Identity & Access Management Engineer

Advocate Health

Charlotte (NC)

Remote

USD 110,000 - 140,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Advocate Health seeks an experienced IAM Engineer to design, implement, and maintain complex IAM solutions including IGA, PAM, and SSO across the enterprise. You will work with SailPoint, Active Directory, Azure AD, Okta, MFA, SAML, OAuth, and LDAP while ensuring security, compliance, and high availability.

You will collaborate with vendors and internal teams, perform access reviews, incident response, and governance activities, and contribute to process improvements, disaster recovery, and

Qualifications

  • IAM certification (SailPoint, Okta, or related) within one year.
  • Bachelor's degree in Information Systems, Computer Science or related field.
  • Typically requires at least three years in IAM Engineering or related IT fields.

Responsibilities

  • Design, implement, and maintain IAM solutions (IGA, PAM, SSO).
  • Participate in testing, validation, QA of IAM solutions for security and performance.
  • Assist with incident investigations, access reviews, risk assessments, and audits.
  • Provide technical guidance to clients and internal teams on IAM matters.
  • Collaborate with vendors and other engineers to resolve issues and manage escalations.
  • Develop and maintain IAM documentation, architecture designs, and policies.

Skills

Identity lifecycle
Access management
Authentication
Authorization
Provisioning
Auditing
Identity federation

Education

Bachelor's Degree in Information Systems, Computer Science

Tools

SailPoint
Okta
Active Directory
Azure AD
IBM Verify
SSO
MFA
SAML
OAuth
LDAP
SCIM

Job description

Major Responsibilities:

Design, implement, andmaintaincomplex IAM solutions, including IGA, PAM, and SSO, using various tools and technologies, suchas SailPoint, Active Directory, IBM Verify, Azure AD, Okta, MFA, SAML, OAuth, and LDAP.Participate in testing, validation, and quality assurance of IAM solutions, ensuring functionality, performance, security,monitorandauditIAM systems, activities, and processes.Assistin developing andimplementprocess improvement initiatives, backup and recovery procedures, and security optimization tasks within IAM.Perform troubleshooting, analysis and remediation of access and permissions issues. Assist working collaboratively with vendors attechnicallevel to resolve problems and manage escalation.


Manage the identity lifecycle and access policies for users, groups, roles, and applications across the organization.Assistwith investigations and responses to high-impact IAM incidents,assistteamtocontainand mitigate threats.Perform access reviews, risk assessments, vulnerabilityanalysisand audits to ensure compliance with IAM policies and standards, and provide audit, privacy, legal and compliance support for IAM security/access related issues.Adhere to all procedures necessary to protect information systems from intentional or inadvertent modification, disclosure, or destruction.


Provide technical support and guidance to clients and internal teams on IAM-related matters, such as user provisioning, access requests, password resets, authentication issues, identity governance, identity verification,etc.Monitor and audit the IAM management systems and processes, make recommendations, takeappropriate actionto ensure the best performance, and generate reports and metrics.Responsible for developing and reporting on overall metrics of assigned areas of responsibility.Evaluate and implement improvements tomonitoringprotocols.Assistin creating andmaintainingcomprehensive IAM documentation, including architecture designs, IAM policies, process workflows, procedures, configurations, and compliance reports, and ensure they align with the best practices and industry standards.


Identify, implement securitycontrolsand remediate any IAM vulnerabilities, risks, or gaps, and implement corrective actions and preventive measures.Assistin ensuring IAM practices align with regulatory requirements (e.g.SOX, PCI DSS, FFIEC, HIPAA), conduct security audits, and support compliance efforts. Support security/access related records in all phases including build, configuration, testing, implementation, go-live support, and optimization, and perform process improvement and security optimization tasks.Serve as escalation for the application teams for security/access issues, and asIAMpoint of contact for assigned audits and security related activities with other departments. Document all responses.Facilitate disaster recovery and business continuance configurations and procedures.Assistindisaster recovery and businesscontinuanceconfigurations and procedures.


Analyze and resolve IAM issues and incidents and provide root cause analysis and recommendations for improvement.Evaluate/resolve issues/tickets working with customers as needed. Recommend and implement solutions for problems within the team.


Participate incomplexIAM projects and initiatives, and collaborate with other engineers, analysts, and managers to deliver high-quality IAM solutions.Analyzes business requirements and creates technical recommendations.Assistin the resolution of project issues and recording time against tasks accurately and timely.Assistin work plan development and management. Ensure successful completion of assigned projects on schedule, within budget, andin accordance withAdvocate Health standards.


Collaborate with the IAM team, application owners, and business stakeholders to understand and document IAM requirements and issues.Ensures integrity for application delivery, creates tasks, work estimates, and resource requirementsonthose tasks. Communicates with teammates and customersin order tokeep them informedwith regard toactivity status and potential problem areas and provides recommendations to management.Identifyand understandbusinessimpact of decisions made to fulfill customer expectations.


Contribute to team effort bysharing ofknowledge, aiding, anddemonstratinginitiative.Train and mentor other IAM teammembers.Define protocol for working with customers and appropriately balance needs and resources.

Maintain knowledge of applicable technologies, job/system related forums,roadmapsand/or related documentation. Research and evaluate new IAM technologies and best practices and recommend improvements and enhancements to the IAM architecture and processes.


Licensure, Registration, and/or Certification Required:

IAM certification (SailPoint, Okta, or other IAM engineering related certification) withinoneyearemployment.


Education Required:

Bachelor's Degree (or equivalent knowledge) in Information Systems, ComputerScienceor related field


Experience Required:

Typically requires at least three years of experience in IAM Engineering, administration, or support, preferably in a large and complex environment and 5 yearsofexperience in IT fields such as Cyber Security, Epic Security, or other technical areas;oran equivalent combination of education and experience.Strong knowledge and skills in IAM concepts, principles,bestpracticesand standards, such as identity lifecycle management, access management, authentication, authorization,provisioning, deprovisioning, auditing,and identity federation.Proficient in IAM tools and technologies, such as Active Directory, Azure AD, SSO, MFA, SAML, OAuth,LDAPand SCIM. Experience in scripting and automation using PowerShell, Python,Bash, JavaScript, Java,C#or other languages. Experience in cloud computing platforms and services, such as Azure, AWS, or Google Cloud.


Preferred remote locations in IL, WI, NC, GA

Fully Remote Role from these states: AL, AK, AR, AZ, DE, FL, GA, IA, ID, IN, IL (Only WI/IL Division), LA, KS, KY, ME, MI, MO, MS, MT, NC, ND, NE, NH, NM, NV, OH, OK, PA, SC, SD, TN, TX, UT, VA, WI, WV, WY.


Due to complex requirements, remote work is NOT permitted for short or long periods in: CA, DC, CO, CT, HI, MA, MD, MN, NJ, NY, OR, RI, VT, WA. and working Internationally (this includes working while on vacation).


No relocation, No Sponsorship or student visa for this position now or in the future.

Knowledge, Skills & Abilities Required:

Strong technical skills inIAM tools,scripting languages (PowerShell, Python, Bash, JavaScript, Java, C#, or other languages), and a deep understanding of security controls and industry standards.Requires an understanding of IAM technology, process and procedures and the ability to apply that understanding to supporting existing systems and/or implementing new systems that directlybenefitthe patientcare, education, and research and/or business functions of Advocate Health.Strong knowledge of user provisioning procedures and role-based access control.


Detailed knowledge of security as it relates to application support.Understanding ofsecurity mechanisms with clinical and hospital information systems.Knowledge of industry standard frameworks and controls such asNIST,CIS, SOX, and Zero Trust principles.


Advanced knowledge of operating systems, vendor-specific environments, and other system software.Broad understanding of tools and technologies from end user devices through the database managementsystem.SQL knowledge is a plus.


Strong data analytical, critical thinking, reasoning, deduction, inference, and problem-solving skills.Ability to learnnew technologiesand skills quickly.


Ability tomaintaina high levelof confidentiality.Excellent verbal and written communication skills and the demonstrated ability to communicate well with all levels of the organization.


Ability to work ina fast-paced, dynamic team environment. Highly organized with the ability to work onnumeroussimultaneous activities while paying attentionto detail and quality.Experience in project management and agile methodologies, such as Scrum or Kanban, is a plus.


Proven experience working in ateam-oriented, collaborative environment.Foster a cooperative work environment by usingeffectivecommunication skills, interpersonalrelationshipsand team building.


Demonstrates experience in developing processes and documents to ensure quality delivery of services.


Clearand strong understanding of customer service requirements and skills.Demonstrated facilitation skills and ability to explain technical subjects to non-technical clients.Demonstrated ability to translate user requirements into system specifications.


Self-motivated, able to work independently to complete tasks and respond to department requests and to collaborate with others toutilizetheir resources and knowledge toidentifyhigh qualitysolutions.


ProficiencyinMicrosoftSuite (Word, PowerPoint, Excel, Access,Outlook) or similar products.


Physical Requirements and Working Conditions:

Work is subject to high-level visibility through verbal and written communications with senior management.


This position requires travel, therefore, will be exposed to weather and road conditions.


Operates all equipment necessary to perform the job.


Exposed to a normal office environment.


Position will require off-hourssupport and on-call rotation.Due to project requirements and schedules in Advocate Health, overtime,eveningand weekend hours may berequiredat times for conversions, training, etc.


Access to verbal,writtenand electronic PHI for this job has beeneterminedbased on job level and job responsibility within the organization. Will limit access to protected health information (PHI) to the informationreasonably necessaryto do the job.


Will share information only on aneed-to-knowbasis for work purposes.


Each employee has the responsibility towork in a safe manner.


Employee doesnot have direct patient contact.


Must be able to lift objects that weigh up to 35 lbs.


Preferred Job Requirements

Preferred Certification / License:

Certifications in IAM, security or Epic are a plus.


DISCLAIMER

All responsibilities and requirements are subject to possible modification to reasonably accommodate individuals with disabilities.

This job description in no way states or implies that these are the only responsibilities to be performed by an employee occupying this job or position. Employees must follow any other job-related instructions and perform any other job-related duties requested by their leaders.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Access Management Engineer
Identity & Access Management Engineer

Atrium Health • Charlotte (NC)

Remote
USD 110,000 - 140,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Hugh Chatham Memorial Hospital • Charlotte (NC)

Remote
USD 52,000 - 80,000
Identity & Access Management Engineer
Identity & Access Management Engineer

aah • Charlotte (NC)

Remote
USD 52,000 - 79,000
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Salem (OR)

Hybrid
USD 86,000 - 139,000
Cybersecurity IAM Engineer
Cybersecurity IAM Engineer

OhioHealth • Columbus (OH)

On-site
USD 95,000 - 120,000
Patient Service Representative-South Elgin
Patient Service Representative-South Elgin

Advocate Health Care • South Elgin (IL)

On-site
USD 32,000 - 48,000
Patient Svc Rep
Patient Svc Rep

Advocate Health • Oshkosh (WI)

On-site
USD 32,000 - 42,000
Patient Service Representative I Hospital
Patient Service Representative I Hospital

Aurora Health Care • Fond du Lac (WI)

On-site
USD 22,000 - 30,000
IT Manager, Identity and Access Management
IT Manager, Identity and Access Management

UMC Health System • Lubbock (TX)

On-site
USD 110,000 - 170,000
Patient Service Representative I Med Grp- Paddock Lake
Patient Service Representative I Med Grp- Paddock Lake

Advocate Health • Town of Salem (WI)

On-site
USD 32,000 - 42,000