Identity And Access Management IAM Engineer

InterScripts, Inc.

Hyderabad

Hybrid

INR 800,000 - 1,400,000

Full time

46 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

InterScripts, Inc. is seeking an IAM Engineer to own identity infrastructure and access lifecycle operations across the enterprise. The role focuses on directory services, authentication, and governance at the platform level, including Active Directory, Microsoft Entra ID, SSO, MFA, and automated provisioning.

You will partner with security and clinical teams to ensure timely identity data, manage joiners/movers/leavers, and support audits while not performing EHR provisioning.

Qualifications

  • 3–5+ years in identity and access management with a focus on directory services.
  • Deep hands-on experience with Active Directory and Entra ID in hybrid environments.
  • Knowledge of SAML, OIDC/OAuth 2.0, SCIM, LDAP, and Kerberos.
  • Experience deploying MFA and conditional access at enterprise scale.
  • PowerShell scripting for AD/Entra automation and reporting.
  • Experience supporting audits and access reviews in a regulated environment.
  • Understanding of least-privilege and HIPAA 'minimum necessary' principles.

Responsibilities

  • Administer on-prem Active Directory and Entra ID lifecycle.
  • Automate joiner/mover/leaver processes driven by HR data with same-day deprovisioning.
  • Configure and maintain SSO integrations (SAML2.0, OIDC) for apps; onboard new apps.
  • Deploy and support MFA and passwordless initiatives across staff, providers, contractors, and students.
  • Support badge-tap / fast user switching for clinical workstations in coordination with desktop engineering.
  • Maintain RBAC at directory level; remediate access creep and stale accounts.
  • Run periodic access certification campaigns; provide evidence for HIPAA, HITRUST, SOC 2, and internal audits.
  • Administer privileged access management including vaulting, rotation, and session monitoring.
  • Manage non-employee identities (vendors, travelers, locum tenens, students).
  • Monitor identity security events and assist incident response and investigations.
  • Document standards, runbooks, and IAM roadmap work.

Skills

IAM
Active Directory
Entra ID
SAML/OIDC
PowerShell

Tools

SailPoint
Okta
CyberArk

Job description

Job Description
Identity& Access Management (IAM) Engineer

Infrastructure& Directory Services | Healthcare Environment | Full-Time

PositionSummary

We areseeking an IAM Engineer to own identity infrastructure and access lifecycleoperations across the enterprise. This role is focused on directory services,authentication, and identity governance at the platform level - ActiveDirectory, Microsoft Entra ID, SSO, MFA, and automated provisioning. EHRapplication security (Epic templates, security classes, user profiles) ishandled by a separate clinical applications team; this role supports that teamupstream by ensuring accurate, timely identity data and account lifecycleevents but does not perform EHR provisioning.

KeyResponsibilities
  • Administer on-prem Active Directory andMicrosoft Entra ID: user and group lifecycle, OU structure, GPOs, hybrid sync(Entra Connect), and conditional access policies.
  • Execute and automate joiner/mover/leaverprocesses driven by the HR system of record, ensuring same-day deprovisioningof departed workforce members across AD, M365, VPN, and downstream systems.
  • Configure and maintain SSO integrations (SAML2.0, OIDC) for enterprise and third-party applications; onboard newapplications to the identity platform.
  • Deploy and support multifactor authenticationand passwordless initiatives across employed staff, credentialed providers,contractors, and students.
  • Support badge-tap / fast user switching forclinical workstations (e.g., Imprivata OneSign) in coordination with desktopengineering.
  • Maintain role-based access models at thedirectory and group level; remediate access creep and orphaned or staleaccounts.
  • Run periodic access certification campaigns;produce evidence for HIPAA, HITRUST, SOC 2, and internal audit requests.
  • Administer privileged access management foradmin and service accounts, including vaulting, rotation, and sessionmonitoring.
  • Manage non-employee identity: vendors,travelers, locum tenens providers, students, and affiliate users outside the HRfeed.
  • Monitor and investigate identity-relatedsecurity events; support incident response and inappropriate-accessinvestigations with Security and Privacy/Compliance.
  • Document standards, runbooks, and workflows;contribute to the IAM roadmap and automation backlog.
Requirements
  • 3-5+ years in identity and access managementor systems administration with a heavy identity focus.
  • Deep hands-on expertise with Active Directoryand Entra ID in a hybrid environment.
  • Working knowledge of SAML, OIDC/OAuth 2.0,SCIM, LDAP, and Kerberos.
  • Experience deploying MFA and conditionalaccess at enterprise scale.
  • PowerShell scripting for AD/Entra automationand reporting.
  • Experience supporting audits and accessreviews in a regulated environment.
  • Understanding of least-privilege and HIPAA "minimum necessary" principles.
PreferredQualifications
  • Experience in a hospital or health system ITenvironment.
  • IGA platform experience (SailPoint, Saviynt,Okta Identity Governance, or similar).
  • PAM tooling (CyberArk, Delinea).
  • Imprivata OneSign or comparable clinical SSO.
  • HR-to-identity integration experience(Workday, UKG, or Oracle HCM feeds).
  • Certifications: SC-300 (Microsoft Identity andAccess Administrator), Security+, CISSP, or CIDPRO.
WhatThis Role Is Not

This positiondoes not include Epic or other EHR application security build. Candidates willnot manage Epic security classes, templates, or user records - that function isowned by the clinical applications team.

WorkEnvironment

Hybrid/on-siteper organizational policy; participation in an on-call rotation foridentity-impacting incidents (account lockouts affecting clinical operations,termination escalations).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity And Access Management IAM Engineer
Identity And Access Management IAM Engineer

InterScripts, Inc. • Kondapur

Hybrid
INR 1,200,000 - 1,800,000
Identity & Access Management (IAM) Engineer
Identity & Access Management (IAM) Engineer

Interscripts, Inc. • Hyderabad

On-site
INR 2,800,000 - 4,000,000
Lead IAM Analyst
Lead IAM Analyst

NationsBenefits, LLC • Hyderabad

On-site
INR 1,800,000 - 3,200,000
IAM/IGA Engineer
IAM/IGA Engineer

Fortive • Bengaluru

On-site
INR 1,200,000 - 1,800,000
IdentIty and Access Management Engineer(Immediate Joiners Only)
IdentIty and Access Management Engineer(Immediate Joiners Only)

Callaway Digital Technologies • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Lead IAM Analyst
Lead IAM Analyst

NationsBenefits • Hyderabad

On-site
INR 900,000 - 1,500,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Cherry Bekaert • Chennai District

On-site
INR 1,200,000 - 1,500,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE Data Services • Hyderabad

On-site
INR 1,500,000 - 2,600,000
Lead Consultant IAM
Lead Consultant IAM

Providence India • Hyderabad

On-site
INR 1,500,000 - 2,100,000
IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000