freehire launches on Product Hunt on 26 August.

Follow →

Staff Security Engineer - IAM

Summary

Designs and maintains cloud-native identity and access management (IAM) systems, focusing on AWS/Azure/GCP IAM, SAML/OIDC, automation (Terraform/Python), and non-human identity security to protect healthcare systems and ensure compliance with HIPAA/SOC 2.

The Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services that support our business. You will understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape.

Primary Duties

  1. Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.

  2. Design and deploy advanced identity security controls to safeguards networks, systems, and applications.

  3. Work across disciplines to shape our security services strategy and execution

  4. Set and uphold the standard for security processes to support high-quality engineering

  5. Mentor and galvanize new engineers to do their best work

Minimum Qualifications

  • BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field

  • 8+ years of experience in software or security engineering within Cloud Native environments


  • Domain Specific Minimum Requirements


    • Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM, Azure Entra ID, or GCP IAM), including designing/enforcing least-privilege roles, RBAC/ABAC, and permission policies.

    • Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML, OIDC, OAuth, LDAP/Directory Services), user lifecycle automation, SSO, MFA, and Just-In-Time (JIT) access.

    • Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or CloudFormation) and scripting (Python or PowerShell) to automate identity provisioning, drift detection, and access workflows.

    • Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts, API keys, bots, and automated workload identities across cloud infrastructure.

Preferred KSA’s

  • Experience architecting, developing, and deploying large-scale distributed systems at scale

  • Experience with cloud technologies, e.g., AWS, Azure, GCP

  • Experience building continuous integration and continuous development (CI/CD) pipelines

  • Familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go)

  • 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value

  • Experience with health-tech systems, like Electronic Health Records, Clinical data, etc.


  • Domain Specific Experience

    • AI Identity & Access Management

      • NHI Architecture: Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads.

      • AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.

      • AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.

      • Advanced Protocols & Microservice Security: Familiarity with SPIFFE/SPIRE, zero-trust network architectures, or complex containerized identity frameworks.

      • SIEM & Security Observability Tools: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g., Crowdstrike, Sumo Logic, Wiz, Zscaler).

      • Industry & Regulatory Context: Experience with health-tech systems, clinical data environments (EHRs), and regulatory standards (HIPAA, SOC 2, ISO 27001).

      • Certifications: CISSP, OSCP, CEH, Certified AI Security Specialist (CAISS), or GIAC Machine Learning Security Engineer (GMSE).

Physical Requirements

Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are:
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.

What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.

In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:

Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!

At Aledade, we don’t just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.

Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website

  • Are you legally eligible to work in the United States? choose one
  • Do you currently require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas. choose one
  • In the future, will you require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas. choose one
  • How did you learn about Aledade? written answer
  • What is your desired salary for this position?
  • Please list the state that you plan to be physically located in while employed with our company? For employment at Aledade, it is required to be located within the United States; even for remote based roles. choose one · optional
  • Are you subject to an agreement with a former employer or other party (such as non-competition agreement) that might, in any way, restrict your ability to work for our Company?* choose one
  • Would you like to opt-in to receiving text messages for this role regarding the hiring process (e.g., interview requests and reminders)? Note: Selecting “No” will not eliminate you from consideration. Message and data rates may apply. You can opt-out at any time by replying “STOP.” choose one
  • By clicking "Submit Application" I agree to the Aledade Applicant Privacy Policy & Terms of Service - https://www.aledade.com/privacy-policy-applicants yes / no · optional
  • By clicking "Submit Application" I certify that all statements made in this application are true and complete. I understand that any falsification, misrepresentation, or omission of fact is sufficient cause for my removal from consideration for employment or my dismissal if hired yes / no · optional
  • Do you have experience leading cloud security initiatives for SaaS companies? choose one
  • Do you have professional experience in AWS and/or GCP? written answer
  • Are you proficient in coding with Python or Java? written answer
  • Describe your experience leading IAM initiatives in a cloud-based environment. written answer

See also