Principal Engineer (S) - Identity and Access Management
thrivent
First seen here today.
Apply at thrivent
Opens the original listing in a new tab.
Full description
As a Principal Engineer (PE) within Identity & Access Management (IAM), you will champion and influence long-term vision for identity security in an AI-enabled enterprise. This role is focused on lifting Thrivent’s IAM capabilities by providing technical leadership for Thrivent's Identity and Access Management (IAM) strategy, enabling teams to deliver secure, scalable, observable, and low-friction identity capabilities across the enterprise. The leader will strengthen IAM maturity through enterprise standards, reusable patterns, and modern identity services that can be consistently adopted across portfolios. Success in this role will be measured by the organization’s ability to delivery identity-enabled capabilities more safely and consistently. As the organization's senior IAM technical authority, this role will shape the future of digital trust by addressing emerging capabilities such as Agentic AI, Generative AI, machine identities, autonomous systems, and digital workforce technologies. The role drives the evolution of authentication, authorization, governance, and identity-centric security, ensuring teams can securely consume IAM capabilities through scalable, composable, and product-oriented services rather than one-off implementations. In addition, this leader is responsible for building and maturing the IAM organization's governance, detection, monitoring, and operational oversight capabilities, enabling proactive management of identity risk, policy compliance, privileged access activities, and emerging identity-based threats across the enterprise. Through the development of sustainable platforms, processes, and engineering practices, the role strengthens the IAM team's ability to govern, monitor, detect, and respond at scale while advancing the organization's overall security posture. You will operate at the intersection of cybersecurity, AI, enterprise architecture, and product engineering, translating rapidly evolving technology trends into secure, scalable, and resilient identity capabilities so that teams can adopt, operate, and stay up to date with consistent, versioned offerings. The role requires deep expertise in identity architecture, AI-enabled threat models, enterprise security design, and strategic systems thinking. You will influence technology direction across portfolios, establish enterprise standards and guardrails, mentor engineering leaders, and partner with executive stakeholders to ensure Thrivent's identity ecosystem remains secure and future-ready and aligned to product/platform outcomes. Success in this role will be measured by the organization's ability to deliver identity-enabled capabilities more safely, consistently, and efficiently across the enterprise. This includes building reusable IAM capabilities, patterns, and guardrails that enable and upskill product, engineering, and platform teams to deliver identity-related solutions with greater autonomy and confidence. Success also requires fostering strong cross-functional partnerships to rapidly design and implement secure, scalable solutions, reducing delivery friction while maintaining appropriate governance, risk management, and security outcomes. DUTIES & RESPONSIBILITIES: Strategic Responsibilities Provide deep technical leadership for enterprise threat modeling efforts focused on AI-enabled attacks, credential abuse, machine identity compromise, and emerging identity-related threats. Solve complex identity security challenges associated with agentic AI, synthetic identities, autonomous workflows, and machine-to-machine communications at enterprise scale. Champion the enterprise identity strategy to support agentic workforce and processes. Lead the technical direction for enterprise identity security by defining and advancing scalable architectures, engineering practices, and security controls for human identities, non-human identities, AI agents, APIs, workloads, and autonomous platforms, driving engineering excellence and secure adoption across teams and platforms. Design next-generation approaches to identity governance, privileged access, authentication, authorization, and continuous trust. Advance adaptive authentication and risk-based access decisions informed by behavioral analytics, AI-driven risk signals, device posture, and contextual intelligence. Drive the integration of AI-powered detection, prevention, and response capabilities into identity security ecosystem. Influence technology and security roadmaps across Engineering, Infrastructure, Cyber Defense, Digital, Data, and Enterprise Architecture teams. Agentic Identity Security Lead the technical direction for enterprise identity security by defining and advancing scalable architectures, engineering practices, and security controls for human identities, non-human identities, AI agents, APIs, workloads, and autonomous platforms, driving engineering excellence and secure adoption across teams and platforms. Define how AI agents are provisioned, governed, monitored, and decommissioned. Establish enterprise controls for agent authorization boundaries, delegated authority, and least-privilege access. Create frameworks to manage agent accountability, auditability, and policy enforcement. Machine and Non-Human Identity Governance Develop enterprise strategies for secrets management, workload identity, service accounts, API security, and machine credential lifecycle management. Reduce risks associated with identity sprawl as autonomous systems proliferate. AI-Driven Identity Operations Champion intelligent automation within IAM, leveraging AI to improve access reviews, entitlement analysis, role mining, policy recommendations, and anomaly detection. Drive innovation that reduces friction while improving security outcomes. Engineer monitoring and detection capabilities for anomalous agent behavior across AI agents, machine identities, and autonomous workflows, working directly with other teams to embed these signals into existing detection and response pipelines. Learning and Applying New Techniques Lead research initiatives focused on emerging AI threat capabilities, adversarial AI techniques, and evolving attack methodologies. Maintain deep expertise in industry frameworks such as OWASP LLM Top 10 and MITRE ATLAS. Continuously evaluate and introduce modern security technologies and approaches to address AI-era risks. Drive adoption of innovative defensive techniques across the organization to stay ahead of threat evolution. Collaborating For Success Provide deep technical expertise in identity and AI security to solve complex, high-impact problems and remove critical technical roadblocks across teams. Partner with product teams and engineering teams to build AI and identity security requirements directly into technical designs, user stories, and delivery. Act as a hands-on technical leader in system design, embedding AI and identity security into how solutions are actually built. Define and drive technical standards for detection, telemetry, and response to AI and identity threats, collaborating with IAM and cross-functional teams to build integrated, measurable, and operationally effective solutions. Build and promote engineering standards, secure-by-default patterns, and reusable reference implementations that teams can adopt directly. Mentor engineers and elevate identity and AI security capabilities through code, design reviews, and hands-on technical guidance. Influence senior leadership on AI and identity risk posture, threat evolution, and the technical investments needed to stay ahead. QUALIFICATIONS & SKILLS: Required: Bachelor's degree in Computer Science, Cybersecurity, or related technical field, or equivalent work experience. 10+ years of experience in security engineering or related field. Proven experience defining and executing enterprise security strategy. Deep knowledge of modern threats, attack techniques, and detection engineering. Experience with threat modeling, incident response, and security operations. Demonstrated ability to influence both technical and executive stakeholders. Preferred: Proven ability to evaluate protocols, practices, and patterns based on enterprise fit, risk management, operability, and adoption at scale. Advance adaptive authentication and risk-based access decisions informed by behavioral analytics, AI-driven risk signals, device posture, and contextual intelligence. Knowledge of Agentic AI architectures, AI agents, machine identities, non-human identities (NHI), autonomous systems, and AI-enabled workflows. Experience establishing governance, authorization, accountability, and trust models for autonomous actors. Familiarity with AI security frameworks (e.g., OWASP LLM Top 10, MITRE ATLAS). Pay Transparency Thrivent’s long-term growth depends on attracting, rewarding, and retaining people who are committed to helping others thrive with purpose. We accomplish this by offering a wide variety of market competitive compensation programs to attract, reward, and retain top talent. The applicable salary or hourly wage range for this full-time role is $161,436.00 - $218,415.00 per year, which factors in various geographic regions. The base pay actually offered will be determined by a variety of factors including, but not limited to, location, relevant experience, skills, and knowledge, business needs, market demand, and other factors Thrivent deems important. Thrivent is unique in our commitment to helping people to be wise with money and live balanced and generous lives. That extends to our benefits. The following benefits may be offered: various bonuses (including, for example, annual or long-term incentives); medical, dental, and vision insurance; health savings account; flexible spending account; 401k; pension; life and accidental death and dismemberment insurance; disability insurance; supplemental protection insurance; 20 days of Paid Time Off each year; Sick and Safe Time; 10 paid company holidays; Volunteer Time Off; paid parental leave; EAP; well-being benefits, and other employee benefits. Eligibility for receipt of these benefits is subject to the applicable plan/policy documents. Thrivent’s plans/policies are subject to change at any time at Thrivent’s discretion. Thrivent provides Equal Employment Opportunity (EEO) without regard to race, religion, color, sex, gender identity, sexual orientation, pregnancy, national origin, age, disability, marital status, citizenship status, military or veteran status, genetic information, or any other status protected by applicable local, state, or federal law. This policy applies to all employees and job applicants. Thrivent is committed to providing reasonable accommodation to individuals with disabilities. If you need a reasonable accommodation, please let us know by sending an email to human.resources@thrivent.com or call 800-847-4836 and request Human Resources. #Remote At Thrivent, we believe money is a tool, not a goal. Driven by a higher purpose at our core, we are committed to providing financial advice, investments, insurance, banking and generosity programs to help people make the most of all they’ve been given. At our heart, we are a membership-owned fraternal organization, as well as a holistic financial services organization, dedicated to serving the unique needs of our customers. We focus on their goals and priorities, guiding them toward financial choices that will help them live the life they want today—and tomorrow. For over 100 years, Thrivent has been helping people build their financial futures and live more generous lives. Today, it’s a Fortune 500 company that offers a full range of expert financial solutions, serving more than 2 million customers, as well as the communities in which they live and work. Thrivent fosters a diverse workforce to serve our diverse clientele, reflecting a wide range of backgrounds and experiences. If you’re intrigued about our work and the possibility of becoming part of it, we invite you to visit Thrivent.com to learn more. You won’t just build a career; you’ll be part of an organization focused on growing, innovating, and serving.