All roles

[Remote] Principal Security Engineer - Temporary

Remote · USA Full-time New today

Note: The job is a remote job and is open to candidates in USA. Achieve is a leading digital personal finance company that provides innovative financial solutions. They are seeking a Principal Security Engineer to architect the next generation of Identity, transitioning the enterprise to a Risk-Based Authorization model and designing comprehensive Identity solutions to secure their critical assets.

Responsibilities

  • Continuous Adaptive Trust: Transition the enterprise from static, role-based access to a Risk-Based Authorization model that evaluates signals (device posture, behavior, location) in real-time
  • Enhance the enterprise Identity strategy, roadmap, and architecture in alignment with business goals and security policies
  • Design and architect comprehensive Identity solutions, including identity lifecycle management, non-human lifecycle management, authentication (MFA, SSO, passwordless), authorization, access governance, and Privileged Access Management (PAM)
  • Evaluate and select appropriate Identity technologies and platforms
  • Create and maintain detailed architectural documentation for Identity solutions
  • Lead the strategy and architecture for comprehensive Identity and Access Management (IAM) solutions, explicitly managing User Identities, Workload & Machine Identities (including Service Mesh, Kubernetes, Lambda, and APIs), and other non-human identities across on-premises and cloud environments to govern access rights and privileges
  • Lead the implementation and integration of Identity solutions across various on-premises and cloud environments (e.g., Azure AD, AWS, GCP, Okta, Entra)
  • Integrate Identity systems with enterprise applications, platforms, and services using standard protocols (SAML, OAuth, OpenID Connect, SCIM)
  • Design and implement strategies to secure non-human machine identities, service accounts, APIs, and automation, utilizing Zero Standing Privilege principles and engineering "Just-in-Time" (JIT) access workflows to eliminate persistent administrative overhead, reduce the blast radius of potential compromises, and enforce strict, least-privilege, and Zero Trust security principles
  • Develop and configure identity provisioning and de-provisioning workflows
  • Partner with the SOC to build ITDR capabilities that detect and automatically neutralize identity-based attacks, such as session hijacking, token theft, and MFA fatigue
  • Act as a "Security Partner" for engineering teams to foster secure development practices
  • Drive successful adoption by collaborating with diverse stakeholders (business units, technology teams, application developers) and translating complex cryptographic and identity concepts into clear business value for product owners and executive leadership
  • Provide technical leadership and guidance, championing and delivering self-service Identity APIs and SDKs to enable developers to build secure products with minimal friction (Developer Experience - DevEx)
  • Provide technical leadership, mentorship and guidance to Identity Engineers and other team members

Skills

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field
  • 8+ years in Cybersecurity/Engineering, with a proven track record of moving legacy organizations towards a Zero Trust architecture
  • 5+ years focused on identity and access management
  • Proven experience in designing and implementing enterprise-scale Identity solutions
  • Drive security automation and 'Builder' Mentality by architecting and implementing automation-first solutions (e.g., scripts, APIs, Infrastructure as Code) to eliminate reliance on manual governance processes and ensure security policy is enforced at scale and embedded into developer workflows
  • Hands-on experience with leading IAM platforms and technologies, such as: Identity Federation: Azure AD/Entra, Okta, Ping Identity, ADFS; IGA (Identity Governance and Administration): SailPoint, Saviynt, Oracle Identity Manager; PAM (Privileged Access Management): CyberArk, Delinea, BeyondTrust; Directory Services: Active Directory, Azure Active Directory, LDAP
  • Deep knowledge of IAM principles, best practices, and security models
  • Proficiency in scripting languages (e.g., PowerShell, Python) for automation and integration
  • Understanding of network security, operating systems, and database concepts
  • Familiarity with API security and microservices architecture
  • Deep mastery of identity protocols and standards: IODC, OAuth 2.0, SAML, and SCIM, with a specific focus on mTLS and JWT security
  • Expert-level experience with cloud-native IAM (AWS IAM, Azure Entra ID, GCP Cloud IAM) and managing identity in distributed microservices architectures
  • Strong experience with Terraform and container orchestration (Kubernetes)
  • Excellent analytical and problem-solving skills
  • Strong communication (written and verbal) and interpersonal skills
  • Ability to work independently and as part of a collaborative team
  • Strong project management and organizational skills
  • Proven ability to strategically influence and expertly negotiate with stakeholders across all organizational levels
  • A Master's degree is a plus
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • Relevant vendor certifications (e.g., Microsoft Certified: Identity and Access Administrator Associate/Expert, Okta Certified Professional/Administrator/Consultant)

Benefits

  • 401 (k) with employer match
  • Medical, dental, and vision with HSA and FSA options
  • Competitive vacation and sick time off, as well as dedicated volunteer days
  • Access to wellness support through Employee Assistance Program, physical and mental health wellness programs
  • Pet care discounts for your furry family members
  • Financial support in times of hardship with our Achieve Care Fund
  • A safe place to connect and a commitment to diversity and inclusion through our six employee resource groups

Company Overview

  • Achieve provides digital personal finance solutions to help clients improve their financial well-being. It was founded in 2002, and is headquartered in Tempe, Arizona, USA, with a workforce of 1001-5000 employees. Its website is https://www.achieve.com.
  • Company H1B Sponsorship

  • Achieve has a track record of offering H1B sponsorships, with 1 in 2026, 13 in 2025, 8 in 2024, 6 in 2023, 18 in 2022, 12 in 2021. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    Related roles

    [Remote] Security Engineer I (Full-Time) - United States

    Remote · USA Full-time

    [Remote] Service Now Customer Support Engineer II (Full-Time) - United States

    Remote · USA Full-time

    [Remote] Senior Mobile Engineer, Deliver

    Remote · USA Full-time

    [Remote] Security Engineer - Email Security

    Remote · USA Full-time

    [Remote] Account Executive III, Strategic Alliances

    Remote · USA Full-time

    [Remote] Reinsurance Underwriter Consultant

    Remote · USA Full-time

    [Remote] Principal Cloud Application Security Engineer

    Remote · USA Full-time

    [Remote] Commercial Danaher Business System Leader, North America (Continuous Improvement Leader)

    Remote · USA Full-time

    [Remote] Senior Product Manager- Revenue Cycle Management (RCM)

    Remote · USA Full-time

    [Remote] DevOps Architect

    Remote · USA Full-time

    Product Management Senior Analyst (Clinical & Customer Data) - Remote

    Remote · USA Full-time

    Attorney Network & Performance Director (1099, Remote, Part-Time)

    Remote · USA Full-time

    Associate Counsel - San Antonio (Remote)

    Remote · USA Full-time

    Legal Counsel (f/m/d)

    Remote · USA Full-time

    (Senior) Fullstack Engineer - New Platform (m/f/x) (onsite / remote in Germany)

    Remote · USA Full-time

    Experienced Customer Success Manager – Cloud Cost Optimization & Strategic Growth

    Remote · USA Full-time

    Live Chat Specialist

    Remote · USA Full-time

    Experienced Technical Content Designer – Customer Service Expertise at blithequark

    Remote · USA Full-time

    Experienced Key Account Manager – Target Beverages Customer Team at arenaflex

    Remote · USA Full-time

    Accounts Receivable Specialist

    Remote · USA Full-time