Principal IAM Engineer
About the role
As a Principal IAM Engineer at Blackhawk Network, you'll play a pivotal role in shaping the identity and access management program, ensuring robust security and efficient operations across the organization.
Responsibilities
-
Leads the overall strategy & direction of the organization's identity and access management program, serving as the principal architect and program owner.
-
Establishes IAM principles, standards, and best practices across identity lifecycle management, identity governance & administration (IGA), privileged access management (PAM), and access request/entitlement processes.
-
Designs & implements comprehensive identity governance solutions to consolidate fragmented identity systems (multiple AD domains, Okta tenants) into a unified, compliant architecture.
-
Provides technical vision in the deployment of authentication, authorization, provisioning, and access governance technologies across heterogeneous environments.
-
PARTNERS WITH COMPLIANCE, SECURITY, AND IT OPERATIONS TEAMS TO ENSURE IAM SOLUTIONS MEET REGULATORY REQUIREMENTS AND SECURITY OBJECTIVES.
-
Develops access request workflows, entitlement models, and identity governance processes that balance security with operational efficiency.
-
Mentors and upskills existing IT staff on IAM principles and best practices, building organizational competency in identity management.
-
Evaluates emerging IAM technologies and methodologies (zero trust, passwordless authentication, identity threat detection) to keep the organization at the forefront of access security.
Qualifications
-
Bachelor's degree + 12+ years experience in identity and access management, directory services, or equivalent relevant experience.
-
Technical master in IAM principles and methodologies including identity lifecycle management, role-based access control (RBAC), identity governance & administration (IGA), privileged access management (PAM), and access certification.
-
Expert-level understanding of identity protocols and standards such as SAML, OAuth, OIDC, SCIM, LDAP, and Kerberos.
-
Deep experience with enterprise directory services (Active Directory, Azure AD) and modern identity platforms; Okta experience highly valued.
-
Proven ability to architect and implement IAM solutions in complex, multi-domain environments with legacy system constraints.
-
Strong understanding of compliance frameworks (PCI DSS, SOC2, SOX, NYDFS) and how IAM controls support regulatory requirements.
-
Experience with ITSM platforms (ServiceNow) for access request and workflow automation.
-
Demonstrated ability to build IAM programs from foundational concepts through mature operational state.
-
AI fluency with demonstrated experience using AI tools effectively in the context of this role.
-
Excellent communication skills with ability to influence senior stakeholders and drive organizational change without direct authority.
Benefits
Salary Range for California Residents Only: $170,360.00 to $230,000.00
Pay is based on several factors including but not limited to education, work experience, certifications, etc.
In addition to your salary, Blackhawk Network offers benefits including 401k with employer match, medical, dental, vision, 12 paid holidays in the year 2026, 1 hour of sick pay accrual for every 30 hours worked, parental leave, life insurance, disability insurance, accident and illness insurance, health and dependent care flexible spending accounts, wellness benefits, and flexible time off for all full-time employees.
EEO Statement
Blackhawk Network provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.