Engineer III, Identity and Access Management

PDS Health

Irving (TX)

On-site

USD 104,000 - 136,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Paid time off
Tuition reimbursement
401K
Community volunteering time

Job summary

A health technology organization in Texas is seeking an Engineer III for Cybersecurity & Risk Management. This role is responsible for managing Identity Governance & Administration, ensuring compliance with security regulations, and optimizing access controls. Applicants should possess 6+ years of experience in Identity & Access Management, hands-on expertise with IGA platforms, and excellent technical skills. The position offers a competitive salary, health benefits, and opportunities for professional growth.

Qualifications

  • 6+ years of experience in Identity & Access Management.
  • At least 2 years of hands-on experience with enterprise IGA platforms.
  • Proven track record of executing governance roadmaps.

Responsibilities

  • Own and maintain the IGA technical roadmap.
  • Manage the full identity lifecycle for human and non-human entities.
  • Design and build access control frameworks.

Skills

Identity & Access Management
Identity lifecycle management
Role-based access control
SaaS security
Compliance reporting

Education

Bachelor’s Degree in IT/Information Security or related field
5+ years of experience in lieu of degree

Tools

Postman
PowerShell
Python

Job description

Now is the time to join PDS Health. You will have opportunities to learn new skills from our team of experienced professionals. If you're ready to take your career to the next level and gain valuable experience, apply today!

The Engineer III, Cybersecurity & Risk Mgmt. - Identity & Access Management independently owns and executes Identity

Governance & Administration (IGA) functions — including identity lifecycle management, access certifications, entitlement

governance, and SaaS security posture — with minimal supervision. Embedded within the IAM team under Cybersecurity & Risk

Mgmt., this position carries primary ownership of day‑to‑day IGA operations and tooling, applying critical thinking to resolve

complex access challenges and ensuring all deliverables meet quality and compliance standards.

Focused on protecting information assets, infrastructure, and patient data, this role enforces least‑privilege access

principles across enterprise and clinical systems through automated JML workflows, role‑based access controls, SoD policy

management, and continuous governance of SaaS application access.

Working in close coordination with IT Operations, HR, Compliance, Privacy, and Clinical Informatics, this role translates policy

into enforceable access controls, contributes to process improvement across the IAM program, and may mentor entry‑level team

members. It ensures adherence to the HIPAA Security and Privacy Rule, PCI DSS, HITRUST, ISO 27001:2022, ISO 22301:2019, and

other applicable regulatory frameworks

Responsibilities
  • Own and maintain the IGA technical roadmap, governance frameworks, and entitlement catalog, ensuring identity capabilities are consistently implemented and aligned to organizational policy.

  • Manage the full identity lifecycle for all human and non‑human entities — including automated joiner, mover, and leaver (JML) workflows — ensuring secure and auditable provisioning and deprovisioning across enterprise and clinical systems.

  • Design, build, and continuously optimize role‑based access control (RBAC) frameworks, including role mining, role design, and access request workflows, to enforce least‑privilege principles across all environments.

  • Define, implement, and maintain Segregation of Duties (SoD) policies; perform conflict detection and lead remediation workflows in partnership with Compliance and application owners.

  • Lead and execute periodic access certification and recertification campaigns, ensuring timely completion, appropriate reviewer engagement, and documented outcomes for audit purposes.

  • Manage SaaS application access governance, including shadow IT discovery, OAuth grant reviews, and SaaS‑to‑SaaS integration risk remediation, using the organization's IGA and SaaS security posture toolset.

  • Architect and maintain integrations between IGA platforms and authoritative sources (HR systems, directories) and downstream applications, including EHR/EMR platforms, using SCIM, REST APIs, SAML, and other standards‑based protocols.

  • Author and maintain comprehensive technical documentation including architectural diagrams, workflow mappings, and SOPs for all IGA systems and processes to ensure operational consistency and audit readiness.

  • Proactively identify, measure, and remediate access‑related risks; perform compliance reporting and regular access control audits to protect critical assets, including PHI and PII.

  • Lead organizational efforts to ensure IGA controls and processes align with HIPAA Security and Privacy Rule, HITRUST, PCI DSS, ISO 27001:2022, and other applicable regulatory frameworks.

  • Ensure the confidentiality, integrity, and availability (CIA) of identity services in accordance with defined SLA metrics, maintaining high levels of data security and patient satisfaction.

  • Serve as a technical liaison between Information Technology and business units, proactively identifying access governance gaps and architecting solutions that balance security with operational efficiency.

  • Collaborate with leaders, architects, and stakeholders to translate business and compliance requirements into IGA controls, building trust‑based relationships that position security as an enabler.

  • Research emerging IGA technologies and trends, proposing scalable solutions that create business value and support organizational growth.

  • Provide subject matter expertise and technical mentorship to junior engineers, driving team proficiency in IGA platforms, access governance practices, and regulatory frameworks.

  • Strictly utilize only PDS Health‑authorized, secured AI environments for ticket summarization and drafting internal notes to ensure no data leakage of company PII or patient data.

  • Ensure all actions and workflows strictly adhere to PDS Health Information Security Policies and all applicable state, federal, and regulatory requirements.

  • Ensures compliance with all policies and standards, as well as state, federal and other regulatory bodies.

  • This is not intended to be a comprehensive list of the duties and responsibilities of the position and the duties and responsibilities may change.

Qualifications
  • Bachelor’s Degree in Arts/Sciences (BA/BS) from an accredited college in IT/Information Security, Computer Science, IT, Engineering or related field. In lieu of degree, 5+ years of experience is required or the equivalent combination of education and experience.

  • 6+ years years of direct experience in Identity & Access Management, with at least 2 years focused specifically on hands‑on experience administering an enterprise IGA platform (e.g., Okta Lifecycle Management, Microsoft Entra Identity Governance, Sa

  • 2+ including ownership of IGA programs, platform administration, and lifecycle automation at enterprise scale. Must include a proven track record of driving IGA maturity, executing governance roadmaps, and taking on increasing responsibility within complex, multi‑application environments.

  • 2+ years of experience designing and enforcing SoD policies, including conflict detection, remediation workflows, and entitlement reviews across enterprise and clinical applications.

  • 2+ years of experience building and troubleshooting IGA integrations using REST APIs, SCIM, and SAML — with proficiency using tools such as Postman for testing and validation.

  • 2+ years of experience with scripting and automation (PowerShell, Python, or equivalent) applied specifically to identity lifecycle events, provisioning routines, and access governance workflows.

  • Strong grasp of identity lifecycle management, RBAC, and access governance in complex, multi‑application environments

  • Strong working knowledge of identity provisioning standards and protocols including SCIM, SAML, OAuth/OIDC, and LDAP as applied to IGA platform integrations.

  • Direct experience across the full IGA project lifecycle — including requirements gathering, governance design, platform configuration, integration, testing, and change management.

  • Proven ability to communicate access governance risks and IGA program status to non‑technical stakeholders and leadership, translating compliance requirements into business‑aligned solutions.

  • Expert‑level understanding of identity governance principles and regulatory frameworks — including NIST 800‑63, ISO 27001, HIPAA, and HITRUST — with a demonstrated ability to operationalize these standards through IGA controls and processes.

Preferred
  • Master’s degree in Arts/Sciences (MA/MS) Master's degree in Cybersecurity, Information Assurance, or a related technical field.

  • One or more industry‑recognized certifications such as CISSP, CISM, or CISA. Specialized IGA or vendor certifications — such as Okta Lifecycle Management, Microsoft Entra Identity Governance, or SailPoint IdentityNow — are considered a significant advantage.

  • Okta Certified Professional/Administrator/Developer or Microsoft Entra SC-300 / SC-5008

  • Experience governing non‑human identities, including service accounts, workload identities, and application credentials, within an IGA framework.

  • Prior experience supporting ISO 27001 certification audits, specifically developing evidence packages for Access Control (Annex A.9) and contributing to audit‑readiness activities tied to identity governance.

  • Experience with Grip Security or similar SSPM/SaaS discovery platforms

  • Familiarity with Valence Security or equivalent SaaS security posture tooling

  • Familiarity with PAM tools (CyberArk)

  • Healthcare or life sciences background with EHR/EMR exposure (Epic, Cerner), or experience in a healthcare (medical or dental), or other large, regulated enterprise environment with complex identity governance requirements.

Knowledge/Skills/Abilities
  • Independently leverages adaptability to handle diverse situations and resolve common issues.

  • Maintains mutually beneficial partnerships with other functions.

  • Communicates using persuasion and authority.

  • Independently leverages customer focus to handle diverse situations and resolve common issues.

  • Independently leverages data literacy to handle diverse situations and resolve common issues.

  • Independently leverages interpersonal skills to handle diverse situations and resolve common issues.

Benefits
  • Medical, dental, and vision insurance
  • Paid time off
  • Tuition Reimbursement
  • 401K
  • Paid time to volunteer in your local community
Compensation Information

$104,000.00-$136,000.00 / Annually

PDS Health is an Equal Opportunity Employer. We celebrate diversity and are united in our mission to create healthier and happier team members.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Engineer, Infrastructure and Platform Services
Sr Engineer, Infrastructure and Platform Services

PDS Health • Irving (TX)

On-site
USD 117,000 - 153,000
Medical, dental, and vision insurance
Paid time off
Tuition Reimbursement
+2
Sr Engineer, Integration
Sr Engineer, Integration

PDS Health • California (MO)

On-site
USD 130,000 - 168,000
Medical, dental, and vision insurance
Paid time off
Tuition Reimbursement
+2
Sr Engineer, Integration
Sr Engineer, Integration

PDS Health • Irvine (CA)

On-site
USD 130,000 - 168,000
Health insurance
401K
Paid time off
+2
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Frankfort (KY)

On-site
USD 86,400 - 138,600
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Boise (ID)

On-site
USD 86,400 - 138,600
Health insurance
Training and professional development
Flexible work arrangements
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Salem (OR)

On-site
USD 86,400 - 138,600
Director, IAM Operations & Support
Director, IAM Operations & Support

ADP • Miami (FL)

On-site
USD 123,000 - 304,000
Director, IAM Operations & Support
Director, IAM Operations & Support

ADP • Norfolk (VA)

Hybrid
USD 123,000 - 304,000
Dir, Risk Internal Controls and Operations
Dir, Risk Internal Controls and Operations

PDS Health • Irvine (CA)

On-site
USD 169,000 - 227,000
Medical, dental, and vision insurance
Paid time off
Tuition Reimbursement
+2
Senior Security Advisor, Identity
Senior Security Advisor, Identity

MRO • United States

On-site
USD 120,000 - 150,000
Annual cash bonus
Comprehensive benefits offering
401(k) plan