Identity & Access Management (IAM) Engineer
Job Summary
Identity & Access Management (IAM) Engineer
Infrastructure & Directory Services Healthcare Environment Full-Time
Position Summary
We are seeking an IAM Engineer to own identity infrastructure and access lifecycle operations across the enterprise. This role is focused on directory services authentication and identity governance at the platform level Active Directory Microsoft Entra ID SSO MFA and automated provisioning. EHR application security (Epic templates security classes user profiles) is handled by a separate clinical applications team; this role supports that team upstream by ensuring accurate timely identity data and account lifecycle events but does not perform EHR provisioning.
Key Responsibilities
Administer on-prem Active Directory and Microsoft Entra ID: user and group lifecycle OU structure GPOs hybrid sync (Entra Connect) and conditional access policies.
Execute and automate joiner/mover/leaver processes driven by the HR system of record ensuring same-day deprovisioning of departed workforce members across AD M365 VPN and downstream systems.
Configure and maintain SSO integrations (SAML 2.0 OIDC) for enterprise and third-party applications; onboard new applications to the identity platform.
Deploy and support multifactor authentication and passwordless initiatives across employed staff credentialed providers contractors and students.
Support badge-tap / fast user switching for clinical workstations (e.g. Imprivata OneSign) in coordination with desktop engineering.
Maintain role-based access models at the directory and group level; remediate access creep and orphaned or stale accounts.
Run periodic access certification campaigns; produce evidence for HIPAA HITRUST SOC 2 and internal audit requests.
Administer privileged access management for admin and service accounts including vaulting rotation and session monitoring.
Manage non-employee identity: vendors travelers locum tenens providers students and affiliate users outside the HR feed.
Monitor and investigate identity-related security events; support incident response and inappropriate-access investigations with Security and Privacy/Compliance.
Document standards runbooks and workflows; contribute to the IAM roadmap and automation backlog.
35 years in identity and access management or systems administration with a heavy identity focus.
Deep hands-on expertise with Active Directory and Entra ID in a hybrid environment.
Working knowledge of SAML OIDC/OAuth 2.0 SCIM LDAP and Kerberos.
Experience deploying MFA and conditional access at enterprise scale.
PowerShell scripting for AD/Entra automation and reporting.
Experience supporting audits and access reviews in a regulated environment.
Understanding of least-privilege and HIPAA minimum necessary principles.
Preferred Qualifications
Experience in a hospital or health system IT environment.
IGA platform experience (SailPoint Saviynt Okta Identity Governance or similar).
PAM tooling (CyberArk Delinea).
Imprivata OneSign or comparable clinical SSO.
HR-to-identity integration experience (Workday UKG or Oracle HCM feeds).
Certifications: SC-300 (Microsoft Identity and Access Administrator) Security CISSP or CIDPRO.
What This Role Is Not
Work Environment
Required Skills:
35 years in identity and access management or systems administration with a heavy identity focus. Deep hands-on expertise with Active Directory and Entra ID in a hybrid environment. Working knowledge of SAML OIDC/OAuth 2.0 SCIM LDAP and Kerberos. Experience deploying MFA and conditional access at enterprise scale. PowerShell scripting for AD/Entra automation and reporting. Experience supporting audits and access reviews in a regulated environment. Understanding of least-privilege and HIPAA minimum necessary principles.
Required Education:
Bachelors degree in Computer Science Information Systems Health Informatics or a related field required.