Genentech
Genentech·Today

Principal enterprise identity engineer - rdt identity & access management

Apply now

Location

onsite, South San Francisco, CA, United States

Salary

$115k – $264k/yr

Commitment

Full Time

Level

Lead / Manager

Required skills

Identity and Access ManagementSailPointCybersecurityEnterprise ArchitectureJavaPythonCloud ArchitectureZero-trust frameworksCI/CDDevOpsMicroservicesAPI integrationIdentity Governance and AdministrationStrategic planningLeadershipTechnical mentoring

Job Description

The Position

Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Opportunity:

As the Principal Enterprise Identity Engineer, you are the ultimate technical authority and visionary for our global Enterprise Identity Management (EIM) and Identity Governance and Administration (IGA) landscape. Moving beyond individual contribution, you will define the multi-year identity strategy, driving zero-trust initiatives across a highly complex, global ecosystem.

Operating at the highest levels of our technical ladder, you will bridge the gap between executive business strategy and deep technical execution. You will architect resilient, massively scalable identity frameworks, mentor senior engineering talent, and lead cross-functional transformations that protect our most critical global assets while enabling frictionless business operations.

Job Responsibilities

  • Lead the multi-year roadmap and end-to-end technical strategy for enterprise identity, aligning IGA architectures with global security policies and zero-trust frameworks.
  • Establish and enforce enterprise-wide architecture patterns, engineering standards, and reusable frameworks across identity, cloud, and infrastructure domains.
  • Architect and oversee the deployment of next-generation, SailPoint-based EIM solutions that operate flawlessly at a massive, distributed scale.
  • Translate complex security paradigms and regulatory requirements into actionable, board-level technical strategies.
  • Pioneer the adoption of emerging identity technologies, including decentralized identity, advanced ML-driven access analytics, and complex microservice/API integrations.
  • Act as the technical cornerstone for the identity organization, mentoring senior engineers and leading Tier 4 escalation and root-cause analysis for catastrophic or highly complex systemic issues.

Who you are:

Qualifications and Core Expertise

  • Minimum of 8-10 years of hands-on engineering experience in Cybersecurity and Identity Management, with at least 5 years operating at an enterprise architecture or principal level.
  • 5+ years of experience steering identity strategies in highly regulated, multinational enterprise environments (Healthcare, Finance, or similar industries highly preferred).
  • Deep-tier technical expertise in SailPoint (IdentityNow/IdentityIQ), encompassing enterprise-scale design, custom development, performance tuning, and global deployment.
  • Expert-level proficiency in Java and Python for developing highly complex connectors, custom rules, and automated workflows.
  • Proven track record of architecting integration solutions across complex multi-cloud environments (AWS, Azure, GCP) and profound familiarity with CI/CD pipelines, DevOps methodologies, and microservices.
  • Exceptional executive presence with the ability to communicate deeply technical concepts to non-technical stakeholders and lead distributed global engineering teams autonomously.
  • The ability to troubleshoot complex identity issues across multiple technology layers—from ISC configuration and APIs through connectors, applications, directories, and downstream provisioning systems.
  • Mentor engineers and solution architects, conduct architecture and design reviews, and help build a strong global Enterprise Identity community.

Education & Certifications

  • Degree: Bachelor’s or Advanced degree (Master’s preferred) in Computer Science, Cyber Security, Information Technology, or a related field.
  • Certifications: CISSP, CISM, or CIAM is strongly preferred for this leadership level.
  • Technical Certifications: Advanced certifications in AWS/Azure/GCP Architecture or SailPoint highly desirable.

Relocation benefits are not available for this job posting.

Must work onsite in South San Francisco

The expected salary range for this position based on the primary location of South San Francisco, CA is between $114,900- $263,500. Actual pay will be determined based on experience, qualifications, geographic location, and other job-related factors permitted by law. A discretionary annual bonus may be available based on individual and Company performance. This position also qualifies for the benefits detailed at the link provided below. Benefits

#RDT2026

Genentech is an equal opportunity employer. It is our policy and practice to employ, promote, and otherwise treat any and all employees and applicants on the basis of merit, qualifications, and competence. The company's policy prohibits unlawful discrimination, including but not limited to, discrimination on the basis of Protected Veteran status, individuals with disabilities status, and consistent with all federal, state, or local laws.

If you have a disability and need an accommodation in relation to the online application process, please contact us by completing this form Accommodations for Applicants.

Ready to join the team?

Apply now