Principal Software Engineer - Identity & Access Management

SAPStanford, CA
$198,200 - $420,000Hybrid

About The Position

SAP Business Network is seeking a Principal Software Engineer to serve as a senior technical leader for the identity, authentication, and authorization engineering domain on the US Navy Business Network (PPS) program. This is a high-priority and strategic government engagement for SAP. In this role, you will own the concept, design, and delivery of complex product features within SAP Business Network across the identity and access management domain, setting the technical direction for the team and ensuring that engineering outcomes meet both SAP's quality standards and the exacting demands of a mission-critical government customer. You will be recognized as a subject matter expert in enterprise identity and access management (IAM) and application security, providing definitive technical guidance and driving innovation across the program. SAP Business Network connects buyers and suppliers globally, enabling seamless procurement, invoicing, and supply chain collaboration at enterprise scale. The US Navy Business Network (PPS) program extends this platform to one of the world's most complex procurement environments, requiring deep technical expertise, rigorous security compliance, and the ability to deliver reliable software in a regulated government context.

Requirements

  • U.S. Citizenship: Must be a U.S. Citizen due to the requirements associated with supporting U.S. public sector customers and government environments.
  • 10+ years of professional software development experience with a proven track record of leading complex, enterprise-scale product delivery.
  • Expert-level proficiency in Java (and OOD/SQL) in a cloud-native production environment; additional languages (JavaScript/TypeScript, Python, or equivalent languages) are a plus.
  • Deep, hands-on expertise in authentication, authorization and security, including enterprise SSO and identity federation, and standards such as SAML 2.0, OAuth 2.0, and OpenID Connect.
  • Deep knowledge of distributed systems architecture, microservices design, RESTful APIs, built on a modern Java cloud-native stack (Spring Boot, Kafka, Kubernetes), and cloud platforms such as SAP BTP, AWS, Azure, or GCP.
  • Strong command of secure engineering practices: token/session management, secrets handling, vulnerability management, and threat modeling for identity systems.
  • Demonstrated ability to lead technical design, drive code reviews, define deliverables, and ensure milestones are met within approved scope.
  • Established track record as a recognized subject matter expert — internally and/or externally — in software engineering, identity or enterprise security.
  • Proven ability to mentor senior and junior engineers.
  • Strong communication skills: able to formulate clear technical plans, communicate with constructive feedback, and represent SAP credibly to customers and partners
  • Comfortable with both deep technical contribution and cross-functional stakeholder management
  • Bachelor's or Master's degree in Computer Science, Software Engineering, or a related discipline (or equivalent practical experience)

Nice To Haves

  • Hands-on experience with SAP Identity Authentication Service (IAS) and SAP Authorization Management Service (AMS).
  • Experience with the SAP BTP security model, XSUAA, and role/authorization management.
  • Experience integrating third-party / customer identity providers (Bring Your Own IdP) and enterprise SSO scenarios at scale.
  • Hands-on product development experience with SAP Business Network, SAP Ariba, or related procurement platforms.
  • Prior experience delivering software for government, defense, or other regulated industry customers.
  • Familiarity with SAP BTP services, CAPM framework (CAP/CDS), SAP Integration Suite, and event-driven architecture.
  • Experience acting as a Scrum Master or technical servant-leader within an agile team.

Responsibilities

  • Own the technical design and end-to-end delivery of high-complexity features across SAP Business Network’s identity and access management domain – authentication, single sign-on, identity federation, authorization, session and user lifecycle management - ensuring alignment with SAP Business Network platform standards and government security requirements
  • Mentor and upskill senior developers (T3) on the team, establishing a culture of engineering excellence aligned with SAP's agile software engineering practices
  • Design and evolve identity and access management capabilities – enterprise SSO, identity federation, and standards-based flows (SAML 2.0, OAuth 2.0, OpenID Connect) and their integration with SAP Identity Authentication Service (IAS) and SAP Authorization Management Service (AMS)
  • Act as the primary technical escalation point for the engineering team; provide definitive interpretation of complex technical situations
  • Provide regular project status, milestone tracking, and technical updates to program leadership and key decision-makers
  • Champion continuous improvement of development methods, tooling, and quality assurance practices within the Business Network engineering organization
  • Manages projects of high volume or high risk/complexity, providing regular project status and updates to stakeholders
  • Builds strategic partnerships with key decision makers in customer and partner organizations

Benefits

  • Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
  • SAP North America Benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service