-
Principal IAM Engineer - Department of Technology
- City and County of San Francisco (San Francisco, CA)
-
Department: DT/Cybersecurity
Job class: 9976
Salary range: [$165,334.00 - $207,974.00] annually
Hours: Full-time.
Role type: Permanent Exempt (PEX), Full Time position is excluded by the Charter from the competitive civil service examination process and shall serve at the discretion of the appointment officer.
About:
+ Application Opening: Monday, November 10, 2025
+ Application Deadline: This job will close no sooner than Monday, November 24, 2025 (11:59 PM).
Department Description:
Are you ready to make an impact in one of the most innovative cities? The Department of Technology (DT) is looking for passionate IT professionals to help shape the future of technology in San Francisco! As the centralized technology services provider for the City and County of San Francisco (CCSF), DT delivers critical infrastructure and services to over 33,000 employees—supporting public safety, municipal broadband, cybersecurity, cloud solutions, and more! With a $140M+ annual budget and a team of 300+ experts, DT is leading the charge in digital transformation. DT provides services through our core areas of IT Excellence:
+ IT Project Management Office
+ Enterprise Application Services
+ Cloud Center of Excellence
+ IT Operations and Support including the Service Desk and NOC
+ City Infrastructure including the Network, Telcom and Data Centers
+ Office of Cybersecurity including Cyber Defense, Identity Management and Disaster Recovery
+ Public Safety Systems and Municipal Broadband Fiber
+ SFGovTV Broadcasting Services
+ IT Finance and Administration Services
+ Emerging Technologies
Why Join Us? Innovative & Impactful Work At DT, you won’t just work on IT—you’ll power a city. Your expertise will directly impact the residents of San Francisco, from closing the digital divide to ensuring secure, efficient city operations.
Benefits of Working for CCSF: In addition to challenging and rewarding work, the City provides a generous suite of benefits to its employees.
+ Competitive pay, benefits, and retirement options
+ Career growth opportunities through training, internal mobility, and subsidized education
+ Diverse work environment in a diverse city
Join the team that’s shaping the future of technology in San Francisco. Apply today and be part of a dynamic, innovative, and mission-driven IT team!
We are committed to ensuring that the City's services are inclusive, efficient, equitable, and culturally competent for San Franciscans of all races, ethnic backgrounds, religions, and sexual orientations. This commitment requires comprehensive review and thorough analysis of existing practices and policies to remove barriers to real inclusion. We are also committed to ensuring that we have a safe, equitable, and inclusive workplace for individuals of all races. This includes creating opportunities for hiring, promotion, training, and development, for all employees, including but no limited to Black, Indigenous, and people of color (BIPOC).
Telecommute: The Department has a hybrid work schedule
IAM Engineer reports to the Director of IAM & Directory services and will be responsible for the development, deployment, administration, and maintenance of Oracle Identity and Access Management (IAM) security solutions and programs. The incumbent will have rich experience in Java, J2EE, cloud services, hybrid cloud access management responsibilities, and Privileged Access Management experience along with continual monitoring of the IAM service for quality levels including performance and outage issues, coordinating with System Administrators, Database Administrators, Information Security, and system owners to architect, deploy and maintain IAM tools and solutions. The position requires a detail-oriented, self-motivated, degreed professional with experience supporting Identity Access Management Systems including Oracle Access Manager and Oracle Identity Management 11gR2/12c/Identity Cloud Services.
Position Duties:
Identity & Access Management (IAM) Engineer will contribute to the overall strategy, planning, evaluation & implementation of the entire Identity/Access Management stack and supervise and help junior engineers. The individual in this role will significantly contribute to the direction and oversight into the IAM functions across the City and County, including areas such as developing centralized provisioning IAM engine to all Citywide Enterprise Applications, workflow and review certification, Audit and Compliance, Hybrid cloud management, Privileged Access Management, Authentication & Authorization. This position will require expert knowledge in Oracle Fusion Middleware, Oracle Identity & Access Management administration, Identity cloud services, WebLogic administration, custom connector development, installation and configuration, performance tuning, backup, and recovery methods in multiple computing environments and must be well versed in J2EE, Service Oriented Architecture (SOA), Web Services, LDAP, XML, and SAML. This position also requires knowledge of Oracle databases and should be able to support other areas or functions as needed.
Working Relationships:
The role reports to the Director of IAM & Directory services and will be responsible for documenting, designing and administering the IAM infrastructure. The position will provide support to security functions and develop appropriate audit controls and procedures to ensure the integrity of applications. The engineer will be working closely with the project managers, Security and Compliance personnel, application developers and other administrators in creating functional, scalable and secure applications from design and development through implementation for business clients.
Education: Possession of an Associate's degree in Computer Science or related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in computer science or a closely-related field.
AND
Experience: Five (5) years of experience in Identity and Access Management.
Substitution: Additional experience as described above may be substituted for the required degree on a year-for-year basis (up to a maximum of two (2) years). One (1) year is equivalent to thirty (30) semester units/ forty-five (45) quarter units with a minimum of 10 semester / 15 quarter units in computer science or a closely related field.
AND
Ability to pass CJIS background check
Desirable Qualifications:
+ 3 plus years of other cloud Identity product experiences from the below products
+ Access Governance Experience
+ SailPoint Experience
+ Savyant exeprience
Note: Applicants must meet the minimum qualification requirement by the final filing date unless otherwise noted.
One-year full-time employment is considered equivalent to 2000 hours (2000 hours of qualifying work experience is based on a 40hour work week). Any overtime hours that you work above forty (40) hours per week are not included in the calculation to determine full-time employment.
+ Information About the Hiring Process (https://careers.sf.gov/knowledge/process/)
+ Conviction History (https://careers.sf.gov/knowledge/conviction-history/)
+ Employee Benefits Overview (https://careers.sf.gov/benefits/)
+ Equal Employment Opportunity (https://www.sf.gov/what-equal-employment-opportunity-and-how-file-claim)
+ Disaster Service Worker (https://sfdhr.org/disaster-service-workers)
+ ADA Accommodation (https://sfdhr.org/information-about-hiring-process#applicantswithdisabilities)
+ Veterans Preference (https://sfdhr.org/recruitment-details#veteranspreference)
+ Seniority Credit i (https://sfdhr.org/recruitment-details#senioritycredit)
+ Right to Work
+ Copies of Application Documents (https://sfdhr.org/recruitment-details#copies)
+ Diversity Statement (https://sfdhr.org/recruitment-details#diversitystatement)
Applicants will receive a confirmation email from [email protected] that their online application has been received in response to every announcement for which they file. Applicants should retain this confirmation email for their records. Failure to receive this email means that the online application was not submitted or received.
Applicants may be contacted by email about this recruitment and, therefore, it is their responsibility to ensure that their registered email address is accurate and kept up-to-date. Also, applicants must ensure that email from CCSF is not blocked on their computer by a spam filter. To prevent blocking, applicants should set up their email to accept CCSF mail from the following addresses (@sfgov.org, @sfdpw.org, @sfport.com, @flysfo.com, @sfwater.org, @sfdph.org, @asianart.org, @sfmta.com, @sfpl.org, @dcyf.org, @first5sf.org, @famsf.org, @ccsf.edu, @smartalerts.info, and @smartrecruiters.com).
Exam Analyst Information: If you have any questions regarding this recruitment or application process, please contact the analyst at [email protected]
The City and County of San Francisco encourages women, minorities and persons with disabilities to apply. Applicants will be considered regardless of their sex, race, age, religion, color, national origin, ancestry, physical disability, mental disability, medical condition (associated with cancer, a history of cancer, or genetic characteristics), HIV/AIDS status, genetic information, marital status, sexual orientation, gender, gender identity, gender expression, military and veteran status, or other protected category under the law.
-
Recent Jobs
-
Principal IAM Engineer - Department of Technology
- City and County of San Francisco (San Francisco, CA)
-
Sr. Distinguished Engineer - SDUI (Remote Eligible)
- Capital One (Mclean, VA)
-
System Test Engineer (Nextest, San Jose)
- Teradyne (San Jose, CA)
-
Manager - Technical Operations Safety and Compliance
- United Airlines (Houston, TX)