Identity & Access Management (IAM) Engineer
Summary
IAM Engineer owning enterprise identity infrastructure in a healthcare environment: administering hybrid Active Directory and Microsoft Entra ID, automating joiner/mover/leaver provisioning, configuring SSO (SAML/OIDC) and MFA, managing privileged access, and producing HIPAA/SOC 2 audit evidence. Explicitly excludes Epic/EHR security work, which belongs to a separate clinical team.
Identity
& Access Management (IAM) Engineer
Infrastructure
& Directory Services | Healthcare Environment | Full-Time
Position
Summary
We are
seeking an IAM Engineer to own identity infrastructure and access lifecycle
operations across the enterprise. This role is focused on directory services,
authentication, and identity governance at the platform level — Active
Directory, Microsoft Entra ID, SSO, MFA, and automated provisioning. EHR
application security (Epic templates, security classes, user profiles) is
handled by a separate clinical applications team; this role supports that team
upstream by ensuring accurate, timely identity data and account lifecycle
events but does not perform EHR provisioning.
Key
Responsibilities
• Administer on-prem Active Directory and
Microsoft Entra ID: user and group lifecycle, OU structure, GPOs, hybrid sync
(Entra Connect), and conditional access policies.
• Execute and automate joiner/mover/leaver
processes driven by the HR system of record, ensuring same-day deprovisioning
of departed workforce members across AD, M365, VPN, and downstream systems.
• Configure and maintain SSO integrations (SAML
2.0, OIDC) for enterprise and third-party applications; onboard new
applications to the identity platform.
• Deploy and support multifactor authentication
and passwordless initiatives across employed staff, credentialed providers,
contractors, and students.
• Support badge-tap / fast user switching for
clinical workstations (e.g., Imprivata OneSign) in coordination with desktop
engineering.
• Maintain role-based access models at the
directory and group level; remediate access creep and orphaned or stale
accounts.
• Run periodic access certification campaigns;
produce evidence for HIPAA, HITRUST, SOC 2, and internal audit requests.
• Administer privileged access management for
admin and service accounts, including vaulting, rotation, and session
monitoring.
• Manage non-employee identity: vendors,
travelers, locum tenens providers, students, and affiliate users outside the HR
feed.
• Monitor and investigate identity-related
security events; support incident response and inappropriate-access
investigations with Security and Privacy/Compliance.
• Document standards, runbooks, and workflows;
contribute to the IAM roadmap and automation backlog.
Requirements
• 3–5+ years in identity and access management
or systems administration with a heavy identity focus.
• Deep hands-on expertise with Active Directory
and Entra ID in a hybrid environment.
• Working knowledge of SAML, OIDC/OAuth 2.0,
SCIM, LDAP, and Kerberos.
• Experience deploying MFA and conditional
access at enterprise scale.
• PowerShell scripting for AD/Entra automation
and reporting.
• Experience supporting audits and access
reviews in a regulated environment.
• Understanding of least-privilege and HIPAA
“minimum necessary” principles.
Preferred
Qualifications
• Experience in a hospital or health system IT
environment.
• IGA platform experience (SailPoint, Saviynt,
Okta Identity Governance, or similar).
• PAM tooling (CyberArk, Delinea).
• Imprivata OneSign or comparable clinical SSO.
• HR-to-identity integration experience
(Workday, UKG, or Oracle HCM feeds).
• Certifications: SC-300 (Microsoft Identity and
Access Administrator), Security+, CISSP, or CIDPRO.
What
This Role Is Not
Work
Environment