have the opportunity to opt out of recording, transcription, and summarization prior to any scheduled interviews. We will not discriminate against you if you choose to opt out. During the interview, we will collect the following categories of personal information from or about you: contact information, identifiers, professional and employment‑related information, sensory information (audio/video recording), and any other categories of personal information you choose to share with us. We will use this information to evaluate your application for employment. We will only share your interview, transcription, or summary with persons whose expertise or technology is necessary to process your application, evaluate your fitness for a position, and administer or support the tool. We will not sell your personal information or disclose it to any third party for their marketing purposes. For more information about how we will handle your personal information, please refer to our Privacy Disclosure. We will delete any recording of your interview promptly but in no event later than 30 days after making a hiring decision.

Company Overview

Happen Bank (formerly LendingClub) is built around a simple purpose: to clear the way to help people turn intention into action, and action into financial progress. That means offering focused products, a frictionless mobile‑first experience, and clear terms with no gotchas. Respect and fairness is part of our DNA, and that ideal shapes how we work, how we treat each other, and how we invest in our employees and our community. Join us in using data, bold thinking, and a commitment to innovation to help clear the way for millions of Americans to achieve more. To learn more visit us at happen.com Please review Happen Bank Work‑related Privacy Disclosure.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Identity Security Engineer
Principal Identity Security Engineer

Happen Bank • San Francisco (CA)

Hybrid
USD 197,000 - 232,000
Medical, dental, and vision
401(k) match
Parental leave (16 weeks)
+1
Principal Identity Security Engineer
Principal Identity Security Engineer

Tally • San Francisco (CA)

Hybrid
USD 197,000 - 232,000
Medical, dental and vision plans
401(k) match
Flexible time off
+1
VP, Business Data Delivery
VP, Business Data Delivery

LendingClub • San Francisco (CA)

Hybrid
USD 240,000 - 270,000
Credit Strategy Director, Home Improvement
Credit Strategy Director, Home Improvement

LendingClub • San Francisco (CA)

Hybrid
USD 175,000 - 205,000
Medical, dental, and vision plans
401(k) match
Parental leave (up to 16 weeks)
+1
Credit Strategy Director, Home Improvement
Credit Strategy Director, Home Improvement

Tally • San Francisco (CA)

Hybrid
USD 175,000 - 205,000
Medical, dental and vision plans
401(k) match
Health and wellness programs
+3
Sr Product Manager, Marketing Data & AI
Sr Product Manager, Marketing Data & AI

Tally • San Francisco (CA)

On-site
USD 176,000 - 207,000
401(k) match
Flexible time off
Medical, dental, and vision plans
Integrated IT Audit Manager
Integrated IT Audit Manager

Tally • San Francisco (CA)

Hybrid
USD 150,000 - 170,000
Health benefits
401(k) match
Parental leave
+1
VP, Business Data Delivery
VP, Business Data Delivery

Happen Bank • San Francisco (CA)

Hybrid
USD 240,000 - 270,000
Competitive benefits package
401(k) match
Flexible time off policies
Lead Data Engineer
Lead Data Engineer

Tally • San Francisco (CA)

Hybrid
USD 190,000 - 220,000
Relocation assistance
Partner Operations Manager
Partner Operations Manager

Tally • San Francisco (CA)

Hybrid
USD 115,000 - 141,000
401(k) match
Medical, dental, vision benefits
Paid parental leave