Point your AI agent at freehire and let it find you a job.

Get the CLI →

Interscripts

NewBe an early applicant

Identity & Access Management (IAM) Engineer

Posted 2 views
Discussion

Summary

IAM Engineer owning enterprise identity infrastructure in a healthcare environment: administering hybrid Active Directory and Microsoft Entra ID, automating joiner/mover/leaver provisioning, configuring SSO (SAML/OIDC) and MFA, managing privileged access, and producing HIPAA/SOC 2 audit evidence. Explicitly excludes Epic/EHR security work, which belongs to a separate clinical team.

Identity & Access Management (IAM) Engineer

Infrastructure & Directory Services | Healthcare Environment | Full-Time

Position Summary

We are seeking an IAM Engineer to own identity infrastructure and access lifecycle operations across the enterprise. This role is focused on directory services, authentication, and identity governance at the platform level — Active Directory, Microsoft Entra ID, SSO, MFA, and automated provisioning. EHR application security (Epic templates, security classes, user profiles) is handled by a separate clinical applications team; this role supports that team upstream by ensuring accurate, timely identity data and account lifecycle events but does not perform EHR provisioning.

Key Responsibilities

Administer on-prem Active Directory and Microsoft Entra ID: user and group lifecycle, OU structure, GPOs, hybrid sync (Entra Connect), and conditional access policies.

Execute and automate joiner/mover/leaver processes driven by the HR system of record, ensuring same-day deprovisioning of departed workforce members across AD, M365, VPN, and downstream systems.

Configure and maintain SSO integrations (SAML 2.0, OIDC) for enterprise and third-party applications; onboard new applications to the identity platform.

Deploy and support multifactor authentication and passwordless initiatives across employed staff, credentialed providers, contractors, and students.

Support badge-tap / fast user switching for clinical workstations (e.g., Imprivata OneSign) in coordination with desktop engineering.

Maintain role-based access models at the directory and group level; remediate access creep and orphaned or stale accounts.

Run periodic access certification campaigns; produce evidence for HIPAA, HITRUST, SOC 2, and internal audit requests.

Administer privileged access management for admin and service accounts, including vaulting, rotation, and session monitoring.

Manage non-employee identity: vendors, travelers, locum tenens providers, students, and affiliate users outside the HR feed.

Monitor and investigate identity-related security events; support incident response and inappropriate-access investigations with Security and Privacy/Compliance.

Document standards, runbooks, and workflows; contribute to the IAM roadmap and automation backlog.



Requirements

3–5+ years in identity and access management or systems administration with a heavy identity focus.

Deep hands-on expertise with Active Directory and Entra ID in a hybrid environment.

Working knowledge of SAML, OIDC/OAuth 2.0, SCIM, LDAP, and Kerberos.

Experience deploying MFA and conditional access at enterprise scale.

PowerShell scripting for AD/Entra automation and reporting.

Experience supporting audits and access reviews in a regulated environment.

Understanding of least-privilege and HIPAA “minimum necessary” principles.

Preferred Qualifications

Experience in a hospital or health system IT environment.

IGA platform experience (SailPoint, Saviynt, Okta Identity Governance, or similar).

PAM tooling (CyberArk, Delinea).

Imprivata OneSign or comparable clinical SSO.

HR-to-identity integration experience (Workday, UKG, or Oracle HCM feeds).

Certifications: SC-300 (Microsoft Identity and Access Administrator), Security+, CISSP, or CIDPRO.

What This Role Is Not

This position does not include Epic or other EHR application security build. Candidates will not manage Epic security classes, templates, or user records — that function is owned by the clinical applications team.

Work Environment

Hybrid/on-site per organizational policy; participation in an on-call rotation for identity-impacting incidents (account lockouts affecting clinical operations, termination escalations).

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available