We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Principal Systems Engineer - IAM

Early Warning Services LLC
parental leave, paid time off, flex time, 401(k), retirement plan
United States, Arizona, Scottsdale
5801 North Pima Road (Show on map)
Mar 04, 2026

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Job Description
We are seeking a Principal Identity & Access Management Engineer to lead the strategy, architecture, and evolution of enterprise IAM across on-premises and cloud environments. This role is a senior technical authority responsible for designing scalable, secure identity platforms and defining identity standards that enable the business while reducing risk.

You will serve as the IAM architect and thought leader, partnering with security, infrastructure, application teams, and cloud engineering to ensure identity is consistently implemented as a foundational security control across the enterprise.

Key Responsibilities

Enterprise IAM Architecture & Strategy

  • Own and evolve the enterprise IAM architecture, spanning on-premises (Active Directory) and cloud identity platforms (e.g., Microsoft Entra ID/Azure AD and related services).
  • Define IAM roadmaps, reference architectures, and design patterns aligned with Zero Trust and least-privilege principles.
  • Lead architectural decisions for hybrid identity, cloud adoption, and identity modernization initiatives.
  • Evaluate and influence IAM tooling, platform capabilities, and vendor solutions.

Active Directory & Directory Services

  • Act as the subject matter expert for Active Directory architecture, including forest/domain design, trusts, replication, authentication flows, and security hardening.
  • Guide AD modernization, consolidation, and integration with cloud identity platforms.
  • Define standards for directory lifecycle management, privileged access, and tiered administration models.

Identity Standards & Controls

  • Establish and govern enterprise identity standards, including:
    • Authentication and session management
    • Authorization models (RBAC, ABAC where applicable)
    • Federation, SSO, and identity brokering
    • Least-privilege and separation of duties
  • Define patterns for secure access to applications, APIs, infrastructure, and cloud resources.
  • Define standards for conditional access, authentication assurance levels, and federation trust models across workforce and/or customer identity platforms.
  • Ensure consistent implementation of identity standards across business units and platforms.

Cloud & Hybrid Identity

  • Architect secure hybrid identity solutions integrating on-prem and cloud environments.
  • Design identity approaches for cloud-native workloads and SaaS platforms.
  • Partner with cloud and platform teams to embed IAM into landing zones, CI/CD pipelines, and infrastructure-as-code.

Governance, Risk & Enablement

  • Serve as a senior advisor on identity-related risk, compliance, and audit initiatives.
  • Review and approve IAM designs for critical systems and enterprise programs.
  • Mentor engineers and architects; raise the overall IAM maturity of the organization.
  • Translate complex identity concepts into clear guidance for technical and non-technical stakeholders.

Required Qualifications

  • Education and/or experience typically obtained through completion of a bachelors degree
  • Typically 15 years of progressive systems or software engineering experience.
  • 10+ years of experience in Identity & Access Management, active directory architecture and security, with significant focus on enterprise-scale environments.
  • Strong experience with cloud identity platforms (e.g., Microsoft Entra ID/Azure AD) and hybrid identity models.
  • Proven knowledge of identity standards and protocols (e.g., SAML, OAuth 2.0, OpenID Connect).
  • Strong understanding of authentication, authorization, session management, federation, SSO, and RBAC.
  • Experience designing identity solutions aligned with least privilege and Zero Trust principles.
  • Ability to lead architecture discussions and influence decisions at senior technical and leadership levels.

Preferred Qualifications

  • Experience operating IAM in highly regulated or large enterprise environments.
  • General familiarity with privileged access concepts to ensure appropriate integration boundaries with IAM platforms.
  • Cloud security or enterprise security architecture background.
  • Relevant certifications (e.g., Microsoft Identity, security architecture certifications) a plus.

What Makes This Role Principal-Level

  • You set direction and standards, not just implement solutions.
  • You influence multiple teams and platforms across the enterprise.
  • You are the escalation point for the most complex identity challenges.
  • Your work shapes how identity enables security, scalability, and business agility.

Physical Requirements

Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.

Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

The base pay scale for this position in:
Phoenix, AZ in USD per year is: $175,000 - $230,000.
San Francisco, CA in USD per year is: $221,000 - $276,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

Some of the Ways We Prioritize Your Health and Happiness

  • Healthcare Coverage-Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.

  • 401(k) Retirement Plan-Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.

  • Paid Time Off -Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.

  • 12 weeks of Paid Parental Leave

  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

AndSOmuch more! We continue to enhance our program, so be sure tocheck our Benefits page herefor the latest. Ourteamcan share more during the interview process!

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.

Applied = 0

(web-6bcf49d48d-j4skk)