Back to jobs

SR. STAFF IAM ENGINEER

Jobgether
Full-timesenior

Job description

Accountabilities: • Own the target-state identity architecture across workforce, non-employee, external, non-human, and AI-agent identities, establishing standards, reference architectures, and architecture decision records that create consistency across projects. • Lead the end-to-end customer identity architecture, including tenant and organization models, MFA, phishing-resistant authentication, machine-to-machine authentication, and external and partner identity use cases. • Define clear separation between customer/patient identity and workforce identity, while designing the interfaces and federation models required between them. • Establish the architecture and migration patterns required to consolidate application authentication onto a unified workforce identity provider. • Design SSO, SCIM provisioning, automated deprovisioning, and lifecycle-management patterns for applications handling sensitive information, ensuring audit evidence is generated through the architecture itself. • Define federation and directory strategies across Okta, Entra ID, AWS, and GCP, including repeatable approaches for subsidiaries, acquisitions, and other organizational changes. • Build and evolve Identity Security Posture Management capabilities, extending an existing identity posture and remediation platform while defining meaningful metrics for identity risk and improvement. • Partner with Security Operations and Security Architecture to integrate identity threat detection and response into the existing SIEM and broader security ecosystem. • Design access controls aligned with HIPAA, HITRUST, and SOC 2 requirements while minimizing manual operational effort and maintaining current architecture documentation and control mappings. • Act as the architectural bridge between identity-risk discovery and engineering remediation, ensuring findings have clear, scalable paths to resolution. • Establish and communicate architectural direction through reference implementations, technical standards, and written decision records that engineering teams can adopt without direct reporting authority. • Drive measurable outcomes, including adoption of the target-state architecture, customer identity maturity, workforce identity consolidation, identity posture improvements, and audit readiness. Requirements • 8+ years of experience in identity and access management, security engineering, platform architecture, or a closely related discipline, including at least 3 years at staff, principal, architect, or equivalent seniority. • Deep hands-on customer identity and access management experience, ideally including end-to-end CIAM architecture and delivery using Auth0 or a comparable platform. • Strong expertise with SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, and FIDO2, with the ability to apply these protocols to enterprise authentication and federation architectures. • Proven experience designing enterprise workforce identity architectures using Okta or an equivalent identity provider, including migrations away from legacy or fragmented authentication systems. • Demonstrated ability to establish architectural direction, influence engineering teams, and drive adoption without relying on formal organizational authority. • Strong written communication skills, including experience producing architecture decision records, reference designs, technical standards, and other durable documentation. • A builder mindset, with the ability and willingness to implement identity solutions rather than operating solely at a conceptual or advisory level. • Experience working effectively in ambiguous environments where systems and platforms are already in flight and require architectural consolidation and completion. • Experience with regulated or security-sensitive environments is highly valuable, particularly HIPAA, PHI safeguards, HITRUST, SOC 2, or SOX access controls. • Strong identity governance knowledge, including joiner-mover-leaver processes, RBAC, access certifications, segregation of duties, and non-employee lifecycle management. Experience with SailPoint ISC, NERM, or comparable IGA platforms is a plus. • Experience with cloud PAM, just-in-time access, and zero-standing-privilege models, particularly Britive or similar technologies. • Knowledge of cloud-native identity architectures across AWS, GCP, and Azure, including migrations away from cloud-provider user pools or social and directory-based authentication. • Experience building Identity Security Posture Management or identity threat-detection capabilities, including integration of identity telemetry with SIEM platforms. • Familiarity with non-human identity, service-account governance, secrets management, and emerging AI-agent identity models. • Experience using infrastructure as code for identity, particularly Terraform. • Relevant professional certifications such as CISSP, CISSP-ISSAP, CISM, TOGAF, SABSA, Okta certifications, Auth0 or SailPoint certifications, or professional-level cloud architecture certifications are advantageous. • Experience in digital health, telehealth, or another regulated, high-growth environment is preferred. • Ability to work autonomously, communicate clearly with both technical and executive stakeholders, and build trust through sound technical judgment and well-documented decisions. Benefits • Medical, dental, and vision insurance plans. • Flexible Spending Accounts and Health Savings Accounts. • Flexible paid time off. • 401(k) retirement plan with company matching. • Life insurance. • Pet insurance. • A relatively flat organizational structure that encourages autonomy, ownership, and direct contribution. • An environment where employees are encouraged to bring forward ideas, influence decisions, and make meaningful improvements. • A culture centered on autonomy, competence, and belonging. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1