Principal Engineer, IAM/PAM

Wells Fargo

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Charlotte, NCIrving, TXPhoenix, AZColumbus, OH
Salary
$159,000–$254,000 / yr
Employment
Full-time
Posted
3 days ago
Freshness
Confirmed live yesterday
Closes
Oct 24, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $203k
This role $206k
$128k most similar roles pay here $279k

This role pays less than 54% of similar roles. Most pay $174,600–$231,600 — the shaded band above. At the midpoint, this role pays about $206k versus about $203k for comparable roles.

Based on 240 similar postings.

Employer

About Wells Fargo

Wells Fargo & Company is one of the largest banks in the United States, providing banking, investment, mortgage, and consumer and commercial finance products and services nationwide. Industry: Banking & Financial Services

Wells Fargo currently has 20 open roles on FindRole.

Listed pay typically runs $139,000–$239,000 across 10 roles with salary data.

Most-posted roles

View all roles at Wells Fargo

At a glance

TL;DR · Principal Engineer, IAM/PAM

The Principal Engineer - IAM/PAM joins the Cybersecurity organization to serve as the principal technical architect for Privileged Access Management strategy, architecture, and engineering standards. This role involves leading the design and modernization of privileged access services for human and non-human identities, focusing on eliminating standing privilege and implementing just-in-time access models. Key responsibilities include establishing enterprise architecture patterns for secrets management, session brokering, and credential discovery while driving strategic integrations across various platforms. The position requires deep expertise in CyberArk Privileged Access Security, HashiCorp Vault, Microsoft Entra ID, ServiceNow, Saviynt, and Sphereboard. Candidates must demonstrate proficiency in AI-assisted development tools like GitHub Copilot to accelerate system design and troubleshooting. The work addresses the technical challenge of securing privileged credentials and automating lifecycle management in a regulated environment.

What does a Engineer earn in Texas?

Median $182000 from 45 postings across 17 companies.

See salary data

What you'll do

  • Serve as the principal technical architect for Privileged Access Management (PAM) strategy and roadmap execution.
  • Lead the design and modernization of privileged access services to eliminate standing privileges and implement just-in-time access.
  • Establish enterprise architecture patterns for privileged credentials, service accounts, secrets management, and non-human identities.
  • Drive strategic integration across CyberArk, HashiCorp Vault, Microsoft Entra ID, and other enterprise identity services.
  • Define engineering standards for credential onboarding, password rotation, session brokering, and privileged access automation.
  • Provide architectural oversight for large-scale PAM transformation initiatives including platform consolidation and vault modernization.
  • Act as a senior technical advisor to executive leadership on security architecture decisions and risk reduction priorities.
  • Leverage AI-assisted development tools to accelerate system design, coding, testing, and troubleshooting.

What we're looking for

  • 7+ years of engineering experience or equivalent through work, training, military, or education.
  • 7+ years of experience in information security, identity and access management, infrastructure security, or engineering.
  • 7+ years of experience designing and implementing enterprise Privileged Access Management solutions.
  • Deep expertise with CyberArk Privileged Access Security, including Enterprise Password Vault, Privileged Session Manager, and Central Policy Manager.
  • Experience developing enterprise security architecture, reference architectures, standards, and engineering patterns.
  • Experience influencing senior leaders, architects, engineering teams, and cross-functional stakeholders.
  • Experience with HashiCorp Vault, cloud-native secrets management, and enterprise secrets modernization programs (preferred).
  • Experience with Microsoft Entra ID, Azure, AWS, Google Cloud, and cloud privileged access models (preferred).

More like this

Similar roles

Associate Director, Cybersecurity Engineering

MSD

Rahway, NJ +1 13 days ago $142,400–$224,100
Privileged Access Management Identity and Access Management HashiCorp Vault CyberArk Delinea BeyondTrust Active Directory Microsoft Entra ID AWS Azure GCP Kubernetes PowerShell Jira Agile Zero Trust ITIL NIST SDLC ServiceNow
10+ yrs exp Hybrid

Solution Lead, Privileged Access Management (PAM)

McKesson Corporation

Irving, TX +1 15 days ago $140,700–$234,500
Privileged Access Management CyberArk Delinea BeyondTrust HashiCorp Vault IAM Zero Trust Azure AWS GCP Kubernetes DevSecOps CI/CD Secrets Management Identity Governance and Administration Infrastructure Automation Containers
10+ yrs exp Hybrid

Principal Engineer

Twilio

Remote 141 days ago $188,240–$235,300
Java Go AWS Lambda EKS DynamoDB Kafka Kubernetes Terraform SQL NoSQL Redis Spark CI/CD LLMs GitHub Copilot Anthropic Claude Microservices
10+ yrs exp Remote

Principal Engineer

Q2

Austin, TX 55 days ago
Python SQL C# Go API Design Cloud Architecture Enterprise Integration Patterns SDLC Service-Oriented Architecture Agile Security Best Practices Integrations Scalability
10+ yrs exp Hybrid

Principal Engineer

Citi

Irving, TX 62 days ago $169,600–$254,400
Java Spring Boot Microservices Open-Shift Public Cloud SOLID TDD BDD LLMs Vector Search high-availability
10+ yrs exp Hybrid

Principal Engineer, VP

State Street

Burlington, MA 89 days ago $120,000–$202,500
Java C# SQL JavaScript Spring Boot Microservices Kubernetes Kafka RDBMS CI/CD Agile Scrum Object-Oriented Programming
10+ yrs exp