IAM Engineer - Cloud Platform

GuideWell

Northern (KY)

Hybrid

USD 109,000 - 178,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work arrangement
Competitive pay
Comprehensive benefits
Retirement Savings Plan with employer
Paid time off and holidays

Job summary

GuideWell is seeking an IAM Engineer to own the cloud side of enterprise identity integration across AWS GovCloud and commercial partitions. You will design federation, automate joiner/mover/leaver processes, and implement workload identity patterns with OIDC for pipelines, while aligning with governance standards.

You will collaborate with application teams to onboard apps to SSO and produce audit-ready evidence, with a focus on cross-account access, security controls, and lifecycle automation

Qualifications

  • 6+ years related work experience in IAM, security, or platform engineering, with 3+ years focused on cloud identity.
  • Related Bachelor's degree required.
  • Strong AWS/Azure IAM skills, including cross-account access, federation, and permission boundaries.
  • Hands-on experience with SSO and federation platforms.
  • Experience integrating an enterprise identity provider such as Okta, Entra ID, or Ping with cloud.
  • Hands-on Terraform.
  • Working knowledge of SAML, OIDC, and SCIM.
  • Experience in environments governed by HIPAA, HITRUST, SOC 2, FedRAMP, or NIST 800-53.
  • Required to obtain CISSP within 180 Days of hire

Responsibilities

  • Design and operate federation and the entitlement model across accounts.
  • Automate access lifecycle: joiner, mover, leaver.
  • Build workload identity patterns; eliminate long-lived keys and standing access.
  • Build access recertification and produce audit evidence.
  • Onboard applications to SSO and review access designs with application teams.
  • Integrate cloud entitlements with the enterprise identity governance platform.
  • Design workload and machine identity patterns, including roles for services and OIDC for pipelines.

Skills

AWS IAM
Azure IAM
SSO
federation
Terraform
SAML/OIDC/SCIM
Okta Entra Ping
SailPoint Saviynt
CyberArk
Python scripting

Education

Bachelor's degree

Tools

Okta
Entra ID
Ping Identity
SailPoint
Saviynt
CyberArk

Job description

GuideWell is migrating to AWS across commercial and GovCloud partitions. The IAM Engineer owns how identity works in that environment: federation from the enterprise identity provider, access lifecycle into cloud accounts, and the authorization model application teams build against. The enterprise identity team owns the identity provider and governance platform. This role owns the cloud side of the integration and the entitlement design within it.

What You Will Be Doing
  • Design and operate federation and the entitlement model across accounts
  • Automate access lifecycle: joiner, mover, leaver
  • Build workload identity patterns; eliminate long-lived keys and standing access
  • Build access recertification and produce audit evidence
  • Onboard applications to SSO and review access designs with application teams
  • Integrate cloud entitlements with the enterprise identity governance platform.
  • Build access recertification for cloud entitlements and produce evidence for audit.
  • Design workload and machine identity patterns, including roles for services and OIDC for pipelines.
What We Require
  • 6+ years related work experience in IAM, security, or platform engineering, with 3+ years focused on cloud identity
  • Related Bachelor's degree required
  • Strong AWS/Azure IAM skills, including cross-account access, federation, and permission boundaries.
  • Hands‑on experience with SSO and federation platforms.
  • Experience integrating an enterprise identity provider such as Okta, Entra ID, or Ping with cloud.
  • Hands‑on Terraform.
  • Working knowledge of SAML, OIDC, and SCIM.
  • Experience in an environment governed by HIPAA, HITRUST, SOC 2, FedRAMP, or NIST 800-53.
  • Required to obtain Certified Information Systems Security Professional License (CISSP) within 180 Days of hire
What We Prefer
  • Identity engineering across a mix of GovCloud and commercial, including the cross‑partition trust boundary.
  • Which partition was primary does not matter. Healthcare payer experience.
  • Privileged access management tooling such as CyberArk.
  • Identity governance and administration tooling such as SailPoint or Saviynt, and lifecycle automation.
  • Machine identity at scale, including workload federation and secrets management.
  • Python or equivalent scripting for identity automation.
  • Cloud Security Specialty, CCSP, or an identity‑focused certification.
General Physical Demands
  • Exerting up to 10 pounds of force occasionally to move objects.
  • Jobs are sedentary if traversing activities are required only occasionally.
  • This position offers a hybrid work arrangement which combines flexibility with in office engagement. Team schedules are determined based on role requirements and business needs. Travel to and from our corporate offices may be required.
What We Offer

As a Florida Blue employee, you will be at the heart of GuideWell’s vision – to lead the nation in transforming health through compassionate, connected, and technology‑enabled care that delivers personalized value and empowered living.

To support your wellbeing, comprehensive benefits are offered. As an employee, you will have access to:

  • Medical, dental, vision, life and global travel health insurance
  • Income protection benefits: life insurance, short‑and‑long‑term disability programs
  • Leave programs to support personal circumstances
  • Retirement Savings Plan including employer match
  • Paid time off, volunteer time off, 10 holidays and 2 well‑being days
  • Additional voluntary benefits available; and a comprehensive wellness program

Employee benefits are designed to align with federal and state employment laws. Benefits may vary based on the state in which work is performed. Benefits for intern, part‑time and seasonal employees may differ.

To support your financial wellbeing, we offer competitive pay as well as opportunities for incentive or commission compensation. We also conduct regular annual reviews with pay for performance considerations for base pay increases.

Typical Annualized Offer/Hiring Range: $109,300 - $136,600

Annualized Salary Range: $109,300 - $177,600

Final pay will be determined with consideration of market competitiveness, internal equity, and the job‑related knowledge, skills, training, and experience you bring.

We are an Equal Employment Opportunity employer committed to cultivating a work experience where everyone feels like they belong and can perform at their best in pursuit of our mission. All qualified applicants will receive consideration for employment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IAM Engineer - Cloud Platform
IAM Engineer - Cloud Platform

Florida Blue Group • United States

Hybrid
USD 109,000 - 178,000
Medical, dental, vision insurance
Retirement Savings Plan with employer
Paid time off & holidays
+1
IAM Engineer - Cloud Platform
IAM Engineer - Cloud Platform

Florida Blue Group • Northern (KY)

Hybrid
USD 109,000 - 178,000
Medical, dental, vision
Retirement plan with employer match
Paid time off
+3
Cloud Security Engineer
Cloud Security Engineer

GuideWell • Northern (KY)

Hybrid
USD 109,000 - 178,000
Cloud Security Engineer
Cloud Security Engineer

Florida Blue Group • Northern (KY)

Hybrid
USD 109,000 - 178,000
Health insurance
Retirement plan with employer match
Paid time off
+1
Cloud Security Engineer
Cloud Security Engineer

Florida Blue Group • Town of Florida (NY)

Hybrid
USD 109,000 - 178,000
Health insurance
Retirement plan
Paid time off
+2
Principal Engineer - Cloud Platform
Principal Engineer - Cloud Platform

Florida Blue • Jacksonville (FL)

Hybrid
USD 130,000 - 211,000
Medical insurance
Dental insurance
Paid time off
Enterprise Cloud Architect
Enterprise Cloud Architect

Florida Blue • Jacksonville (FL)

Hybrid
USD 142,000 - 230,000
Medical, dental, vision insurance
Retirement Savings Plan with employer
Paid time off and holidays
Enterprise Cloud Architect
Enterprise Cloud Architect

GuideWell • Jacksonville (FL)

Hybrid
USD 142,000 - 230,000
Medical, dental, vision insurance
Retirement plan
Paid time off
+2
Enterprise Cloud Architect
Enterprise Cloud Architect

WEB-TPA, Inc. • Jacksonville (FL)

Hybrid
USD 142,000 - 230,000
Medical, dental, vision insurance
Retirement savings plan
Paid time off
Enterprise Cloud Architect
Enterprise Cloud Architect

Florida Blue Group • Jacksonville (FL)

Hybrid
USD 142,000 - 230,000
Medical, dental, vision insurance
Retirement plan with employer match
Paid time off and holidays
+1