Principal IAM Engineer
Pleasanton, Alameda County, California, 94566, USA
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Principal IAM Engineer
Job : | Category:
Technology | Position Type:
Full Time |
Location:
US-CA-Pleasanton
Today, through BHN’s single global platform, businesses of all kinds can tap into the world’s largest network of branded payment solutions. BHN helps businesses grow revenue, increase loyalty, motivate and reward their teams, disburse funds and engage consumers. Branded payment solutions include the issuance and distribution of gift cards, egifts, corporate payouts and rewards, along with the technology to deliver these products in seamless, integrated ways.
BHN’s network spans the globe with more than 400,000 consumer touchpoints. Learn more at
Hybrid flexibility: At Blackhawk Network, you’ll enjoy the best of both worlds—focused remote work plus in‑person collaboration on Tuesdays and Wednesdays
, our regular in‑office days at our Pleasanton headquarters. This rhythm gives you the tools, connection, and autonomy you need to make a real impact.
As a Principal IAM Engineer, you’ll lead the strategic vision and technical direction of our identity and access management program, shaping how we leverage IAM principles and emerging technologies to build a world‑class identity governance framework. You’ll be the technical architect who designs and implements comprehensive IAM solutions across our complex multi‑domain environment, establishing the foundational practices and standards that will govern access security for years to come.
This role combines deep technical mastery in areas such as identity lifecycle management, access governance, privileged access management, and authentication/authorization protocols with influential leadership that guides both technology decisions and organizational IAM maturity. Your work will directly impact the security, compliance, and operational efficiency of our entire organization.
YOU' D LOVE THIS JOB IF
- you’re passionate about establishing IAM best practices from the ground up and love the challenge of building a comprehensive identity governance program in a complex, fragmented environment
- you thrive on being the technical visionary who doesn’t just solve today’s access and entitlement challenges, but architects the foundational principles and strategies that mature the organization’s entire IAM posture
- you find deep satisfaction in leading and influencing cross‑functional teams without direct reports, knowing that your technical guidance and program ownership shapes how the entire organization thinks about identity, access, and security
- you excel at translating sophisticated IAM concepts into strategic roadmaps that align with compliance requirements (PCI DSS, SOC2, NYDFS) and get stakeholders excited about identity governance investments
- Leads the overall strategy & direction of the organization’s identity and access management program, serving as the principal architect and program owner
- Establishes IAM principles, standards, and best practices across identity lifecycle management, identity governance & administration (IGA), privileged access management (PAM), and access request/entitlement processes
- Designs & implements comprehensive identity governance solutions to consolidate fragmented identity systems (multiple AD domains, Okta tenants) into a unified, compliant architecture
- Provides technical vision in the deployment of authentication, authorization, provisioning, and access governance technologies across heterogeneous environments
- Partners with Compliance, Security, and IT Operations teams to ensure IAM solutions meet regulatory requirements and security objectives
- Develops access request workflows, entitlement models, and identity governance processes that balance security with operational efficiency
- Mentors and upskills existing IT staff on IAM principles and best practices, building organizational competency in identity management
- Evaluates emerging IAM technologies and methodologies (zero trust, passwordless authentication, identity threat detection) to keep the organization at the forefront of access security
- BA + 12+ years experience in identity and access management, directory services,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).