Job Description
Identity& Access Management (IAM) Engineer
Infrastructure& Directory Services | Healthcare Environment | Full-Time
PositionSummary
We areseeking an IAM Engineer to own identity infrastructure and access lifecycleoperations across the enterprise. This role is focused on directory services,authentication, and identity governance at the platform level - ActiveDirectory, Microsoft Entra ID, SSO, MFA, and automated provisioning. EHRapplication security (Epic templates, security classes, user profiles) ishandled by a separate clinical applications team; this role supports that teamupstream by ensuring accurate, timely identity data and account lifecycleevents but does not perform EHR provisioning.
KeyResponsibilities
- Administer on-prem Active Directory andMicrosoft Entra ID: user and group lifecycle, OU structure, GPOs, hybrid sync(Entra Connect), and conditional access policies.
- Execute and automate joiner/mover/leaverprocesses driven by the HR system of record, ensuring same-day deprovisioningof departed workforce members across AD, M365, VPN, and downstream systems.
- Configure and maintain SSO integrations (SAML2.0, OIDC) for enterprise and third-party applications; onboard newapplications to the identity platform.
- Deploy and support multifactor authenticationand passwordless initiatives across employed staff, credentialed providers,contractors, and students.
- Support badge-tap / fast user switching forclinical workstations (e.g., Imprivata OneSign) in coordination with desktopengineering.
- Maintain role-based access models at thedirectory and group level; remediate access creep and orphaned or staleaccounts.
- Run periodic access certification campaigns;produce evidence for HIPAA, HITRUST, SOC 2, and internal audit requests.
- Administer privileged access management foradmin and service accounts, including vaulting, rotation, and sessionmonitoring.
- Manage non-employee identity: vendors,travelers, locum tenens providers, students, and affiliate users outside the HRfeed.
- Monitor and investigate identity-relatedsecurity events; support incident response and inappropriate-accessinvestigations with Security and Privacy/Compliance.
- Document standards, runbooks, and workflows;contribute to the IAM roadmap and automation backlog.
Requirements
- 3-5+ years in identity and access managementor systems administration with a heavy identity focus.
- Deep hands-on expertise with Active Directoryand Entra ID in a hybrid environment.
- Working knowledge of SAML, OIDC/OAuth 2.0,SCIM, LDAP, and Kerberos.
- Experience deploying MFA and conditionalaccess at enterprise scale.
- PowerShell scripting for AD/Entra automationand reporting.
- Experience supporting audits and accessreviews in a regulated environment.
- Understanding of least-privilege and HIPAA "minimum necessary" principles.
PreferredQualifications
- Experience in a hospital or health system ITenvironment.
- IGA platform experience (SailPoint, Saviynt,Okta Identity Governance, or similar).
- PAM tooling (CyberArk, Delinea).
- Imprivata OneSign or comparable clinical SSO.
- HR-to-identity integration experience(Workday, UKG, or Oracle HCM feeds).
- Certifications: SC-300 (Microsoft Identity andAccess Administrator), Security+, CISSP, or CIDPRO.
WhatThis Role Is Not
This positiondoes not include Epic or other EHR application security build. Candidates willnot manage Epic security classes, templates, or user records - that function isowned by the clinical applications team.
WorkEnvironment
Hybrid/on-siteper organizational policy; participation in an on-call rotation foridentity-impacting incidents (account lockouts affecting clinical operations,termination escalations).