Achieve
Principal Security Engineer - Temporary
Tempe, AZ, United States · Principal · Contract
Sponsorship not specifiedDetected 95 days ago
PythonPowerShellAWSGCPAzureCloud PlatformsKubernetesTerraformOAuthCybersecurityNetwork SecurityProject ManagementRecruitingZero TrustLeadershipCommunicationCollaborationProblem SolvingMentoringCISSP
About the role
- Achieve is a leading digital personal finance company.
- We help everyday people move from struggling to thriving by providing innovative, personalized financial solutions.
- By leveraging proprietary data and analytics, our solutions are tailored for each step of our member's financial journey to include personal loans, home equity loans, debt consolidation, financial tools and education.
Responsibilities
- Strategy and Design
- Design and architect comprehensive Identity solutions, including identity lifecycle management, non-human lifecycle management, authentication (MFA, SSO, passwordless), authorization, access governance, and Privileged Access Management (PAM).
- Create and maintain detailed architectural documentation for Identity solutions.
- Lead the strategy and architecture for comprehensive Identity and Access Management (IAM) solutions, explicitly managing User Identities, Workload & Machine Identities (including Service Mesh, Kubernetes, Lambda, and APIs), and other non-human identities across on-premises and cloud environments to govern access rights and privileges.
- Lead the implementation and integration of Identity solutions across various on-premises and cloud environments (e.g., Azure AD, AWS, GCP, Okta, Entra).
- Design and implement strategies to secure non-human machine identities, service accounts, APIs, and automation, utilizing Zero Standing Privilege principles and engineering "Just-in-Time" (JIT) access workflows to eliminate persistent administrative overhead, reduce the blast radius of potential compromises, and enforce strict, least-privilege, and Zero Trust security principles.
- Develop and configure identity provisioning and de-provisioning workflows.
- Partner with the SOC to build ITDR capabilities that detect and automatically neutralize identity-based attacks, such as session hijacking, token theft, and MFA fatigue.
- Act as a "Security Partner" for engineering teams to foster secure development practices.
- Drive successful adoption by collaborating with diverse stakeholders (business units, technology teams, application developers) and translating complex cryptographic and identity concepts into clear business value for product owners and executive leadership.
Requirements
- 5+ years focused on identity and access management.
- Proven experience in designing and implementing enterprise-scale Identity solutions.
- Expert-level experience with cloud-native IAM (AWS IAM, Azure Entra ID, GCP Cloud IAM) and managing identity in distributed microservices architectures.
- Strong experience with Terraform and container orchestration (Kubernetes).
- Hands-on experience with leading IAM platforms and technologies, such as:
Nice to have
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A Master's degree is a plus.
- 8+ years in Cybersecurity/Engineering, with a proven track record of moving legacy organizations towards a Zero Trust architecture.
Skills
- Deep knowledge of IAM principles, best practices, and security models.
- Proficiency in scripting languages (e.g., PowerShell, Python) for automation and integration.
- Understanding of network security, operating systems, and database concepts.
- Familiarity with API security and microservices architecture.
- Protocols:
- Deep mastery of identity protocols and standards: IODC, OAuth 2.0, SAML, and SCIM, with a specific focus on mTLS and JWT security.
- Infrastructure: Strong experience with Terraform and container orchestration (Kubernetes).
- Soft
- Excellent analytical and problem-solving skills.
- Strong communication (written and verbal) and interpersonal skills.
- Strong project management and organizational skills.
- Proven ability to strategically influence and expertly negotiate with stakeholders across all organizational levels.
Benefits
- Medical, dental, and vision with HSA and FSA options
- Competitive vacation and sick time off, as well as dedicated volunteer days
Equal opportunity
- Identity and Access Administrator Associate/Expert, Okta Certified Professional/Administrator/Consultant).
- All your information will be kept confidential according to EEO guidelines.
- A safe place to connect and a commitment to diversity and inclusion through our six employee resource groups
Apply directly at Achieve →Create a free account for alerts like thisView Achieve immigration profile
This listing is sourced directly from Achieve's careers page and normalized into a canonical job model.