Skip to content
← Back to job listings

Principal Software Engineer (Privileged Access Management)

Saviynt · Vancouver, Canada

Quick applyfull-time10 days ago

About The Role

Join our team as a Principal Software Engineer focused on Privileged Access Management (PAM). In this role, you will drive technical strategy and architecture across PAM platform components, lead the design and delivery of new services, and mentor other engineers. You will work within our AI-Driven Development Lifecycle (AiDLC) and serve as a technical expert for internal teams and customer-facing escalations. This position offers competitive pay, great benefits, flexible time off, and employee recognition.

  • Conduire la stratégie technique et l'architecture des composants de la plateforme PAM, y compris les topologies de déploiement conformes aux exigences fédérales.
  • Collaborer avec la gestion des produits et de l'ingénierie pour l'analyse des exigences, la planification de la feuille de route et la prise de décisions techniques.
  • Diriger la conception et la livraison de nouveaux services, de la phase de conception à la mise en production.
  • Workflow orchestration experience (Temporal or similar) is a plus
  • Infrastructure as Code: Terraform, Helm; GitOps (ArgoCD) a plus
  • Critical-review instincts: you don’t ship AI-generated code without reading it, testing it, and understanding it
  • Active, deliberate use of AI coding tools (Claude Code, Cursor, Copilot, or comparable) as part of your daily workflow — beyond autocomplete
  • Relational database design at scale — PostgreSQL preferred; schema-per-tenant or comparable isolation patterns a plus
  • Demonstrated experience mentoring engineers and leading technical initiatives across distributed teams
  • Polyglot capability — you can read, reason about, and contribute across multiple languages, and you can defend language-choice decisions on technical merit
  • Comfort working in a spec-driven, agent-assisted development model with mandatory verification gates; AiDLC will be our SDLC, and we expect candidates to embrace and help refine it
  • Containerization: Docker multi-stage builds, distroless/minimal runtimes
  • Strong written and verbal communication — you can write a clear design doc, a clear PR description, and a clear engineering contract for an AI agent
  • Observability: OpenTelemetry, structured logging, metrics, tracing
  • Demonstrated initiative and ability to prioritize independently in a fast-moving environment
  • Qualifications
  • Comfortable operating in a globally distributed organization (US + India)
  • Bachelor’s or Master’s degree in Computer Science, a related technical discipline, or equivalent professional experience
  • Working knowledge of modern cryptography in practice: TLS/mTLS, KMS-backed key hierarchies, envelope encryption, HSM/key vault integration
  • Solid hands-on Kubernetes experience — EKS or equivalent, Helm, manifests, operators, day-2 operations. Not “I used kubectl apply once.”
  • Excellent facilitation and consensus-building skills across engineering, product, and security stakeholders
  • Go strongly preferred as the platform’s primary language; deep proficiency in at least one systems/services language (Go, Rust, C++, Java, or similar) is required
  • 1+ year of software engineering experience as a Principal Software Engineer with a SaaS company
  • Hands-on experience building security-focused systems — Privileged Access Management, Identity Governance, Authentication, Secrets Management, or adjacent domains
  • Cloud platform proficiency on AWS or Azure; multi-cloud experience is a plus
  • CI/CD pipeline design and ownership — GitLab, GitHub Actions, Jenkins, CloudBees, or equivalent
  • Strong testing discipline: unit, integration, end-to-end, and property-based testing
  • Track record of taking systems from design through production at scale, including multi-tenant SaaS
  • Frontend literacy in TypeScript/React is a plus
  • Microservices and API design: REST, gRPC/Protobuf, and the trade-offs between them
  • Experience with event-driven architectures (message buses, async workflows) — you know when to reach for them and when not to
  • Required knowledge of FedRAMP, FIPS 140-3, and GovCloud (AWS GovCloud or Azure Government) — what they constrain, why, and how to design within them

This listing was posted by a verified recruiter at Saviynt. Report this listing