Identity & Access Management Engineer

Atrium Health

Charlotte (NC)

Remote

USD 110,000 - 140,000

Full time

29 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Atrium Health is seeking an experienced IAM Engineer to design, implement, and maintain complex identity and access management solutions across the organization. You will work with SailPoint, Active Directory, Azure AD, Okta, MFA, SAML, OAuth and LDAP to ensure secure access for users, roles, and applications.

You will test and validate IAM implementations, monitor systems, perform risk assessments and audits, and collaborate with vendors to resolve issues.

Qualifications

  • Bachelor's degree in Information Systems, Computer Science or related field.
  • Typically requires several years of experience in IAM engineering, administration, or support; strong knowledge of IAM concepts, identity lifecycle, access control, authentication and provisioning.

Responsibilities

  • Design, implement, and maintain IAM solutions (IGA, PAM, SSO) using tools like SailPoint, AD, Azure AD, Okta.
  • Test, validate and QA IAM solutions; monitor and audit IAM activities and processes.
  • Perform access reviews, risk assessments, audits to ensure IAM policy compliance.
  • Collaborate with vendors at a technical level to resolve problems and manage escalation.
  • Provide technical support and guidance on IAM-related matters; document architectures and processes.

Skills

IAM concepts
Scripting
PowerShell
Python
Bash
JavaScript
Java
C#
Communication

Education

Bachelor's Degree in Information Systems or Computer Science

Tools

SailPoint
Active Directory
Azure AD
Okta
MFA
SAML
OAuth
LDAP
IBM Verify
SSO

Job description

Major Responsibilities

Design, implement, and maintain complex IAM solutions, including IGA, PAM, and SSO, using various tools and technologies, such as SailPoint, Active Directory, IBM Verify, Azure AD, Okta, MFA, SAML, OAuth, and LDAP. Participate in testing, validation, and quality assurance of IAM solutions, ensuring functionality, performance, security, monitor and audit IAM systems, activities, and processes. Assist in developing and implement process improvement initiatives, backup and recovery procedures, and security optimization tasks within IAM. Perform troubleshooting, analysis and remediation of access and permissions issues. Assist working collaboratively with vendors at technical level to resolve problems and manage escalation.

Design, implement, and maintain complex IAM solutions, including IGA, PAM, and SSO, using various tools and technologies, such as SailPoint, Active Directory, IBM Verify, Azure AD, Okta, MFA, SAML, OAuth, and LDAP. Participate in testing, validation, and quality assurance of IAM solutions, ensuring functionality, performance, security, monitor and audit IAM systems, activities, and processes. Assist in developing and implement process improvement initiatives, backup and recovery procedures, and security optimization tasks within IAM. Perform troubleshooting, analysis and remediation of access and permissions issues. Assist working collaboratively with vendors at technical level to resolve problems and manage escalation.

Manage the identity lifecycle and access policies for users, groups, roles, and applications across the organization. Assist with investigations and responses to high-impact IAM incidents, assist team to contain and mitigate threats. Perform access reviews, risk assessments, vulnerability analysis and audits to ensure compliance with IAM policies and standards, and provide audit, privacy, legal and compliance support for IAM security/access related issues. Adhere to all procedures necessary to protect information systems from intentional or inadvertent modification, disclosure, or destruction.

Provide technical support and guidance to clients and internal teams on IAM-related matters, such as user provisioning, access requests, password resets, authentication issues, identity governance, identity verification, etc. Monitor and audit the IAM management systems and processes, make recommendations, take appropriate action to ensure the best performance, and generate reports and metrics. Responsible for developing and reporting on overall metrics of assigned areas of responsibility. Evaluate and implement improvements to monitoring protocols. Assist in creating and maintaining comprehensive IAM documentation, including architecture designs, IAM policies, process workflows, procedures, configurations, and compliance reports, and ensure they align with the best practices and industry standards.

Identify, implement security controls and remediate any IAM vulnerabilities, risks, or gaps, and implement corrective actions and preventive measures. Assist in ensuring IAM practices align with regulatory requirements (e.g. SOX, PCI DSS, FFIEC, HIPAA), conduct security audits, and support compliance efforts. Support security/access related records in all phases including build, configuration, testing, implementation, go-live support, and optimization, and perform process improvement and security optimization tasks. Serve as escalation for the application teams for security/access issues, and as IAM point of contact for assigned audits and security related activities with other departments. Document all responses. Facilitate disaster recovery and business continuance configurations and procedures. Assist in disaster recovery and business continuance configurations and procedures.

Analyze and resolve IAM issues and incidents and provide root cause analysis and recommendations for improvement. Evaluate/resolve issues/tickets working with customers as needed. Recommend and implement solutions for problems within the team.

Participate in complex IAM projects and initiatives, and collaborate with other engineers, analysts, and managers to deliver high-quality IAM solutions. Analyzes business requirements and creates technical recommendations. Assist in the resolution of project issues and recording time against tasks accurately and timely. Assist in work plan development and management. Ensure successful completion of assigned projects on schedule, within budget, and in accordance with Advocate Health standards.

Collaborate with the IAM team, application owners, and business stakeholders to understand and document IAM requirements and issues. Ensures integrity for application delivery, creates tasks, work estimates, and resource requirements on those tasks. Communicates with teammates and customers in order to keep them informed with regard to activity status and potential problem areas and provides recommendations to management. Identify and understand business impact of decisions made to fulfill customer expectations.

Contribute to team effort by sharing of knowledge, aiding, and demonstrating initiative. Train and mentor other IAM team members. Define protocol for working with customers and appropriately balance needs and resources.

Maintain knowledge of applicable technologies, job/system related forums, roadmaps and/or related documentation. Research and evaluate new IAM technologies and best practices and recommend improvements and enhancements to the IAM architecture and processes.

Licensure, Registration, And/or Certification Required

IAM certification (SailPoint, Okta, or other IAM engineering related certification) within one year employment.

Education Required

Bachelor's Degree (or equivalent knowledge) in Information Systems, Computer Science or related field

Experience Required

Typically requires at least three years of experience in IAM Engineering, administration, or support, preferably in a large and complex environment and 5 years of experience in IT fields such as Cyber Security, Epic Security, or other technical areas; or an equivalent combination of education and experience. Strong knowledge and skills in IAM concepts, principles, best practices and standards, such as identity lifecycle management, access management, authentication, authorization, provisioning, deprovisioning, auditing, and identity federation. Proficient in IAM tools and technologies, such as Active Directory, Azure AD, SSO, MFA, SAML, OAuth, LDAP and SCIM. Experience in scripting and automation using PowerShell, Python, Bash, JavaScript, Java, C# or other languages. Experience in cloud computing platforms and services, such as Azure, AWS, or Google Cloud.

Preferred remote locations in IL, WI, NC, GA

Preferred remote locations in IL, WI, NC, GA

Fully Remote Role from these states: AL, AK, AR, AZ, DE, FL, GA, IA, ID, IN, IL (Only WI/IL Division), LA, KS, KY, ME, MI, MO, MS, MT, NC, ND, NE, NH, NM, NV, OH, OK, PA, SC, SD, TN, TX, UT, VA, WI, WV, WY.

Fully Remote Role from these states: AL, AK, AR, AZ, DE, FL, GA, IA, ID, IN, IL (Only WI/IL Division), LA, KS, KY, ME, MI, MO, MS, MT, NC, ND, NE, NH, NM, NV, OH, OK, PA, SC, SD, TN, TX, UT, VA, WI, WV, WY.

Due to complex requirements, remote work is NOT permitted for short or long periods in: CA, DC, CO, CT, HI, MA, MD, MN, NJ, NY, OR, RI, VT, WA. and working Internationally (this includes working while on vacation).

Due to complex requirements, remote work is NOT permitted for short or long periods in: CA, DC, CO, CT, HI, MA, MD, MN, NJ, NY, OR, RI, VT, WA. and working Internationally (this includes working while on vacation).

No relocation, No Sponsorship or student visa for this position now or in the future.

No relocation, No Sponsorship or student visa for this position now or in the future.

Knowledge, Skills & Abilities Required

Strong technical skills inIAM tools,scripting languages (PowerShell, Python, Bash, JavaScript, Java, C#, or other languages), and a deep understanding of security controls and industry standards.Requires an understanding of IAM technology, process and procedures and the ability to apply that understanding to supporting existing systems and/or implementing new systems that directly benefit the patient care, education, and research and/or business functions of Advocate Health. Strong knowledge of user provisioning procedures and role-based access control.

Detailed knowledge of security as it relates to application support. Understanding of security mechanisms with clinical and hospital information systems. Knowledge of industry standard frameworks and controls such asNIST,CIS, SOX, and Zero Trust principles.

Advanced knowledge of operating systems, vendor-specific environments, and other system software. Broad understanding of tools and technologies from end user devices through the database management system. SQL knowledge is a plus.

Strong data analytical, critical thinking, reasoning, deduction, inference, and problem-solving skills. Ability to learn new technologies and skills quickly.

Ability to maintain a high level of confidentiality. Excellent verbal and written communication skills and the demonstrated ability to communicate well with all levels of the organization.

Ability to work in a fast-paced, dynamic team environment. Highly organized with the ability to work on numerous simultaneous activities while paying attention to detail and quality. Experience in project management and agile methodologies, such as Scrum or Kanban, is a plus.

Proven experience working in a team-oriented, collaborative environment. Foster a cooperative work environment by using effective communication skills, interpersonal relationships and team building.

Demonstrates experience in developing processes and documents to ensure quality delivery of services.

Clear and strong understanding of customer service requirements and skills. Demonstrated facilitation skills and ability to explain technical subjects to non-technical clients. Demonstrated ability to translate user requirements into system specifications.

Self-motivated, able to work independently to complete tasks and respond to department requests and to collaborate with others to utilize their resources and knowledge to identify high quality solutions.

Proficiency in Microsoft Suite (Word, PowerPoint, Excel, Access, Outlook) or similar products.

Physical Requirements And Working Conditions

Work is subject to high-level visibility through verbal and written communications with senior management.

This position requires travel, therefore, will be exposed to weather and road conditions.

Operates all equipment necessary to perform the job.

Exposed to a normal office environment.

Position will require off‑hours support and on‑call rotation. Due to project requirements and schedules in Advocate Health, overtime, evening and weekend hours may be required at times for conversions, training, etc.

Access to verbal, written and electronic PHI for this job has been determined based on job level and job responsibility within the organization. Will limit access to protected health information (PHI) to the information reasonably necessary to do the job.

Will share information only on a need‑to‑know basis for work purposes.

Each employee has the responsibility to work in a safe manner.

Employee does not have direct patient contact.

Must be able to lift objects that weigh up to 35 lbs.

Preferred Certification / License:

Certifications in IAM, security or Epic are a plus.

DISCLAIMER

All responsibilities and requirements are subject to possible modification to reasonably accommodate individuals with disabilities.

This job description in no way states or implies that these are the only responsibilities to be performed by an employee occupying this job or position. Employees must follow any other job‑related instructions and perform any other job‑related duties requested by their leaders.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Access Management Engineer
Identity & Access Management Engineer

Advocate Health • Charlotte (NC)

Remote
USD 110,000 - 140,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Hugh Chatham Memorial Hospital • Charlotte (NC)

Remote
USD 52,000 - 80,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Hugh Chatham Health • Charlotte (NC)

Remote
USD 53,000 - 79,000
Health and welfare benefits
Paid Time Off
Educational Assistance Program
Identity & Access Management Engineer
Identity & Access Management Engineer

aah • Charlotte (NC)

Remote
USD 52,000 - 79,000
Cybersecurity IAM Engineer
Cybersecurity IAM Engineer

OhioHealth • Columbus (OH)

On-site
USD 95,000 - 120,000
IT Manager, Identity and Access Management
IT Manager, Identity and Access Management

umchealthsystem • United States

On-site
USD 140,000 - 190,000
Patient Service Representative I Med Grp- Paddock Lake
Patient Service Representative I Med Grp- Paddock Lake

Advocate Health • Town of Salem (WI)

On-site
USD 32,000 - 42,000
Patient Svc Rep- Imaging
Patient Svc Rep- Imaging

Advocate Health • Town of Germantown (WI)

On-site
USD 36,000 - 48,000
End User Computing Architect | PAM Health Corporate
End User Computing Architect | PAM Health Corporate

PAM Health • Plano (TX)

On-site
USD 140,000 - 180,000
Senior Security Engineer - Secure SDLC
Senior Security Engineer - Secure SDLC

Highmark Health • Baton Rouge (LA)

On-site
USD 103,000 - 165,000