Jobs › Companies › Roche › Principal Enterprise Identity Engineer - RDT Identity & Access Management

About this Principal Enterprise Identity Engineer - RDT Identity & Access Management role at Roche

Roche · Onsite · South San Francisco

Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Opportunity:

As the Principal Enterprise Identity Engineer, you are the ultimate technical authority and visionary for our global Enterprise Identity Management (EIM) and Identity Governance and Administration (IGA) landscape. Moving beyond individual contribution, you will define the multi-year identity strategy, driving zero-trust initiatives across a highly complex, global ecosystem.

Operating at the highest levels of our technical ladder, you will bridge the gap between executive business strategy and deep technical execution. You will architect resilient, massively scalable identity frameworks, mentor senior engineering talent, and lead cross-functional transformations that protect our most critical global assets while enabling frictionless business operations.

Job Responsibilities

  • Lead the multi-year roadmap and end-to-end technical strategy for enterprise identity, aligning IGA architectures with global security policies and zero-trust frameworks.

  • Establish and enforce enterprise-wide architecture patterns, engineering standards, and reusable frameworks across identity, cloud, and infrastructure domains.

  • Architect and oversee the deployment of next-generation, SailPoint-based EIM solutions that operate flawlessly at a massive, distributed scale.

  • Translate complex security paradigms and regulatory requirements into actionable, board-level technical strategies.

  • Pioneer the adoption of emerging identity technologies, including decentralized identity, advanced ML-driven access analytics, and complex microservice/API integrations.

  • Act as the technical cornerstone for the identity organization, mentoring senior engineers and leading Tier 4 escalation and root-cause analysis for catastrophic or highly complex systemic issues.

Who you are:

Qualifications and Core Expertise

  • Minimum of 8-10 years of hands-on engineering experience in Cybersecurity and Identity Management, with at least 5 years operating at an enterprise architecture or principal level.

  • 5+ years of experience steering identity strategies in highly regulated, multinational enterprise environments (Healthcare, Finance, or similar industries highly preferred).

  • Deep-tier technical expertise in SailPoint (IdentityNow/IdentityIQ), encompassing enterprise-scale design, custom development, performance tuning, and global deployment.

  • Expert-level proficiency in Java and Python for developing highly complex connectors, custom rules, and automated workflows.

  • Proven track record of architecting integration solutions across complex multi-cloud environments (AWS, Azure, GCP) and profound familiarity with CI/CD pipelines, DevOps methodologies, and microservices.

  • Exceptional executive presence with the ability to communicate deeply technical concepts to non-technical  stakeholders and lead distributed global engineering teams autonomously.

  • The ability to troubleshoot complex identity issues across multiple technology layers—from ISC configuration and APIs through connectors, applications, directories, and downstream provisioning systems.

  • Mentor engineers and solution architects, conduct architecture and design reviews, and help build a strong global Enterprise Identity community.

Education & Certifications

  • Degree: Bachelor’s or Advanced degree (Master’s preferred) in Computer Science, Cyber Security, Information Technology, or a related field.

  • Certifications: CISSP, CISM, or CIAM is strongly preferred for this leadership level.

  • Technical Certifications: Advanced certifications in AWS/Azure/GCP Architecture or SailPoint highly desirable.

Relocation benefits are not available for this job posting.

Must work onsite in South San Francisco

The expected salary range for this position based on the primary location of South San Francisco, CA is between $114,900- $263,500.  Actual pay will be determined based on experience, qualifications, geographic location, and other job-related factors permitted by law.  A discretionary annual bonus may be available based on individual and Company performance.  This position also qualifies for the benefits detailed at the link provided below. Benefits


 

#RDT2026

Genentech is an equal opportunity employer. It is our policy and practice to employ, promote, and otherwise treat any and all employees and applicants on the basis of merit, qualifications, and competence. The company's policy prohibits unlawful discrimination, including but not limited to, discrimination on the basis of Protected Veteran status, individuals with disabilities status, and consistent with all federal, state, or local laws.

If you have a disability and need an accommodation in relation to the online application process, please contact us by completing this form Accommodations for Applicants.

Ready to apply to Roche?
Apply to Roche

About Roche

We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow. We are proud of who we are, what we do, and how we do it. We are many, working as one across functions, across companies, and across the world. We are Roche.

See all jobs at Roche →

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Roche

See all jobs at Roche →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free