Principal Security Engineer (IAM / Zero Trust)
$75 - $90 per hourVaco Charlotte
Vaco is partnering with a fintech organization to hire a Principal Security Engineer focused on Identity and Access Management as part of a broader shift toward modern, Zero Trust architecture. This is a high-impact, hands-on role centered on designing and building scalable identity systems that support a cloud-native, distributed environment.
This role goes beyond traditional IAM. The focus is on evolving identity into a dynamic, risk-aware control plane across both human and non-human access. The ideal candidate is a builder who can operate at the architecture level while still driving implementation, automation, and integration across complex systems.
The role is ideally based in Tempe with a hybrid schedule, but remote candidates will be considered.
What You'll Be Doing
- Define and evolve enterprise Identity strategy, architecture, and roadmap aligned to Zero Trust principles
- Design and implement modern IAM solutions across user, application, and machine identities
- Transition access models from static RBAC to risk-based and adaptive authorization frameworks
- Architect identity lifecycle management including provisioning, deprovisioning, and governance workflows
- Design authentication and authorization solutions including MFA, SSO, and passwordless approaches
- Lead efforts to secure non-human identities including service accounts, APIs, and distributed workloads
- Implement Just-in-Time (JIT) access and least privilege models to reduce standing access risk
- Integrate IAM solutions across cloud and enterprise platforms using protocols such as SAML, OAuth, OpenID Connect, and SCIM
- Partner with SOC and security teams to build detection and response capabilities for identity-based threats
- Develop automation-first solutions using scripting, APIs, and Infrastructure as Code
- Provide technical leadership and mentorship to engineering teams and influence secure development practices
- Collaborate with business and technical stakeholders to drive adoption and align identity strategy with business needs
- 8 years of experience in cybersecurity, security engineering, or related fields
- 5 years focused on Identity and Access Management
- Proven experience designing and implementing enterprise-scale IAM solutions
- Strong understanding of Zero Trust architecture and modern identity security principles
- Hands-on experience with IAM platforms such as Okta, Entra ID, Ping, or similar
- Experience with identity governance and PAM tools such as SailPoint, Saviynt, or CyberArk
- Strong understanding of identity protocols including OAuth, OpenID Connect, SAML, and SCIM
- Experience securing cloud-native environments across AWS, Azure, or GCP
- Experience with scripting and automation using tools such as Python or PowerShell
- Familiarity with microservices and API-driven architectures
- Experience in fintech or other regulated environments
- Experience with Kubernetes, service mesh, or container-based architectures
- Familiarity with Terraform or Infrastructure as Code practices
- Experience building identity threat detection and response capabilities
- Security certifications such as CISSP, CISM, or vendor-specific IAM certifications
- The current volume of automated and AI-generated applications is on the rise. If you have read this posting in full and believe this role genuinely aligns with your experience, we encourage you to apply thoughtfully.
- Applicants who include the word "Blue Steel" somewhere in their resume or cover note, or who reach out directly via LinkedIn to the recruiter who appreciates a good Zoolander reference, will help us route submissions more effectively
- Hourly rate: $75-90/hr
- 1-year W2 contract through Vaco
- Eligible for Vaco benefits including health, dental, vision, and 401(k)
Vaco by Highspring values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. EEO Notice
Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.
Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact View email address on click.appcast.io .
Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal .
By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. Privacy Notice
Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies.
- California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here .
- Virginia residents may access our state specific policies here .
- Residents of all other states may access our policies here .
- Canadian residents may access our policies in English here and in French here .
- Residents of countries governed by GDPR may access our policies here .
Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to:
- the individual's skill sets, experience and training;
- licensure and certification requirements;
- office location and other geographic considerations;
- other business and organizational needs.
With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
$218.03k - $256.5k
..., sensitive data, and the trust that underpins our position... ...and Access Management (IAM) program, housed within Security, is a cross-functional team... ...program, partnering with Engineering, IT, Platform, and business... ...identity solutions that balance zero-trust security with...SuggestedFor contractorsLocal area$184k - $230k
...Principal Engineer, Identity and Access Management At Early Warning, we... ...Paze℠, and so much more. As a trusted name in payments, we partner... ...and Access Management (IAM) team, you will play a pivotal... ...implementing, and maintaining robust security solutions to safeguard...SuggestedHourly payFor contractorsWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Overview: IAM Security Engineer (Full Stack) Location: Phoenix, AZ (Onsite | Contract Role) Job Description We are seeking an experienced IAM Security Engineer with strong expertise in Identity and Access Management (IAM), Information Security, DevOps...SuggestedContract work
- ...Systems Security Engineer Location: Phoenix, AZ Company Stage of Funding: Early-Stage Autonomous... ...integrity, encryption, key management, IAM, and secure communications Secure... ...with secure communications protocols, zero-trust networking, VPNs, TLS/mTLS, and distributed...SuggestedWork at office
$114k - $142k
...to help us make the future? We are seeking a Cyber Security Architect/Engineer II – Active Directory/IAM to join our team. In this role, you will work... ...the future of aviation and energy transition. As a trusted partner, we provide actionable solutions and innovation...SuggestedPermanent employmentTemporary workWork experience placementRemote workFlexible hours- ...If you like high profile and challenging cloud system security work supporting the readiness of America’s Navy ships... ...forces – Serco has a great opportunity for you! This Principal Information Security Systems Engineer (ISSE) will be working with a dynamic team supporting...Full timeContract workPart timeFor contractorsLocal areaRemote workFlexible hours
$100k - $172.5k
...more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job... ...Description: We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week$100k
...SEIII M365 - MS Purview, Intune & Security Engineer Salary: $100K+ Location: Must reside in AZ, NM, NV, TX, CO, UT, OR Position... ...Conditional Access and endpoint security controls to enforce Zero Trust access models. Identity and Access Management Configure...$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across... ...validate secure solutions. You'll serve as a trusted security advisor, guiding architecture... ...issues within components like IAM and S3. Performing an in-depth security...Work at officeRemote work- ...The Network Security Engineer is responsible for the day-to-day operations, maintenance, and continuous improvement of perimeter security... ...cloud environments. This role focuses on firewall, proxy, and zero-trust solutions, ensuring secure, reliable connectivity while...Permanent employmentTemporary workRemote workFlexible hours
$152.41k - $179.3k
...expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security... ...You have secured endpoint communication using device trust and zero trust network access products (like Cloudflare, Prisma...Local area$105.1k - $164.13k
...foundation in network architecture, design, and security - individuals who are ready to step up from traditional network engineering roles to take ownership of strategic,... ...perspective. Supporting the integration of Zero Trust, Software-Defined Networking (SDN), and...Permanent employmentFull timeContract workPart timeLocal areaRemote work- ...Network Security Engineer LOCATIONS BY PREFERENCE: 1. Most Preferred – Pittsburgh, PA, 15222 2. Second Preferred – Cleveland, OH, 4413... ...knowledge of network protocols (TCP/IP, UDP, security concepts (zero trust, segmentation), and cloud networking (VPCs, VNETs. Expertise...Contract workWork experience placementFlexible hours
$174.88k - $233.17k
...people, data and applications – quickly, securely, and effortlessly. Together, we are... ...the people up – committed to teamwork, trust and transparency. People power progress.... ...Senior Director of Security Architecture & Engineering leads cybersecurity architecture and engineering...Temporary workRemote work$154k - $193k
...Paze, and so much more. As a trusted name in payments, we partner... ...technical ServiceNow principal engineer involved in setting the standards... ...including infrastructure teams, security teams, architecture,... ...federation, SSO, OAuth, SAML, and zero-trust integration patterns....Hourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Principal Application Security Engineer Duration: 12+ Months Location: Charlotte, NC / Dallas, TX / Minneapolis, MN / Phoenix, AZ – Hybrid Role (3 days/week onsite) In this role, you will: · Drive strategic efforts and lead transformative projects in the application...Work experience placement3 days per week
$172k - $215k
...Paze℠, and so much more. As a trusted name in payments, we partner... ...employment Visa sponsorship. Engineering at Early Warning (EWS) is a... ...storage, observability, and security leveraging Terraform, Ansible... ...automating AWS services (EC2, IAM, ELB, Route53, S3, Lambda,...Hourly payWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Security Architect - Identity and Access Management... ...to life. As a Principal Security Architect... ...architecture for IAM products. A... ...on role, act as a trusted partner between IAM and business (Engineering, Security, Compliance... ...Identity Management, and Zero Trust. ~...Remote work
$115k - $135k
...and continuous improvement of security architecture across AWS and... ...g., GuardDuty, Security Hub, IAM, KMS, CloudTrail) and Azure security... ...principles Partner with engineering and development teams to... ...posture. Help drive a culture of zero trust security across engineering,...Full timeLocal areaRemote work$104k - $156k
...Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate... ...Administrator Associate (SC-300). ~ Knowledge of Zero Trustprinciplesand compliance standards (e.g., GDPR, HIPAA)....Remote work$144.2k - $288.4k
...Position Summary Development, Standards & Secure Design Lead development and... ...Agentic Security Architecture Serve as the principal SME for securing AI-enabled applications... ..., Leadership & Influence Influence engineering and product teams to integrate secure engineering...Hourly payFull timeTemporary workLocal area- ...Job Title: Architect III - Security Architect Location: Block 23 What you'll do... ...Strong understanding of security domains (IAM, Network, Application, Cloud, Data, AI) with... ...governance and security practices, and Zero Trust principles for securing cloud,...
- ...Overview: IAM Security Engineer (Python/Java/React, Cloud) 7-9 yrs, Only Local Description: • In depth knowledge of IAM with Information Security, Devops and Full stack5 or more years in a role primarily focused on Information Security• Deep understanding of...Local area
$107.5k - $204.5k
....S. government issued security clearance is required... ...experience and renowned engineering expertise to meet the... ...from the frigid, sub-zero vacuum of space to the... ...Power Team is seeking a Principal Digital Design... ...RTX we value: Safety, Trust, Respect, Accountability...Temporary workWork experience placementInterim roleWork at officeRemote workRelocationFlexible hours- ...Senior Security Operations Engineer II Scottsdale, Arizona, United States Join Axon and be a Force... ...user identity and access management (IAM) initiatives. Your work will have a direct... ...certificates, secrets, keys, and trust stores, including issuance, renewal, rotation...Work at officeRemote work
- ...using dynamic routing protocols, traffic engineering, and high-availability frameworks.... ...cloud connectivity. Develop scalable, secure network architectures aligned with business... ...Knowledge of Zscaler products (ZIA, ZPA, Zero Trust) is a significant plus. Advanced degrees...Temporary workFlexible hours
$186.07k - $218.9k
...expected and fully supported. Security is a primary competency at... ...employees can enjoy a safe, trusted experience. As Coinbase scales... ...Partner with software engineering teams to advise on code and architecture... ...novel innovations such as zero-knowledge proofs and bleeding...Contract workLocal area- ...Overview of Job Function: As a Principal Engineer, you will be the senior-most technical... ...technical risks, scalability constraints, and security vulnerabilities; drive their... ...understanding of OWASP Top 10, OAuth 2.0/JWT, zero-trust principles, and enterprise identity...Local areaShift work
$105.3k - $175.21k
.... Who we Are: Intel's Information Security organization enables Intel to provide secure... ...is seeking a Identity Security - PKI Engineer. The candidate chosen for this role will... ...Phoenix Business group: IT is the trusted technology partner for Intel's business,...InternshipLocal areaImmediate startShift work- ...CTG is seeking a Mainframe Security Engineer to support and secure enterprise IBM z/OS environments for our client. This role is responsible... ...on expertise with RACF, ACF2, or CA Top Secret Knowledge of IAM, RBAC, and privileged access controls Experience with mainframe...Permanent employmentLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security Engineer (IAM / Zero Trust). Be the first to apply!
- director data engineering Phoenix, AZ
- senior civil engineer project manager Phoenix, AZ
- principal cloud engineer Phoenix, AZ
- director systems engineering Phoenix, AZ
- engineering director Phoenix, AZ
- principal infrastructure engineer Phoenix, AZ
- principal network engineer Phoenix, AZ
- chief engineer Phoenix, AZ
- civil engineer project manager Phoenix, AZ
- data center chief engineer Phoenix, AZ


