Identity & Access Management Engineer

Blue Cross & Blue Shield of Rhode Island

Deutschland

Hybrid

EUR 72.000 - 107.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Tuition reimbursement
Student-loan repayment assistance
Health insurance
Dental insurance
Vision insurance
Bonuses

Zusammenfassung

BCBSRI is seeking an IAM specialist to administer Entra ID, Active Directory, and Okta, implementing SSO, MFA, and access controls across cloud and on-prem environments. You will automate tasks with PowerShell, Terraform, and Python, while upholding HIPAA and Zero Trust standards.

You will collaborate with Security, Infrastructure, and Compliance teams to ensure secure identity services and governance, including audit readiness and incident resolution.

Qualifikationen

  • 3–5 years of IAM, Cloud Identity, Directory Services, Access Management, or Security Engineering in enterprises.
  • Strong knowledge of IAM technologies including Entra ID, AD, Okta, Google Cloud IAM, SSO, MFA, Conditional Access, and PIM.
  • Hands-on experience with authentication, federation, and identity integration technologies (SAML 2.0, OAuth 2.0, OIDC, SCIM, LDAP).
  • Very good understanding of IAM concepts, best practices, and security governance.

Aufgaben

  • Administer and support Microsoft Entra ID, Active Directory, and Okta environments including user lifecycle management, group administration, authentication services, directory synchronization, and access governance.
  • Design, implement, and maintain SSO, MFA, Conditional Access, Passwordless, and Identity Protection across cloud and on-prem applications.
  • Manage PIM, RBAC, admin role assignments, service accounts, and privileged access across Azure, Entra ID, Okta, and GCP.
  • Configure and maintain integrations using SAML, OAuth 2.0, OIDC, SCIM, LDAP, Kerberos, and federation technologies for secure auth and provisioning.
  • Support GCP identity services including Cloud Identity, IAM roles, service accounts, workload identity federation, and secure access to GCP resources.
  • Automate tasks with PowerShell, Python, Terraform, Azure CLI, APIs; improve governance and efficiency.
  • Investigate and resolve identity, authentication, provisioning, authorization, and access incidents escalated by various teams.
  • Participate in Identity Governance, compliance, audits, security assessments, PoCs; support HIPAA, SOC2, NIST, and Zero Trust requirements.

Kenntnisse

Microsoft Entra ID
Active Directory
Okta
SSO
MFA
PAM
RBAC
PowerShell
Python
Terraform

Ausbildung

Bachelor’s degree (preferred) in Computer Science/IT/IS/Cybersecurity

Tools

Azure
Google Cloud IAM
SAML
OAuth 2.0
OIDC

Jobbeschreibung

Pay Range:

$83,200.00 - $124,800.00

At BCBSRI, our greatest resource is our people.

We come from varying backgrounds, different cultures, and unique experiences. We are hard-working, caring, and creative individuals who collaborate, support one another, and grow together. Passion, empathy, and understanding are at the forefront of everything we do—not just for our members, but for our employees as well.

We recognize that to do your best work, you have to be your best self.
It’s why we offer flexible work arrangements that include remote and hybrid opportunities and paid time off. We provide tuition reimbursement and assist with student-loan repayment. We offer health, dental, and vision insurance as well as programs that support your mental health and well-being. We pay competitively, offer bonuses and investment plans, and are committed to growing and developing our employees.

Our culture is one of belonging.
We strive to be transparent and accountable. We believe in equipping our associates with the knowledge and resources they need to be successful. No matter where you’re at in the organization, you’re an integral part of our team and your input, thoughts, and ideas are valued.

Join others who value a workplace for all.
We appreciate and celebrate everything that makes us unique, from personal characteristics to past experiences. Our different perspectives strengthen us as an organization and help us better serve all Rhode Islanders.

We’re dedicated to serving Rhode Islanders.
Our focus extends beyond providing access to high-quality, affordable, and equitable care. To further improve the health and well-being of our fellow Rhode Islanders, we regularly roll up our sleeves and get to work (literally) in communities all across the state—building homes, working in food pantries, revitalizing community centers, and transforming outdoor spaces for children and adults. Because we believe it is our collective responsibility to uplift our fellow Rhode Islanders when and where we can, our associates receive additional paid time to volunteer.

Why this job matters:

Supports and administers enterprise identity platforms across Microsoft Entra ID, Azure, Okta, Active Directory, and Google Cloud Platform (GCP) environments. Works under the guidance of senior engineers and IT leadership to design, implement, secure, automate, and maintain identity services that enable secure access to enterprise applications, cloud resources, and business data. Assists with identity lifecycle management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Privileged Access Management (PAM), cloud access governance, federation services, and identity security initiatives. Contributes to the organization’s Zero Trust strategy, cloud transformation efforts, automation initiatives, and regulatory compliance requirements supporting protected and sensitive data.

What you will do:
  • Administer and support Microsoft Entra ID, Active Directory, and Okta environments, including user lifecycle management, group administration, authentication services, directory synchronization, and access governance.
  • Design, implement, and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Passwordless Authentication, and Identity Protection capabilities across cloud and on-premises applications.
  • Manage Privileged Identity Management (PIM), Role-Based Access Control (RBAC), administrative role assignments, service accounts, and privileged access operations across Microsoft Azure, Entra ID, Okta, and GCP environments.
  • Configure and maintain application integrations utilizing SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, LDAP, Kerberos, and federation technologies to enable secure authentication and provisioning.
  • Support Google Cloud Platform (GCP) identity services, including Cloud Identity, IAM roles, service accounts, workload identity federation, and secure access to GCP resources and services.
  • Contribute to automation and workflow optimization using PowerShell, Microsoft Graph API, Terraform, Python, Okta Workflows, Azure Automation, and Infrastructure-as-Code practices to improve operational efficiency and governance.
  • Investigate and resolve complex identity, authentication, provisioning, authorization, and access-related incidents escalated from Service Desk, Infrastructure, Security Operations, and application support teams.
  • Participate in Identity Governance, compliance, audit readiness, security assessments, Proof-of-Concept initiatives, and continuous improvement efforts while supporting organizational requirements related to HIPAA, SOC2, NIST, and Zero Trust security frameworks.
  • Perform other duties as assigned.
What you need to succeed:
  • Bachelor’s degree in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field is preferred but not required; equivalent hands‑on experience may fully substitute for formal education. 3–5 years of direct experience in Identity and Access Management (IAM), Cloud Identity, Directory Services, Access Management, or Security Engineering within enterprise environments.
  • Strong knowledge of identity and access management technologies including Microsoft Entra ID (Azure AD), Active Directory Domain Services, Microsoft Entra Connect/Cloud Sync, Azure RBAC, Okta Workforce Identity Cloud, Google Cloud IAM, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and Privileged Identity Management (PIM).
  • Demonstrated hands‑on expertise with enterprise authentication, federation, and identity integration technologies including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and LDAP.
  • Strong understanding of Identity and Access Management (IAM) concepts and best practices.
  • Expertise in authentication, authorization, federation, and identity governance.
  • Strong troubleshooting skills across identity, network, security, and cloud environments.
  • Ability to automate operational tasks using PowerShell, Python, Terraform, Azure CLI, and APIs.
  • Strong understanding of certificate-based authentication, PKI, and cryptographic concepts.
  • Ability to develop technical documentation, standards, SOPs, and architecture diagrams.
  • Strong collaboration and communication skills when working with Security, Infrastructure, Cloud, Application Development, and Compliance teams.
  • Ability to manage multiple priorities and deliver projects within established timelines.
  • Understanding of requirements for building and maintaining a secure identity environment.
  • Ability to identify opportunities for automation, process improvement, and AI‑assisted operational efficiencies.
The extras:
  • Experience supporting hybrid and cloud identity environments, including Microsoft 365, Azure, Google Cloud, and enterprise SaaS application integrations.
  • Hands‑on experience with user provisioning, identity synchronization, federation services, access requests, account lifecycle automation, and governance processes.
  • Experience troubleshooting authentication, authorization, federation, conditional access, MFA, and identity synchronization issues across on‑premises and cloud environments.
  • Knowledge of security best practices related to identity protection, privileged access management, Zero Trust architecture, identity risk management, and compliance requirements.
  • Experience supporting identity‑related migrations, platform upgrades, cloud adoption initiatives, and enterprise access management transformations.
  • Advanced knowledge of Microsoft Entra Identity Governance and Access Reviews.
  • Experience with Okta Identity Engine and Okta Workflows.
  • Proficiency with Microsoft Graph API, Azure Automation, and Azure Landing Zone identity controls.
  • Experience with Terraform and Infrastructure‑as‑Code practices.
  • Experience securing cloud‑native applications and APIs.
  • Familiarity with ServiceNow integrations and IAM workflow automation.
  • Knowledge of CyberArk, Delinea, or other PAM solutions.
  • Experience supporting regulated healthcare or financial environments.
  • Understanding of HIPAA, SOC2, NIST, CIS Controls, and cybersecurity frameworks.
  • Familiarity with security monitoring, audit logging, and incident response processes.
  • Microsoft Certified in any of the following: Identity and Access Administrator Associate (SC-300); Azure Administrator Associate (AZ-104), Azure Solutions Architect Expert (AZ-305), Cybersecurity Architect Expert (SC-100)
  • ITIL Foundation Certification
  • Any other Identity Certification e.g. Okta
Location:

BCBSRI is headquartered in downtown Providence, conveniently located near the train station and bus terminal. We actively support associate well‑being and work/life balance and offer the following schedules, based on role:

  • In-office : onsite 5 days per week
  • Hybrid : onsite 2‑4 days per week
  • Remote : onsite 0‑1 days per week. Permitted to reside in the following states, pending approval from the Human Resources Department: Arizona, Connecticut, Florida, Georgia, Louisiana, Massachusetts, North Carolina, Oklahoma, Rhode Island, South Carolina, Texas, Virginia

Our culture of belonging at Blue Cross & Blue Shield of Rhode Island (BCBSRI) is at the core of all we do, and it strengthens our ability to meet the challenges of today’s healthcare industry. BCBSRI is an equal opportunity employer.

The law requires an employer to post notices describing the Federal laws. Please visit www.eeoc.gov/know-your-rights-workplace-discrimination-illegal to view the “Know Your Rights” poster.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior EPMO Project Manager
Senior EPMO Project Manager

Blue Cross & Blue Shield of Rhode Island • Deutschland

Hybrid
EUR 88.000 - 141.000
Flexible work arrangements (remote &hy
Paid time off
Tuition reimbursement
+3
Manager Client Implementation
Manager Client Implementation

Embedded Shishya • Deutschland

Hybrid
EUR 88.000 - 140.000
Flexible schedules (in-office/remote/h
Health, dental, vision insurance
Tuition reimbursement
+3
Actuary
Actuary

Blue Cross & Blue Shield of Rhode Island • Deutschland

Hybrid
EUR 101.000 - 161.000
Flexible work arrangements
Active Directory Engineer
Active Directory Engineer

TEKsystems • Deutschland

Hybrid
EUR 116.000 - 129.000
Medical benefits
Dental benefits
Vision benefits
+5
Director, Enterprise Employer Access - Cell Therapy
Director, Enterprise Employer Access - Cell Therapy

Bristol Myers Squibb • Deutschland

Remote
EUR 169.000 - 205.000
Health Coverage
Wellbeing Support
401(k) plan
+1
Member Advocate | Member Services Division | November 2026 - Remote
Member Advocate | Member Services Division | November 2026 - Remote

Blue Cross Blue Shield of Massachusetts • Deutschland

Hybrid
EUR 31.000 - 38.000
Medical/dental/vision
401(k)
Paid time off
Identity Management Engineer
Identity Management Engineer

CloudPay, Inc. • Deutschland

Hybrid
EUR 90.000 - 120.000
Calm app
WFH Allowance
Life Assurance
+9
Mainframe Storage Administrator
Mainframe Storage Administrator

Highmark Health • Deutschland

Hybrid
EUR 68.000 - 109.000
Senior Cloud Identity Engineer (m/f/d)
Senior Cloud Identity Engineer (m/f/d)

Redcare Pharmacy • Berlin

Hybrid
EUR 90.000 - 120.000
Welcome days
Remote setup allowance
Anchor days
+2
Senior Cloud Identity Engineer (m/f/d)
Senior Cloud Identity Engineer (m/f/d)

Redcare Pharmacy • Hamburg

Hybrid
EUR 90.000 - 130.000
Welcome days
Home office allowance
Anchor days travel
+2