LendingClub

Principal IAM Engineer

LendingClub
Apply
4 hours ago

Base Salary

$197k - $232k/yr

Responsibilities

  • Set technical direction, architecture, and engineering standards for the enterprise identity security ecosystem.
  • Design and deliver scalable identity solutions across SailPoint, Okta, Active Directory, AWS, Terraform, and GitHub.
  • Own privileged access management on Delinea (Thycotic) Secret Server, including vaulting, secret rotation, discovery, session controls, and privileged account lifecycle.
  • Build automation, APIs, infrastructure-as-code, and AI-assisted engineering workflows for provisioning, access governance, and lifecycle management.
  • Define and mature non-human identity capabilities covering service accounts, workload identities, machine identities, secrets integrations, ownership, lifecycle governance, and access controls.
  • Lead identity initiatives from strategy through implementation and partner with Security, Infrastructure, Risk, and Internal Audit on controls, examinations, remediation, and findings.
  • Evaluate identity security capabilities such as phishing-resistant authentication, Zero Trust, and identity threat detection and response.
  • Mentor engineers, conduct design reviews, evaluate vendors, and lead proof-of-concept initiatives.

Requirements

  • 10+ years of experience in identity and access management, information security, or security engineering.
  • Bachelor's degree in a related field or equivalent work experience.
  • Deep expertise in identity lifecycle management, identity governance and administration, authentication, authorization, access certification, privileged access, and non-human identity.
  • Strong hands-on experience with SailPoint or another enterprise IGA platform, Okta, Active Directory, AWS identity services, Terraform, GitHub, and identity automation.
  • Production experience with enterprise privileged access management, ideally Delinea (Thycotic) Secret Server, including vaulting, rotation, discovery, and privileged account lifecycle.
  • Experience designing enterprise-scale identity architectures and leading complex technical initiatives across competing priorities and cross-functional dependencies.
  • Experience building automation through scripting, infrastructure-as-code, AI-assisted development practices, and software engineering principles.
  • Experience in highly regulated environments supporting examinations, audits, control assessments, and remediation.
  • Understanding of SOX, FFIEC, OCC, PCI DSS, NIST, least privilege, segregation of duties, control design, and audit evidence requirements.
  • Ability to make and defend technical decisions across security, regulatory, operational, and business requirements.
  • Ability to mentor engineers, improve technical standards, influence senior stakeholders, and drive organizational change without direct authority.
  • Preferred experience includes non-human or machine identity programs, identity controls for AI agents, cloud and workload identity patterns, and vendor selection or proof-of-concept leadership.

Benefits

  • Hybrid work model with required in-office attendance Tuesdays, Wednesdays, and Thursdays in San Francisco; remote placement is not considered.
  • Relocation assistance is offered based on actual job level.
  • Medical, dental, and vision plans for employees and families.
  • 401(k) match and health and wellness programs.
  • Flexible time off policies for salaried employees.
  • Up to 16 weeks of paid parental leave.
  • Travel to Happen Bank offices or other locations as needed.
  • Local Pacific Time working hours, with flexibility across time zones when necessary.

Tech Stack

Categories

LendingClub

About LendingClub

1,001-5,000 employees

LendingClub is now Happen Bank — a name that reflects who we are today and why we exist. While our name, logo, and visual identity are changing, the company, our products and services, and core values remain the same. To learn more about us, please visit https://www.linkedin.com/company/happen-bank/.

Contact me