Principal Product Security Engineer
Blackhawk Network Pleasanton, California, United States · $190K–$256K/yr
Financial Services · 1,001-5,000 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Principal Product Security Engineer will serve as the technical strategist and architect driving security and identity strategy across the organization's entire technical ecosystem. They will lead the vision for the IAM program while managing data loss prevention, remote access, and secure enterprise browsing initiatives.
What they look for
Requirements
Candidates must have a bachelor's degree and over 12 years of experience in information security or identity and access management. Expert-level knowledge of identity protocols, compliance frameworks, and enterprise directory services is required.
Benefits
Full description
About Blackhawk Network
Today, through BHN’s single global platform, businesses of all kinds can tap into the world’s largest network of branded payment solutions. BHN helps businesses grow revenue, increase loyalty, motivate and reward their teams, disburse funds and engage consumers. Branded payment solutions include the issuance and distribution of gift cards, egifts, corporate payouts and rewards, along with the technology to deliver these products in seamless, integrated ways. BHN’s network spans the globe with more than 400,000 consumer touchpoints. Learn more at BHN.com.
Hybrid flexibility: At Blackhawk Network, you’ll enjoy the best of both worlds—focused remote work plus in-person collaboration on Tuesdays and Wednesdays, our regular in-office days at our Pleasanton headquarters. This rhythm gives you the tools, connection, and autonomy you need to make a real impact.
Overview
As a Principal Security Engineer, you'll serve as the technical strategist and architect driving security and identity strategy across the organization's entire technical ecosystem—Network, Endpoint, Azure/AD Infrastructure, and Identity (Okta). With a primary focus on identity and access management, you'll lead the vision and technical direction of our IAM program while extending your influence across the broader corporate security landscape, including data loss prevention, remote access, and secure enterprise browsing. You'll be the trusted right-hand technical leader who partners closely with security and infrastructure leadership to establish foundational practices, mature our security posture, and ensure our defenses keep pace with an evolving threat landscape. Your work will directly impact the security, compliance, and resilience of the entire organization.
YOU'D LOVE THIS JOB IF• you're passionate about establishing security and IAM best practices from the ground up and love the challenge of driving technical strategy across multiple domains—identity, network, endpoint, and cloud infrastructure• you thrive on being the technical visionary and trusted advisor who doesn't just solve today's security challenges, but architects the principles, strategies, and roadmaps that mature the organization's entire security posture• you find deep satisfaction in influencing and elevating engineering teams across disciplines, knowing that your technical guidance shapes how the entire organization approaches identity, access, and security• you excel at translating sophisticated security and identity concepts into strategic roadmaps that align with compliance requirements (PCI DSS, SOC2, NYDFS) and get stakeholders excited about security investments
Responsibilities
- Serves as the principal technical strategist and architect driving security and identity strategy across Network, Endpoint, Azure/AD Infrastructure, and Okta, partnering closely with security and infrastructure leadership
- Leads the overall strategy, direction, and technical vision of the organization's identity and access management program, establishing IAM principles and best practices across identity lifecycle management, identity governance & administration (IGA), privileged access management (PAM), and access request/entitlement processes
- Designs & implements comprehensive identity governance solutions to consolidate fragmented identity systems (multiple AD domains, Okta tenants) into a unified, compliant architecture
- Drives the organization's remote access strategy, architecting secure connectivity solutions (Prisma Access / SASE) including SSL/TLS decryption for traffic inspection and threat prevention
- Establishes and manages data loss prevention (DLP) strategy and controls to protect sensitive data across the enterprise
- Leads adoption and integration of secure enterprise browser technology (Prisma Browser) to protect access to corporate applications and data
- Provides technical vision in the deployment of authentication, authorization, provisioning, network security, and endpoint security technologies across heterogeneous environments
- Partners with Compliance, Security, and IT Operations teams to ensure solutions meet regulatory requirements and security objectives
- Evaluates emerging security and IAM technologies (zero trust, passwordless authentication, identity threat detection, SASE) to keep the organization at the forefront of access and data security
- Mentors and upskills engineering teams across disciplines, building organizational competency in security and identity best practices
Qualifications
- BA + 12+ years experience in information security, identity and access management, or equivalent relevant experience
- Technical master in IAM principles and methodologies including identity lifecycle management, role-based access control (RBAC), identity governance & administration (IGA), privileged access management (PAM), and access certification
- Expert-level understanding of identity protocols and standards such as SAML, OAuth, OIDC, SCIM, LDAP, and Kerberos
- Strong experience across corporate security domains including data loss prevention (DLP), secure remote access / SASE (Prisma Access or equivalent) with SSL/TLS decryption, and secure enterprise browser technologies (Prisma Browser or equivalent)
- Deep experience with enterprise directory services (Active Directory, Azure AD) and modern identity platforms; Okta experience highly valued
- Solid understanding of network and endpoint security concepts and how they integrate with a zero trust security model
- Proven ability to architect and implement security and IAM solutions in complex, multi-domain environments with legacy system constraints
- Strong understanding of compliance frameworks (PCI DSS, SOC2, SOX, NYDFS) and how security and IAM controls support regulatory requirements
- Experience with ITSM platforms (ServiceNow) for access request and workflow automation
- Demonstrated ability to build security programs from foundational concepts through mature operational state
- AI fluency with demonstrated experience using AI tools effectively in the context of this role
- Excellent communication skills with ability to influence senior stakeholders and drive organizational change without direct authority
We seek candidates who not only demonstrate curiosity and adaptability in emerging technologies but have also successfully implemented and utilized AI tools to enhance their work, improve processes, or deliver measurable results. Our teams embrace continuous learning and the thoughtful integration of AI to create meaningful impact – for our employees and the future of work.
Employment is contingent upon the successful completion of a background check.
Benefits
Salary Range for California Residents Only: $189,990.00 to $256,500.00
Pay is based on several factors including but not limited to education, work experience, certifications, etc. In addition to your salary, Blackhawk Network offers benefits including 401k with employer match, medical, dental, vision, 12 paid holidays in the year, 1 hour of sick pay accrual for every 30 hours worked, parental leave, life insurance, disability insurance, accident and illness insurance, health and dependent care flexible spending accounts, wellness benefits, and flexible time off for all full-time employees.
Similar roles
-
Cybersecurity Compliance Analyst
Booz Allen Hamilton Arlington, Virginia, United States
-
Azure Security Engineer
Booz Allen Hamilton Fort Meade, Maryland, United States · $87K–$198K/yr
-
Cybersecurity Engineer Team Lead
Booz Allen Hamilton North Las Vegas, Nevada, United States · $113K–$257K/yr
-
Information Systems Security Engineer
Booz Allen Hamilton Fayetteville, North Carolina, United States · $99K–$225K/yr
-
Staff Security Engineer, Threat Intelligence
Nscale San Francisco, California, United States · $190K–$225K/yr
-
Cybersecurity Engineer (Splunk)
Horizon Industries Columbus, Ohio, United States