AVP IAM & Governance

HealthEquity, Inc.

United States

Remote

USD 244,000 - 270,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) match
HSA contribution & match
Uncapped PTO
Paid parental leave
Gym & fitness reimbursement
Wellness program incentives

Job summary

HealthEquity, Inc. seeks an AVP to lead Identity & Access Management, shaping a multi-year AI-led strategy that places identity at the security perimeter.

You will own governance, RBAC to ABAC evolution, and the enterprise authentication framework, including FIDO2/WebAuthn and SSO across cloud and on-prem apps. You will build and mentor a high-performing IAM team, align OKRs/SLOs for identity services, and partner with auditors and executives to advance the security program while driving

Qualifications

  • 12–15+ years of progressive information security experience, with at least 5 years leading IAM teams and programs at enterprise scale.
  • Proven track record architecting and delivering major identity transformations end to end (IGA, PAM, zero trust identity modernization).
  • Fluency in identity standards and protocols (OAuth 2.0, OIDC, SAML 2.0, SCIM, FIDO2/WebAuthn).
  • Executive communication – translate complex identity architecture into board-level risk narratives.

Responsibilities

  • Own and evangelize a multi-year AI-led identity strategy and reference architecture.
  • Lead IAM team: architects, engineers, and analysts; define career paths and automation-driven operations.
  • Govern identity lifecycle (JML, provisioning, deprovisioning) with SLAs and governance controls.
  • Set MFA, federation (SAML 2.0, OIDC), and token security strategies across enterprise apps.
  • Drive governance for entitlement sprawl across SaaS/IaaS/on‑prem and CIEM.

Skills

Identity domain expertise
Leadership
Executive communication
Architecture decision records

Education

Bachelor's degree in CS/Cybersecurity or related
Master's degree preferred

Tools

SailPoint
Saviynt
Okta
Microsoft Entra
Ping Identity
CyberArk
Delinea

Job description

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview
How You Can Make a Difference

The AVP, Identity & Access Management, the enterprise authority on identity — the architect, evangelist, and operational owner of an identity-first security model in which identity is the control plane for a cloud-first, zero trust enterprise.

This leader defines and executes a multi-year B2E IAM strategy spanning identity governance and administration (IGA), privileged access management (PAM), customer and workforce access management, non-human/machine identity, and identity threat detection and response (ITDR), and is accountable for the engineering rigor, control effectiveness, and audit posture of the entire identity fabric.

This is a role for a practitioner-leader and recognized thought leader: someone who has designed and operated identity programs at scale, who is fluent in modern identity standards and protocols (OAuth 2.0, OIDC, SAML 2.0, SCIM, FIDO2/WebAuthn), who can whiteboard an authorization model one hour and defend a control posture to auditors and executives the next, and who actively shapes the direction of the identity discipline — inside the organization and in the broader industry — through published points of view, standards engagement, and community leadership.

What You’ll be Doing
  • Identity Strategy & Thought Leadership:
    • Own and evangelize a multi-year AI led identity strategy and reference architecture that treats identity as the primary security perimeter, aligned to zero trust principles (NIST SP 800-207) and enterprise business objectives.
    • Serve as the organization's most senior voice on identity: publish internal position papers and architectural decision records, brief executive leadership and the Board on identity risk, and represent the company externally through industry forums, standards bodies, conference speaking, and peer communities.
    • Anticipate and translate emerging shifts — decentralized identity, verifiable credentials, passwordless/phishing-resistant authentication, AI-agent and workload identity, continuous access evaluation (CAEP/Shared Signals) — into pragmatic roadmap decisions with clear build/buy/retire rationale.
  • Organizational Leadership:
    • Build, lead, and mentor a high-performing team of IAM architects, engineers, and analysts; establish engineering career paths, on‑call/operational maturity, and a culture of automation‑first identity operations.
    • Operate identity as a product: define OKRs and SLOs for identity services (provisioning latency, certification completion, authentication availability, orphaned‑account rates), and manage a prioritized backlog with IT, HR, Legal, Compliance, and business‑line stakeholders.
  • Identity Governance & Administration (IGA):
    • Architect and operate the full identity lifecycle — joiner/mover/leaver (JML) automation driven by authoritative HR sources, birthright provisioning, SCIM‑based downstream integration, and deprovisioning SLAs measured in minutes to hours.
    • Design and mature the enterprise access model using Agentic AI capabilities: role engineering and role mining, RBAC evolving toward attribute‑and‑policy‑based access control (ABAC/PBAC), segregation‑of‑duties (SoD) rulesets, and risk‑based, evidence‑quality access certifications that eliminate rubber‑stamping.
    • Own governance of entitlement sprawl across SaaS, IaaS, and on‑prem estates, including cloud infrastructure entitlement management (CIEM) and least‑privilege enforcement in AWS/Azure environments.
  • Authentication, Authorization & Directory Architecture:
    • Set the enterprise standard for authentication: phishing‑resistant MFA (FIDO2/WebAuthn), passwordless adoption, adaptive/risk‑based authentication, and session management policies calibrated to data sensitivity.
    • Own federation and SSO architecture (SAML 2.0, OIDC/OAuth 2.0), token security and lifetime strategy, and conditional access policy design across the enterprise application portfolio.
    • Govern directory and identity‑store architecture — Entra ID and Active Directory hardening (tiered administration, attack‑path reduction), hybrid identity synchronization, and rationalization of legacy identity repositories.
    • Advance externalized, policy‑as‑code authorization patterns (e.g., OPA/Rego, Cedar) for fine‑grained, auditable access decisions in modern applications.
  • Privileged Access & Non‑Human Identity:
    • Own the privileged access management program: credential vaulting, session isolation and recording, just‑in‑time/zero‑standing‑privilege elevation, and break‑glass governance.
    • Establish lifecycle governance for non‑human identities — service accounts, API keys, certificates, workload identities, and emerging AI‑agent identities — including inventory, ownership attestation, secrets management, and automated rotation.
  • IAM Platform Engineering & Operations:
    • Lead evaluation, selection, and engineering of the IAM technology stack — IGA, access management/IdP, PAM, CIEM, and ITDR platforms — with a bias toward API‑first integration, infrastructure‑as‑code deployment, and CI/CD‑managed identity configuration.
    • Ensure availability, resilience, and disaster recovery of identity services as tier‑zero infrastructure; identity outages are business outages.
    • Instrument the identity fabric end to end: stream identity telemetry to SIEM, define detections for identity‑centric attack techniques (credential stuffing, token theft, MFA fatigue, golden ticket/SAML forging, privilege escalation), and partner with the SOC on ITDR playbooks.
  • Risk, Compliance & Assurance:
    • Own identity‑related control design and operating effectiveness for HIPAA Security Rule safeguards, HITRUST CSF, SOC 1/SOC 2, SOX ITGCs, and applicable state privacy regimes; serve as primary identity interface for internal audit, external auditors, and regulators.
    • Run a continuous identity risk program: access‑risk scoring, toxic‑combination detection, periodic attack‑path and privilege‑escalation reviews, and identity‑specific tabletop exercises.
    • Develop and maintain incident response plans for identity compromise scenarios and lead identity workstreams during security incidents.
What You’ll Need to be Successful

Education and Experience

  • Bachelor's degree in Computer Science, Cybersecurity, or a related discipline, or equivalent work experience. Master's degree preferred.
  • 12–15+ years of progressive information security experience, with at least 5 years leading IAM teams and programs at enterprise scale.
  • Demonstrated track record of architecting and delivering at least one major identity transformation end to end (e.g., IGA platform implementation, workforce IdP migration, PAM program build‑out, or zero trust identity modernization).

Specialized Knowledge, Skills, and Abilities

  • Deep, hands‑on‑credible expertise across the identity domain: IGA, access management, PAM, CIEM, ITDR, directory services, and non‑human identity.
  • Fluency in identity standards and protocols — OAuth 2.0, OIDC, SAML 2.0, SCIM, LDAP/Kerberos, FIDO2/WebAuthn — and the architectural trade‑offs among them.
  • Enterprise experience with leading IAM platforms (e.g., SailPoint, Saviynt, Okta, Microsoft Entra, Ping Identity, CyberArk, Delinea or comparable) and with integrating identity into SIEM/SOAR ecosystems.
  • Working knowledge of zero trust architecture (NIST SP 800-207), NIST SP 800-63 digital identity guidelines, and least‑privilege design in cloud environments (AWS IAM, Azure RBAC/Entra).
  • Strong command of identity‑relevant regulatory and assurance frameworks — HIPAA, HITRUST, SOC 2, SOX ITGCs — and experience defending control design to auditors.
  • Evidence of thought leadership: published writing, conference talks, standards or working‑group participation, patents, open‑source contribution, or recognized community leadership in the identity space.
  • Executive‑caliber communication — able to translate deep technical architecture into board‑level risk narratives — paired with strong leadership, mentorship, and team‑building skills.

Certifications, Licenses, Registrations

  • Relevant industry certifications strongly preferred — e.g., CISSP, CISM, CISA, CIDPRO, or vendor‑specific identity certifications (SailPoint, Okta, Microsoft, CyberArk).
Travel Requirements
  • Occasional travel to attend training, industry conferences, or meetings may be required.

This is a remote position.

Salary Range

$244000.00 To $270000.00 / year

Benefits & Perks

The actual compensation offer is determined based on job‑related knowledge, education, skills, experience, and work location. This position will be eligible for performance‑based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education& tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives

Onboarding & Travel

This is a remote role, with an in‑person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.

This role may begin with a virtual, self‑paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.

HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt‑out request from you, we will assume that you consent to the use of Microsoft Copilot.

At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.

As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.

HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visitHealthEquity Privacy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AVP IAM & Governance
AVP IAM & Governance

HealthEquity, Inc. • Mission (TX), Northern (KY)

Hybrid
USD 244,000 - 270,000
Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
+6
Sr IAM Security Engineer
Sr IAM Security Engineer

Visa Hunt • United States

On-site
USD 115,000 - 150,000
Medical, dental, and vision
HSA contribution and match
401(k) match
+1
AVP IAM & Governance
AVP IAM & Governance

HealthEquity • Draper (UT)

Remote
USD 244,000 - 270,000
Principal Security Engineer
Principal Security Engineer

HealthEquity, Inc. • Mission (TX)

On-site
USD 133,000 - 173,000
Medical, dental, and vision
HSA match
401(k) match
+2
Enterprise Solutions Manager
Enterprise Solutions Manager

HealthEquity, Inc. • Mission (TX), Northern (KY)

On-site
USD 88,000 - 106,000
Medical, dental, vision
HSA match
Dependent care FSA
+7
Cyber Def. & SaaS Security Mgr
Cyber Def. & SaaS Security Mgr

HealthEquity • Draper (UT)

On-site
USD 121,000 - 157,000
Medical, dental, and vision
HSA match
PTO and holidays
+5
Executive Assistant
Executive Assistant

HealthEquity • Draper (UT)

Remote
USD 60,000 - 75,000
Medical, dental, and vision
401(k) match
Paid time off
Sr Implementation Mgr
Sr Implementation Mgr

HealthEquity, Inc. • United States

Remote
USD 60,000 - 75,000
Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
+6
Executive Assistant
Executive Assistant

HealthEquity, Inc. • Mission (TX), Northern (KY)

Hybrid
USD 60,000 - 75,000
Medical benefits
Dental & Vision
HSA match
+7
Sr Implementation Mgr
Sr Implementation Mgr

HealthEquity • Draper (UT)

Remote
USD 60,000 - 75,000
Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
+6