Principal Software Engineer, Identity Services
THE TEAM
Our client's Identity Services team owns Identity and Access Management (IAM) within the company, with a core focus on enabling secure and appropriate administrative access to production and production-adjacent services. The team's scope spans Active Directory, Okta, Adaxes, bastion and jumpbox implementations, multi-factor authentication, hardware security keys, and a range of other access solutions. This team plays a critical role in protecting privileged access pathways and ensuring production access follows least privilege principles across a high-volume, 24x7 global environment.
What makes this team distinctive is that they don't just configure identity platforms, they engineer them. They build automation, internal tooling, and integrations that make identity services reliable, scalable, and self-healing at the scale of one of the world's largest live entertainment companies.
THE JOB
Are you an engineer who thinks deeply about security, builds things that last, and can lead a team while doing it? Our client is looking for a Principal Software Engineer to set the technical direction for their Identity Services function, and to help lead the people who deliver it.
This is a hybrid role by design. The majority of your time (~70%) is spent in the Identity function: hands-on building, and owning the strategy, architecture, and roadmap for how they engineer and automate identity infrastructure. The remainder (~30%) is spent leading, mentoring, coaching, and providing day-to-day technical and people leadership for the team. They're looking for someone who has been a team lead or people manager before and wants to keep their hands on the keyboard: a player-coach, not a full-time manager and not a heads-down IC.
You will own the architecture of the IAM tooling and integrations, drive security-first design across the platform, own the Identity Services roadmap, and lead adoption of privileged access principles for production access. Critically, you will do this with a strong bias toward a software-engineering-based solutions approach: what the team builds is production-quality software, designed, tested, observable, and maintainable, not one-off scripts. You set that bar by example, in the code you write and the code you review.
If you're energized by solving hard identity engineering problems, building systems that run at scale, growing the engineers around you, and leaving a permanent mark on how a global platform manages access, this is your role.
What success looks like at 6 months: The team is executing against a roadmap you own, with your architectural guidance on identity automation and tooling. You've driven meaningful improvement in at least one core area, PAM, compliance reporting, or automated provisioning, and shipped it, not just designed it. Engineers come to you for technical decisions and for growth; you run effective 1:1s and raise the team's engineering bar measurably. You've built trust through delivery, not just direction. Much of the access review and provisioning work is still manual; your first year is turning it into owned software.
WHAT YOU WILL BE DOING
Work Distribution (≈70% Identity function / ≈30% leadership):
- Hands-On Identity Engineering (35%): Writing and reviewing production-grade code for identity automation, integrations, and tooling. Building the prototype that proves (or kills) an approach. Incident response, debugging, and urgent security fixes when they arise.
- Strategy, Architecture & Roadmap Ownership (35%): Owning and driving the Identity Services roadmap and long-term technical direction. Designing secure identity architectures, conducting security reviews, implementing and leading PAM strategy. Producing documentation, diagrams, and proofs-of-concept that guide the team's execution and align identity strategy with the company's security program objectives.
- Team Leadership & People Management (30%): Providing day-to-day technical and people leadership, mentoring and coaching engineers, running 1:1s and growth conversations, setting standards, and helping prioritize and unblock the team's work. Acting as a lead the team trusts and leadership relies on.
Identity Engineering & Automation:
- Design and build internal tooling, APIs, and automation frameworks that make identity operations reliable, repeatable, and self-service
- Apply secure software development practices to all IAM tooling, automation, and integrations, writing maintainable, testable, observable code, and holding others' code to the same standard in review
- Build and own integrations between identity platforms (Okta, Active Directory, Adaxes) and adjacent infrastructure systems
- Implement Infrastructure as Code for identity infrastructure provisioning and lifecycle management
- Automate identity lifecycle workflows: provisioning, deprovisioning, access reviews, and reconciliation
- Drive adoption of CI/CD practices for identity configuration and tooling deployments via GitLab
- Set the software-engineering standard for the team, production-quality engineering over scripting; solutions validated with working code, not slideware
Security Architecture, Strategy & Roadmap:
- Own the Identity Services technical roadmap and drive enterprise-wide identity architecture decisions
- Design and implement privileged access management architecture for production access, aligned with enterprise security strategy
- Develop the identity security roadmap for production and administrative access aligned with the company's security program
- Lead privileged access management (PAM) strategy and implementation for production systems
- Establish security metrics and KPIs for production access and privileged identity services
- Lead threat modeling for production access pathways and identity infrastructure
- Design break-glass procedures, just-in-time access, and temporary privilege escalation workflows
- Conduct security reviews of authentication and authorization patterns and propose improved designs
- Design highly scalable, resilient IAM architecture supporting 24x7 global operations
Team Leadership & People Management:
- Provide technical and people leadership for the Identity Services team, fostering a culture of psychological safety, continuous learning, and technical excellence
- Mentor and coach engineers; run regular 1:1s and career-development conversations that help engineers grow
- Set clear expectations and standards for engineering quality, security, and delivery
- Help prioritize the backlog and remove blockers; balance operational demand against strategic project work
- Participate in recruiting, interviewing, and hiring top IAM/engineering talent
- Serve as an escalation point and advocate for the team across the broader technology organization
Cross-Team Collaboration & Leadership:
- Serve as the technical authority for identity engineering across the organization
- Partner with Infrastructure Security Engineering and enterprise InfoSec on enterprise identity requirements and security initiatives
- Drive remediation of identity-related findings from audits and assessments
- Collaborate with platform, application, and development teams to ensure identity services integrate cleanly across the stack
- Communicate priorities, progress, risks, and roadmap clearly to senior leadership and adjacent stakeholders
Incident Response & Operational Excellence:
- Support security incident response with identity and access expertise
- Implement preventative measures to reduce identity-related security incidents
- Develop and maintain incident response runbooks for identity services; run tabletop exercises
- Proactively identify and address stability, capacity, and performance concerns before they become incidents
- Participate in on-call rotation and after-hours support as required
WHAT YOU NEED TO KNOW (TECHNICAL SKILLS/COMPETENCIES)
Required:
- Prior experience as a team lead or people manager, with direct responsibility for engineer mentorship/development and team delivery, you've led people, not just projects
- Strong software engineering proficiency in Python and/or Go, beyond scripting and automation glue. You design, build, test, and review production-quality services and tools, and you write maintainable, testable, observable code with an emphasis on security
- Expertise in Microsoft Active Directory and related components: Group Policy, LAPS, LDAP, AD-integrated DNS
- Experience with Privileged Access Management (PAM) solutions and strategies
- Practical knowledge of MFA best practices and hardware security key management (e.g., YubiKey)
- OAuth/OIDC/SAML authentication protocols and their security and engineering implications
- DevOps/SRE experience: GitLab CI/CD, IaC (Terraform, Ansible, or similar), monitoring and alerting (Prometheus, Grafana, Splunk), SRE principles
- Must be legally authorized to work in the US; this role is not eligible for visa sponsorship
Highly Desirable:
- Advanced Okta configuration and security hardening experience
- Experience with Adaxes or similar unified Active Directory management platforms
- Familiarity with cloud IAM patterns on AWS (preferred) or GCP, with a security and engineering focus
- Experience with identity verification / IDV platforms (e.g., Persona) and self-service verification flows
- Experience designing or building internal developer portals, service catalogs, or self-service access tooling
- Solid grounding in Zero Trust architecture principles and hands-on implementation experience
- Experience working within Agile/SAFe frameworks including sprint planning and PI Planning
- Understanding of PCI-DSS compliance and security best practices in the context of identity systems
- Kubernetes and containerization experience (identity workloads increasingly run as containerized jobs/services)
- Experience with architectures for secure production access
- Experience owning a technical roadmap or strategic direction for a service or platform
- Familiarity with security frameworks and threat modeling methodologies
- Experience managing large-scale Linux & Windows infrastructure
- Contribution to open-source security or identity tooling
- Background in API design for identity and access-control integrations
HOW WE WORK
- Software-engineering approach to identity: solutions are validated with working code, not slideware; prototypes are built to graduate into owned, maintained software rather than remain one-off scripts
- AI-assisted engineering is standard practice, with the same discipline as always: small focused changes, real review, working demos
- Significant autonomy within an Agile (SAFe) environment
- High-trust, high-visibility work: privileged-access changes, incidents, and audits come with composure, discretion, and rigor attached
YOU (BEHAVIORAL SKILLS / COMPETENCIES)
- Player-coach: You lead a team and still ship. You get energy from both building great systems and growing great engineers, and you know when each is the job
- Builder's mindset: You ship things that work, get adopted, and make a lasting difference
- Security-first: Deeply concerned with the security and compliance implications of your systems; able to balance rigorous security requirements with operational and business needs
- Technically authoritative: Extremely knowledgeable on IAM and security subject matter; comfortable making and defending high-stakes architectural decisions and owning the roadmap behind them
- People-first leadership: Genuinely invests in the growth and wellbeing of team members; uses coaching to develop engineers' problem-solving and careers
- Autonomous and proactive: Drives your own work forward, identifies problems before they surface, and owns outcomes end-to-end
- Focused on quality: Committed to security, reliability, observability, and high standards of code quality and maintainability across everything the team builds
Information collected and processed through your application with INSPYR Solutions (including any job applications you choose to submit) is subject to INSPYR Solutions’ Privacy Policy and INSPYR Solutions’ AI and Automated Employment Decision Tool Policy: https://www.inspyrsolutions.com/policies/. By submitting an application, you are consenting to being contacted by INSPYR Solutions through phone, email, or text.