1

Privileged Access Management Engineer Jobs in California

Lead Infrastructure Engineer

Concord, CA · On-site +1

$118K - $154K/yr

Experience implementing least-privilege access models, privileged access management, segregation of ... Proven ability to mentor engineers, lead large-scale infrastructure initiatives, and influence ...

Principal Security Software Engineer, IAM

San Mateo, CA · On-site

$153K - $206K/yr

As a Principal Security Software Engineer on the Production IAM team, you will set the technical ... access management platform, production PKI and certificate lifecycle, and just-in-time privileged ...

Principal Security Software Engineer, IAM

San Mateo, CA · On-site

$153K - $206K/yr

As a Principal Security Software Engineer on the Production IAM team, you will set the technical ... access management platform, production PKI and certificate lifecycle, and just-in-time privileged ...

Principal IAM Engineer

Pleasanton, CA · On-site

$170.36 - $230/hr

Overview As a Principal IAM Engineer, you'll lead the strategic vision and technical direction of ... privileged access management, and authentication/authorization protocols with influential ...

Cybersecurity Engineer

El Segundo, CA · On-site

$125K - $140K/yr

The Cybersecurity Engineer is responsible for implementing, maintaining, and supporting ... Administer identity and access management processes, including account provisioning and privileged ...

The Cybersecurity Engineer is responsible for implementing, maintaining, and supporting ... Administer identity and access management processes, including account provisioning and privileged ...

Showing results 41-60

Privileged Access Management Engineer information

What is a privileged access management engineer?

A Privileged Access Management (PAM) Engineer is responsible for designing, implementing, and maintaining security controls to manage and protect privileged accounts within an organization. They work with PAM solutions to enforce least privilege access, monitor privileged session activity, and prevent unauthorized access to critical systems. PAM Engineers collaborate with security teams to ensure compliance with industry standards and regulatory requirements while continuously improving identity and access management processes.

What are the typical daily responsibilities of a privileged access management engineer?

As a Privileged Access Management Engineer, your daily tasks often involve managing user access permissions, maintaining and upgrading PAM solutions, and monitoring for unauthorized access attempts. You may work closely with IT security and operations teams to enforce security policies and address access-related incidents. Routine responsibilities also include auditing privileged accounts, updating documentation, and participating in compliance and risk assessments. This role requires you to be proactive and responsive, ensuring that only authorized personnel can access critical systems and sensitive data.

What are the key skills and qualifications needed to thrive as a privileged access management engineer?

A Privileged Access Management (PAM) Engineer needs a strong background in information security, identity and access management principles, and experience with enterprise PAM solutions. Familiarity with tools such as CyberArk, BeyondTrust, or Thycotic, and relevant certifications like CISSP or CompTIA Security+ are highly valued. Exceptional problem-solving skills, attention to detail, and effective communication enable success in a collaborative environment. These skills are critical for safeguarding sensitive assets, ensuring regulatory compliance, and supporting secure business operations.

What are the most commonly searched types of Privileged Access Management Engineer jobs in California?

The most popular types of Privileged Access Management Engineer jobs in California are:

What are popular job titles related to Privileged Access Management Engineer jobs in California?

For Privileged Access Management Engineer jobs in California, the most frequently searched job titles are:

What job categories do people searching Privileged Access Management Engineer jobs in California look for?

The top searched job categories for Privileged Access Management Engineer jobs in California are:

Infographic showing various Privileged Access Management Engineer job openings in California as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 74% In-person, 17% Hybrid, and 9% Remote job distribution.

Lead Infrastructure Engineer

Wells Fargo

Concord, CA • On-site, Remote

$118K - $154K/yr

Full-time

Medical, Life, Retirement, PTO

Re-posted 3 days ago


Wells Fargo rating

7.8

Company rating: 7.8 out of 10

Based on 709 frontline employees who took The Breakroom Quiz

89th of 171 rated banks


Job description

About this role:

Wells Fargo is seeking a Lead Infrastructure Engineer to drive the evolution of our AWS cloud platform by designing, building, and operating scalable, secure, and resilient cloud foundations. In this role, you will provide technical leadership across engineering teams, mentor infrastructure engineers, establish and promote cloud engineering best practices, and influence enterprise cloud strategy.

The ideal candidate will possess deep hands-on experience with AWS Landing Zones, Infrastructure as Code (Terraform), cloud governance, event-driven architectures, and modern DevOps/GitOps practices. This role requires strong technical leadership, architectural expertise, and the ability to collaborate across engineering, security, operations, and product teams to deliver innovative, enterprise-grade cloud solutions.


In this role, you will:

  • Lead the strategy, architecture, and delivery of highly complex, large-scale AWS cloud solutions, leveraging expertise across distributed systems, networking, security, data platforms, automation, DevOps, and application modernization. Drive long-term technical direction through innovation, strategic thinking, and engineering excellence
  • Translate business objectives and enterprise technology requirements into AWS-based infrastructure solutions, utilizing deep knowledge of AWS services such as Amazon EKS, ECS, EC2, Lambda, API Gateway, EventBridge, SQS, SNS, DynamoDB, RDS, VPC, and AWS Organizations, while ensuring alignment with enterprise cloud governance, security, and modernization initiatives
  • implement enterprise IAM solutions and access control strategies
  • Follow standards for federation, IAM Identity Center, role-based access controls, and privileged access management
  • Lead ongoing evolution of AWS Landing Zones and multi-account operating models
  • Lead and manage governance controls using AWS Organizations, Service Control Policies (SCPs), Control Tower, and policy-based guardrails
  • Partner closely with engineering, security, infrastructure, operations, risk, and product teams, serving as a trusted technical advisor for AWS strategy, architecture reviews, cloud governance, and enterprise transformation initiatives
  • Drive infrastructure automation and standardization through Terraform, CI/CD pipelines, and GitOps methodologies, enabling consistent, repeatable, and secure cloud deployments across the organization.


Required Qualifications:

  • 5+ years of Infrastructure Engineering, Cloud Engineering, or related experience, or equivalent demonstrated through work experience, training, military experience, or education
  • 5+ years of hands-on AWS cloud engineering experience designing, implementing, and supporting enterprise-scale cloud platforms
  • 5+ years of experience designing and managing AWS Landing Zones, multi-account strategies, and enterprise governance frameworks using AWS Organizations and Control Tower
  • 3+ years of experience with AWS foundational services, including networking, identity and access management, security, monitoring, logging, and compliance
  • 3+ years of experience partnering with Cloud Operations and Site Reliability Engineering (SRE) teams to provide L3 support, perform root cause analysis, resolve complex AWS infrastructure issues, and implement long-term reliability improvements
  • 3+ years of Terraform experience, including developing reusable modules, implementing Infrastructure as Code standards, managing remote state securely, and automating AWS infrastructure deployments at scale.


Desired Qualifications:

  • Strong expertise in AWS cloud platform architecture, including multi-account, multi-region, hybrid cloud, and multi-cloud deployment patterns
  • Broad technical expertise across networking, compute, storage, security, compliance, identity and access management, encryption, disaster recovery, and observability
  • Advanced knowledge of GitOps, Infrastructure as Code, Policy as Code, and enterprise configuration management practices
  • Deep experience with Terraform and GitHub ecosystem tools, including GitHub Actions, repositories, workflows, and CI/CD automation
  • Hands-on experience with Site Reliability Engineering (SRE) or Cloud Operation principles, including incident management, capacity planning, resiliency engineering, and performance optimization
  • Strong understanding of AWS Identity and Access Management (IAM), AWS Organizations, Service Control Policies (SCPs), AWS KMS, AWS Secrets Manager, Security Hub, GuardDuty, CloudTrail, Config, and Control Tower
  • Advanced proficiency in Python, PowerShell, and Terraform, with demonstrated ability to design reusable automation frameworks and cloud engineering platforms
  • Experience implementing least-privilege access models, privileged access management, segregation of duties, and cloud security best practices
  • Hands-on experience building event-driven automation solutions using AWS Lambda, EventBridge, SNS, SQS, Step Functions, or similar cloud-native services
  • Proven ability to mentor engineers, lead large-scale infrastructure initiatives, and influence global cross-functional engineering teams
  • AWS certifications such as AWS Certified Solutions Architect Professional, AWS Certified DevOps Engineer Professional, or AWS Advanced Networking Specialty are highly preferred.


Job Expectations:

  • Ability to travel up to 10% of the time
  • Ability to work additional hours as needed
  • This position offers a hybrid work schedule
  • This position is not eligible for visa sponsorship.

Pay Range

Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.

$119,000.00 - $224,000.00

Benefits

Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. VisitBenefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Posting End Date:

17 Aug 2026

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visitDisability Inclusion at Wells Fargo.

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements:

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.


What Wells Fargo employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Wells Fargo logo

About Wells Fargo

Sourced by ZipRecruiter

Wells Fargo & Company (NYSE: WFC) is a leading financial services company that has approximately $1.9 trillion in assets, proudly serves one in three U.S. households and more than 10% of small businesses in the U.S., and is a leading middle market banking provider in the U.S. We provide a diversified set of banking, investment and mortgage products and services, as well as consumer and commercial finance, through our four reportable operating segments: Consumer Banking and Lending, Commercial Banking, Corporate and Investment Banking, and Wealth & Investment Management. Wells Fargo ranked No. 41 on Fortune's 2022 rankings of America's largest corporations. In the communities we serve, the company focuses its social impact on building a sustainable, inclusive future for all by supporting housing affordability, small business growth, financial health and a low-carbon economy.

Industry

Finance and insurance

Company size

10,000+ Employees

Headquarters location

San Francisco, CA, US

Year founded

1852

Social media