Staff Security Engineer - IAM
Summary
Designs and maintains cloud-native identity and access management (IAM) systems, focusing on AWS/Azure/GCP IAM, SAML/OIDC, automation (Terraform/Python), and non-human identity security to protect healthcare systems and ensure compliance with HIPAA/SOC 2.
Primary Duties
-
Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.
-
Design and deploy advanced identity security controls to safeguards networks, systems, and applications.
-
Work across disciplines to shape our security services strategy and execution
-
Set and uphold the standard for security processes to support high-quality engineering
-
Mentor and galvanize new engineers to do their best work
Minimum Qualifications
-
BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field
-
8+ years of experience in software or security engineering within Cloud Native environments
-
Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM, Azure Entra ID, or GCP IAM), including designing/enforcing least-privilege roles, RBAC/ABAC, and permission policies.
-
Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML, OIDC, OAuth, LDAP/Directory Services), user lifecycle automation, SSO, MFA, and Just-In-Time (JIT) access.
-
Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or CloudFormation) and scripting (Python or PowerShell) to automate identity provisioning, drift detection, and access workflows.
-
Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts, API keys, bots, and automated workload identities across cloud infrastructure.
Domain Specific Minimum Requirements
Preferred KSA’s
-
Experience architecting, developing, and deploying large-scale distributed systems at scale
-
Experience with cloud technologies, e.g., AWS, Azure, GCP
-
Experience building continuous integration and continuous development (CI/CD) pipelines
-
Familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go)
-
4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value
-
Experience with health-tech systems, like Electronic Health Records, Clinical data, etc.
-
AI Identity & Access Management
-
NHI Architecture: Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads.
-
AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.
-
Advanced Protocols & Microservice Security: Familiarity with SPIFFE/SPIRE, zero-trust network architectures, or complex containerized identity frameworks.
-
SIEM & Security Observability Tools: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g., Crowdstrike, Sumo Logic, Wiz, Zscaler).
-
Industry & Regulatory Context: Experience with health-tech systems, clinical data environments (EHRs), and regulatory standards (HIPAA, SOC 2, ISO 27001).
-
Certifications: CISSP, OSCP, CEH, Certified AI Security Specialist (CAISS), or GIAC Machine Learning Security Engineer (GMSE).
-
Domain Specific Experience
Physical Requirements
Skills
- Agentic AI
- AI
- Analytics
- API
- Automation
- AWS
- AWS Bedrock
- Azure
- CI/CD
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- CloudFormation
- C++
- Crowdstrike
- C#
- Cybersecurity
- Distributed Systems
- Entra ID
- GCP
- Hipaa
- IAM
- Infrastructure as Code
- ISO 27001
- Java
- LDAP
- Machine Learning
- Microservices
- OAuth
- Observability
- OpenID
- PowerShell
- Python
- RBAC
- SAML
- Scala
- SIEM
- SOC 2
- SSO
- Terraform
- VPC
- Zero Trust
As published by lever · 14 questions · 4 written answers
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (1)
- What is your desired salary for this position?
Pick from a list (9)
- Are you legally eligible to work in the United States?
- Do you currently require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas.
- In the future, will you require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas.
- Please list the state that you plan to be physically located in while employed with our company? For employment at Aledade, it is required to be located within the United States; even for remote based roles. optional
- Are you subject to an agreement with a former employer or other party (such as non-competition agreement) that might, in any way, restrict your ability to work for our Company?*
- Would you like to opt-in to receiving text messages for this role regarding the hiring process (e.g., interview requests and reminders)? Note: Selecting “No” will not eliminate you from consideration. Message and data rates may apply. You can opt-out at any time by replying “STOP.”
- By clicking "Submit Application" I agree to the Aledade Applicant Privacy Policy & Terms of Service - https://www.aledade.com/privacy-policy-applicants optional
- By clicking "Submit Application" I certify that all statements made in this application are true and complete. I understand that any falsification, misrepresentation, or omission of fact is sufficient cause for my removal from consideration for employment or my dismissal if hired optional
- Do you have experience leading cloud security initiatives for SaaS companies?
Written answers (4)
- How did you learn about Aledade?
- Do you have professional experience in AWS and/or GCP?
- Are you proficient in coding with Python or Java?
- Describe your experience leading IAM initiatives in a cloud-based environment.