Principal Identity Security Engineer
San Francisco, CA - USA
Job Summary
Happen Bank(formerly LendingClub)is built around a simple purpose: to clear the way to help people turn intention into action and action intofinancial progress. That means offering focused products a frictionless mobile-first experience and clear terms with no gotchas. Respect and fairness is part of our DNA and that ideal shapes how we work how we treat each other and how we invest in our employees and our community. Join us in using data bold thinking and a commitment to innovation to help clear the way for millions of Americans to achieve more.
- Set the technical direction architecture and engineering standards for Happen Banks identity security ecosystem across identity governance authentication authorization directory services privileged access and non-human identity establishing reference architectures and reusable patterns that improve security reliability and scalability
- Design and deliver scalable identity solutions across SailPoint Okta Active Directory AWS Terraform and GitHub staying hands-on in architecture automation integrations and troubleshooting when needed
- Own the design and operation of privileged access management on Delinea (Thycotic) Secret Server including vaulting secret rotation discovery session controls and privileged account lifecycle across the enterprise
- Build automation APIs and Infrastructure-as-Code and establish AI-assisted engineering workflows that improve provisioning access governance lifecycle management and engineering quality while maintaining appropriate security governance and regulatory controls
- Define and mature non-human identity (NHI) capabilities including service accounts workload identities machine identities secrets integrations ownership lifecycle governance and access controls
- Lead complex identity initiatives from strategy through implementation partnering with Security Infrastructure Risk and Internal Audit to support examinations control design remediation and sustainable resolution of identity-related findings
- Evaluate emerging identity security capabilities including phishing-resistant authentication Zero Trust and identity threat detection and response and set standards for the responsible adoption of AI across identity engineering
- Raise the technical bar of the identity function through mentorship design reviews vendor evaluations and proof-of-concept initiatives
- 10 years of experience in identity and access management (IAM) Information Security or Security Engineering; bachelors degree in a related field; or equivalent work experience
- Deep expertise in identity security principles including identity lifecycle management identity governance and administration authentication authorization access certification privileged access and non-human identity
- Strong hands-on experience with SailPoint or another enterprise IGA platform Okta Active Directory AWS identity services Terraform GitHub and identity automation
- Hands-on production experience with enterprise privileged access management ideally Delinea (Thycotic) Secret Server including vaulting rotation discovery and privileged account lifecycle
- Proven experience designing enterprise-scale identity architectures and leading complex technical initiatives through ambiguity competing priorities and cross-functional dependencies
- Experience building automation through scripting Infrastructure-as-Code AI-assisted development practices and sound software engineering principles
- Experience working in a highly regulated environment and supporting regulatory examinations audits control assessments and remediation activities
- Strong understanding of SOX FFIEC OCC PCI DSS NIST least privilege segregation of duties control design and audit evidence requirements
- Ability to make and defend sound technical decisions when security regulatory operational and business requirements compete
- Demonstrated ability to mentor engineers improve technical standards influence senior stakeholders and drive organizational change without direct authority
- You take ownership of outcomes not just deliverables and proactively identify opportunities to improve identity security engineering quality and operational resilience
- You understand how to apply AI to complex high-stakes identity security worknot just to improve efficiency but to improve engineering quality accelerate delivery and unlock better business outcomes. You establish a high bar for responsible AI adoption by considering data integrity security model limitations privacy and regulatory requirements and you continuously evolve engineering practices by building new AI-enabled workflows rather than simply automating existing ones
Nice to Have
- Experience designing non-human identity or machine identity programs at scale
- Experience designing identity authorization and governance controls for AI agents including identity guardrails least-privilege access and policy enforcement
- Experience with cloud identity and workload identity patterns in AWS or comparable cloud environments
- Experience evaluating identity technologies and leading vendor selection or proof-of-concept initiatives
Work Location
San Francisco
The above locations are eligible offices for this locations have been determined to foster in-person collaboration with this roles team or the related business lines. We utilize a hybrid work model and our teams are in-office Tuesdays Wednesdays and -person attendance is essential for this roles success and remote placement will not be Bank offers relocation based on actual job level.
Time Zone Requirements
Local hours (PT)
While the position will primarily work local hours Happen Bank is headquartered in Pacific Time and our ideal candidate will be flexible working across time zones when necessary.
Travel Requirements
As needed travel to Happen Bank offices and/or other locations as needed.
Compensation
The target base salary range for this position is 00. The base salary of the role will be determined by job-related knowledge experience education skills and location. Base salary is just one part of Happen Banks Total Rewards package. You may also be eligible for long-term awards (equity) and an annual bonus (which is based on company performance employee performance and eligible earnings).
Were creating new financial services solutions for our members based on fairness simplicity and heart and we treat our employees the same way. We offer a competitive benefits package that includes medical dental and vision plans for employees and their families 401(k) match health and wellness programs flexible time off policies for salaried employees up to 16 weeks paid parental leave and more.
#LI-Hybrid
#LI-JH1
Happen Bank is an equal opportunity employer and dedicated to diversity equity and inclusion in the workplace. We do not discriminate on the basis of race religion color national origin sex (including pregnancy childbirth reproductive health decisions or related medical conditions) gender gender identity gender expression sexual orientation age marital status veteran status disability status political views or activity or other applicable legally protected characteristics. We believe that a variety of perspectives will make our teams and business stronger as we work together to transform the traditional banking system.
We are committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. If you need assistance or an accommodation due to a disability please contact us at
Notice on AI Tool Use
For select roles and locations candidate interviews may be recorded transcribed and summarized by tools such as artificial intelligence (AI) to assist our hiring managers with the application process.
You will have the opportunity to opt out of recording transcription and summarization prior to any scheduled interviews. We will not discriminate against you if you choose to opt out.
During the interview we will collect the following categories of personal information from or about you: contact information identifiers professional and employment-related information sensory information (audio/video recording) and any other categories of personal information you choose to share with us. We will use this information to evaluate your application for employment.
We will only share your interview transcription or summary with persons whose expertise or technology is necessary to process your application evaluate your fitness for a position and administer or support the tool. We will not sell your personal information or disclose it to any third party for their marketing purposes. For more information about how we will handle your personal information please refer to our Privacy Disclosure.
We will delete any recording of your interview promptly but in no event later than 30 days after making a hiring decision.
Required Experience:
Staff IC
About Company
We’re rewriting the rules of traditional banking, and we only win when our customers succeed. Personal loans up to $60,000, savings, CDs and more. Check your rate online in minutes without impacting your credit score.