Wells Fargo Logo

Wells Fargo

Principal Engineer

Posted An Hour Ago
Be an Early Applicant
Hybrid
New York, NY
191K-305K Annually
Senior level
Hybrid
New York, NY
191K-305K Annually
Senior level
Provides enterprise technical leadership for identity and access management architecture across Microsoft environments. Designs authentication, authorization, federation, identity governance, privileged access, Zero Trust, and lifecycle-management solutions. Defines reference architectures, standards, roadmaps, and security controls; leads architecture reviews and threat modeling; partners with cybersecurity, infrastructure, application, risk, and architecture teams; mentors engineers; and advises senior leadership. Applies AI-assisted development responsibly while meeting security, compliance, privacy, and regulatory requirements.
The summary above was generated by AI
Wells Fargo is seeking a Principal Engineer within Identity and Access Management (IAM) Learn more about career areas and business divisions at wellsfargojobs.com
This role will provide technical leadership for enterprise identity architecture, authentication, access governance, privileged access, and Microsoft identity platform strategy.
This role will serve as a senior engineering leader responsible for defining the future-state architecture for workforce identity, privileged access, access governance, and Zero Trust initiatives across the Microsoft ecosystem. The Principal Engineer will partner closely with Cybersecurity, Infrastructure Engineering, Application Development, Risk, and Architecture teams to deliver secure, scalable, and resilient identity solutions supporting enterprise business and regulatory requirements.
In this role, you will:
  • Serve as a principal technical advisor for enterprise identity architecture, authentication, authorization, federation, access governance, and privileged access management initiatives.
  • Lead the design and adoption of enterprise identity solutions leveraging Microsoft Entra ID, Active Directory, Privileged Identity Management (PIM), Conditional Access, and related identity technologies.
  • Define IAM reference architectures, engineering standards, roadmaps, and reusable patterns supporting enterprise-scale identity services.
  • Provide technical leadership for Zero Trust strategies, Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), privileged access, and identity governance programs.
  • Lead the evaluation, design, and implementation of secure authentication and authorization services supporting cloud, on-premises, and hybrid environments.
  • Drive adoption of modern identity capabilities including passwordless authentication, federation, adaptive access controls, lifecycle management, and privileged access controls.
  • Collaborate with Cybersecurity, Infrastructure, Product, Risk, and Application teams to assess identity-related risks and develop secure engineering solutions.
  • Lead architecture reviews, threat modeling exercises, technology assessments, and engineering design decisions for strategic IAM initiatives.
  • Develop standards and best practices for identity governance, access certifications, entitlement management, privileged access, and identity lifecycle management.
  • Evaluate emerging technologies and industry trends to influence enterprise identity strategy and improve security posture.
  • Mentor engineers and architects while serving as a subject matter expert across IAM and identity security domains.
  • Communicate technical strategy, architecture direction, and risk considerations to senior leadership and stakeholders across the enterprise.
  • Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents)
  • Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
  • Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions
  • Understand and account for model limitations, security risks, and operational considerations
  • Apply AI responsibly in development and production environments
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Required Qualifications:
  • 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
  • 7+ years of experience designing and implementing enterprise Identity and Access Management solutions.
Desired Qualifications:
  • Deep expertise in Microsoft Entra ID (Azure AD), Active Directory, Conditional Access, Privileged Identity Management (PIM), Identity Governance, and Access Reviews.
  • Experience defining and governing Agentic AI and Agent365 platforms, including AI agent lifecycle management, security controls, identity integration, privileged access governance, risk management, policy enforcement, audit readiness, regulatory compliance, and human-in-the-loop oversight for enterprise AI deployments.
  • Experience designing enterprise authentication and federation solutions leveraging SAML, OAuth 2.0, OpenID Connect (OIDC), Kerberos, and SCIM.
  • Experience with identity governance, entitlement management, access certifications, joiner/mover/leaver processes, and role lifecycle management.
  • Experience implementing passwordless authentication, phishing-resistant MFA, and modern access management solutions.
  • Strong knowledge of Zero Trust architecture, RBAC, ABAC, least-privilege access, and privileged access management.
  • Experience leading enterprise identity architecture and engineering initiatives within large-scale organizations.
  • Experience with authentication, authorization, federation, and access management technologies.
  • Experience defining engineering standards, technical roadmaps, and enterprise architecture strategies.
  • Experience collaborating across Cybersecurity, Infrastructure, Risk, and Architecture organizations to deliver complex technical solutions.
  • Experience integrating enterprise applications with Microsoft identity services and cloud-based access management platforms.
  • Experience implementing automation and Identity-as-Code using PowerShell, APIs, Terraform, or related technologies.
  • Experience supporting regulated environments and security frameworks including SOX, FFIEC, NIST, PCI-DSS, or similar standards.
  • Industry certifications such as Microsoft Certified: Identity and Access Administrator Associate, Microsoft Cybersecurity Architect Expert, CISSP, CCSP, SABSA, TOGAF, or equivalent.
  • Strong leadership, stakeholder management, and executive communication skills.
Locations:
  • 150 E 42nd Street, New York, NY 10017
Posting Statements:
  • Job posting may come down early due to volume of applicants.
  • Required location(s) listed above. Relocation assistance is not available for this position
  • Salary range is determined by location of the job. May be considered for a discretionary bonus, Restricted Share Rights, or other long - term incentive awards.
  • This position is not eligible for visa sponsorship
  • This role is NOT available for 100% remote work
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$191,000.00 - $305,000.00
Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.
  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement
Posting End Date:
16 Sep 2026
* Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo .
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
HQ

Wells Fargo San Francisco, California, USA Office

420 Montgomery St, San Francisco, CA, United States, 94103

Similar Jobs at Wells Fargo

An Hour Ago
Hybrid
120K-196K Annually
Senior level
120K-196K Annually
Senior level
Fintech • Financial Services
Designs, develops, tests, deploys, and supports secure identity, authentication, authorization, and AI-enabled access management solutions. Leads moderately complex technical initiatives, resolves engineering challenges, mentors less experienced staff, and collaborates with cybersecurity, infrastructure, cloud, product, and application teams. Uses AI-assisted development tools responsibly while addressing security, privacy, compliance, ethical, and operational requirements. Builds cloud-native services using modern programming languages, APIs, containers, Kubernetes, AWS, DevOps practices, and AI technologies.
Top Skills: Access GovernanceAmazon EksAuthenticationAuthorizationAWSCi/CdClaude CodeDockerFastapiGitGithub CopilotIdentity And Access ManagementJavaJavaScriptKubernetesLarge Language ModelsPythonReactRest ApisRetrieval Augmented GenerationSpring BootVector Databases
An Hour Ago
Hybrid
23-31 Hourly
Entry level
23-31 Hourly
Entry level
Fintech • Financial Services
Build customer relationships, understand financial needs, recommend banking products and services, support account openings and credit applications, handle cash transactions, and provide compliant branch service. The role includes proactive outreach, digital-tool adoption, referrals to specialists, risk escalation, and collaboration with branch teammates. Saturday availability and SAFE registration are required.
Top Skills: Digital Banking ToolsLo/Cfpb RequirementsSafe Registration
An Hour Ago
Hybrid
23-31 Hourly
Junior
23-31 Hourly
Junior
Fintech • Financial Services
Build customer relationships in a branch setting, understand financial needs, recommend banking products and services, support account openings and credit applications, process cash transactions, use digital banking tools, make referrals, and maintain compliance with risk and operational standards.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account