Identity & Access Management Engineer

Blue Cross & Blue Shield of Rhode Island

Providence, Northern (RI, KY)

Hybrid

USD 132,000 - 133,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Tuition reimbursement
Health, dental, vision insurance
Paid time off
Bonuses and investments
Volunteer time off

Job summary

Blue Cross & Blue Shield of Rhode Island (BCBSRI) is seeking an Identity Engineer to administer enterprise identity platforms across Microsoft Entra ID, Azure, Okta, Active Directory, and Google Cloud. You will design, implement, secure, and automate identity services enabling secure access to applications and data.

Responsibilities include SSO, MFA, RBAC/PIM, and federation across cloud/on‑prem environments, plus automation using PowerShell, Terraform, and Python.

Qualifications

  • 3–5 years in Identity and Access Management (IAM)
  • Experience with SSO, MFA, Conditional Access, RBAC, PIM
  • Knowledge of SAML, OAuth 2.0, OpenID Connect and SCIM
  • Experience across cloud and on‑prem environments

Responsibilities

  • Administer and support Entra ID, AD, and Okta environments
  • Design and implement SSO, MFA, Conditional Access, Passwordless authentication
  • Manage privileged access and RBAC across Azure, Entra ID, Okta, and GCP
  • Configure integrations using SAML, OAuth, OIDC, SCIM, LDAP
  • Support GCP identity services and IAM roles
  • Automate tasks with PowerShell, Terraform, Python, and APIs
  • Investigate identity and access incidents and support governance/compliance

Skills

IAM expertise
Cloud IAM
Entra ID
SSO/MFA

Education

Bachelor's degree

Tools

Microsoft Entra ID
Azure
Okta
Terraform
PowerShell

Job description

Pay Range: $83,200.00 - $124,800.00 Please email HR_Talent_AcquisitionTeam@bcbsri.org if you are a candidate seeking a reasonable accommodation for the application and/or interview process.

At BCBSRI, our greatest resource is our people. We come from varying backgrounds, different cultures, and unique experiences. We are hard-working, caring, and creative individuals who collaborate, support one another, and grow together. Passion, empathy, and understanding are at the forefront of everything we do — not just for our members, but for our employees as well. We recognize that to do your best work, you have to be your best self. It’s why we offer flexible work arrangements that include remote and hybrid opportunities and paid time off. We provide tuition reimbursement and assist with student-loan repayment. We offer health, dental, and vision insurance as well as programs that support your mental health and well-being. We pay competitively, offer bonuses and investment plans, and are committed to growing and developing our employees. Our culture is one of belonging. We strive to be transparent and accountable. We believe in equipping our associates with the knowledge and resources they need to be successful. No matter where you’re at in the organization, you’re an integral part of our team and your input, thoughts, and ideas are valued. Join others who value a workplace for all. We appreciate and celebrate everything that makes us unique, from personal characteristics to past experiences. Our different perspectives strengthen us as an organization and help us better serve all Rhode Islanders. We’re dedicated to serving Rhode Islanders. Our focus extends beyond providing access to high-quality, affordable, and equitable care. To further improve the health and well-being of our fellow Rhode Islanders, we regularly roll up our sleeves and get to work (literally) in communities all across the state—building homes, working in food pantries, revitalizing community centers, and transforming outdoor spaces for children and adults. Because we believe it is our collective responsibility to uplift our fellow Rhode Islanders when and where we can, our associates receive additional paid time to volunteer.

Why this job matters

Supports and administers enterprise identity platforms across Microsoft Entra ID, Azure, Okta, Active Directory, and Google Cloud Platform (GCP) environments. Works under the guidance of senior engineers and IT leadership to design, implement, secure, automate, and maintain identity services that enable secure access to enterprise applications, cloud resources, and business data. Assists with identity lifecycle management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Privileged Access Management (PAM), cloud access governance, federation services, and identity security initiatives. Contributes to the organization's Zero Trust strategy, cloud transformation efforts, automation initiatives, and regulatory compliance requirements supporting protected and sensitive data.

What you will do
  • Administer and support Microsoft Entra ID, Active Directory, and Okta environments, including user lifecycle management, group administration, authentication services, directory synchronization, and access governance.
  • Design, implement, and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Passwordless Authentication, and Identity Protection capabilities across cloud and on-premises applications.
  • Manage Privileged Identity Management (PIM), Role-Based Access Control (RBAC), administrative role assignments, service accounts, and privileged access operations across Microsoft Azure, Entra ID, Okta, and GCP environments.
  • Configure and maintain application integrations utilizing SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, LDAP, Kerberos, and federation technologies to enable secure authentication and provisioning.
  • Support Google Cloud Platform (GCP) identity services, including Cloud Identity, IAM roles, service accounts, workload identity federation, and secure access to GCP resources and services.
  • Contribute to automation and workflow optimization using PowerShell, Microsoft Graph API, Terraform, Python, Okta Workflows, Azure Automation, and Infrastructure-as-Code practices to improve operational efficiency and governance.
  • Investigate and resolve complex identity, authentication, provisioning, authorization, and access-related incidents escalated from Service Desk, Infrastructure, Security Operations, and application support teams.
  • Participate in Identity Governance, compliance, audit readiness, security assessments, Proof-of-Concept initiatives, and continuous improvement efforts while supporting organizational requirements related to HIPAA, SOC2, NIST, and Zero Trust security frameworks.
  • Perform other duties as assigned.
What you need to succeed
  • Bachelor's degree in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field is preferred but not required; equivalent hands‑on experience may fully substitute for formal education.
  • 3–5 years of direct experience in Identity and Access Management (IAM), Cloud Identity, Directory Services, Access Management, or Security Engineering within enterprise environments.
  • Strong knowledge of identity and access management technologies including Microsoft Entra ID (Azure AD), Active Directory Domain Services, Microsoft Entra Connect/Cloud Sync, Azure RBAC, Okta Workforce Identity Cloud, Google Cloud IAM, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and Privileged Identity Management (PIM).
  • Demonstrated hands‑on expertise with enterprise authentication, federation, and identity integration technologies including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and LDAP.
  • Strong understanding of Identity and Access Management (IAM) concepts and best practices.
  • Expertise in authentication, authorization, federation, and identity governance.
  • Strong troubleshooting skills across identity, network, security, and cloud environments.
  • Ability to automate operational tasks using PowerShell, Python, Terraform, Azure CLI, and APIs.
  • Strong understanding of certificate-based authentication, PKI, and cryptographic concepts.
  • Ability to develop technical documentation, standards, SOPs, and architecture diagrams.
  • Strong collaboration and communication skills when working with Security, Infrastructure, Cloud, Application Development, and Compliance teams.
  • Ability to manage multiple priorities and deliver projects within established timelines.
  • Understanding of requirements for building and maintaining a secure identity environment.
  • Ability to identify opportunities for automation, process improvement, and AI‑assisted operational efficiencies.
The extras
  • Experience supporting hybrid and cloud identity environments, including Microsoft 365, Azure, Google Cloud, and enterprise SaaS application integrations.
  • Hands‑on experience with user provisioning, identity synchronization, federation services, access requests, account lifecycle automation, and governance processes.
  • Experience troubleshooting authentication, authorization, federation, conditional access, MFA, and identity synchronization issues across on‑premises and cloud environments.
  • Knowledge of security best practices related to identity protection, privileged access management, Zero Trust architecture, identity risk management, and compliance requirements.
  • Experience supporting identity‑related migrations, platform upgrades, cloud adoption initiatives, and enterprise access management transformations.
  • Advanced knowledge of Microsoft Entra Identity Governance and Access Reviews.
  • Experience with Okta Identity Engine and Okta Workflows.
  • Proficiency with Microsoft Graph API, Azure Automation, and Azure Landing Zone identity controls.
  • Experience with Terraform and Infrastructure‑as‑Code practices.
  • Experience securing cloud‑native applications and APIs.
  • Familiarity with ServiceNow integrations and IAM workflow automation.
  • Knowledge of CyberArk, Delinea, or other PAM solutions.
  • Experience supporting regulated healthcare or financial environments.
  • Understanding of HIPAA, SOC2, NIST, CIS Controls, and cybersecurity frameworks.
  • Familiarity with security monitoring, audit logging, and incident response processes.
  • Microsoft Certified in any of the following: Identity and Access Administrator Associate (SC‑300); Azure Administrator Associate (AZ‑104), Azure Solutions Architect Expert (AZ‑305), Cybersecurity Architect Expert (SC‑100) ITIL Foundation Certification Any other Identity Certification e.g. Okta.
Location

Location: BCBSRI is headquartered in downtown Providence, conveniently located near the train station and bus terminal.

In-office: onsite 5 days per week Hybrid: onsite 2-4 days per week Remote: onsite 0-1 days per week.

  • Arizona
  • Connecticut
  • Florida
  • Georgia
  • Louisiana
  • Massachusetts
  • North Carolina
  • Oklahoma
  • Rhode Island
  • South Carolina
  • Texas
  • Virginia

BCBSRI is an equal opportunity employer.

The law requires an employer to post notices describing the Federal laws. Please visit www.eeoc.gov/know-your-rights-workplace-discrimination-illegal to view the "Know Your Rights" poster.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity & Access Management Engineer
Identity & Access Management Engineer

Blue Cross & Blue Shield of Rhode Island • United States

Hybrid
USD 83,000 - 125,000
Remote and hybrid options
Paid time off
Tuition reimbursement
+4
Lead Transformation Discovery Analyst
Lead Transformation Discovery Analyst

Blue Cross & Blue Shield of Rhode Island • Providence (RI), Northern (KY)

Hybrid
USD 117,000 - 187,000
Tuition reimbursement
Student-loan repayment assistance
Paid time off
+2
Senior Data Platform Engineer
Senior Data Platform Engineer

Blue Cross & Blue Shield of Rhode Island • United States

Hybrid
USD 102,000 - 164,000
Remote/hybrid options
Tuition reimbursement
Health, dental, and vision insurance
+1
Senior Data Platform Engineer
Senior Data Platform Engineer

Blue Cross & Blue Shield of Rhode Island • Providence (RI), Northern (KY)

Hybrid
USD 102,000 - 164,000
Health insurance
Dental & Vision insurance
Tuition reimbursement
+2
Lead Transformation Discovery Analyst
Lead Transformation Discovery Analyst

Blue Cross & Blue Shield of Rhode Island • United States

Hybrid
USD 117,000 - 187,000
Senior Business Transformation Product Manager - Utilization Management
Senior Business Transformation Product Manager - Utilization Management

Blue Cross & Blue Shield of Rhode Island • Providence (RI)

Hybrid
USD 102,000 - 164,000
Tuition reimbursement
Health insurance
Dental insurance
+4
Senior Business Transformation Product Manager - Total Cost of Care/Medical Economics
Senior Business Transformation Product Manager - Total Cost of Care/Medical Economics

Blue Cross & Blue Shield of Rhode Island • Providence (RI)

Hybrid
USD 102,000 - 164,000
Remote and hybrid opportunities
Tuition reimbursement
Student-loan repayment assistance
+4
Temporary Case Specialist- Grievance & Appeals Unit
Temporary Case Specialist- Grievance & Appeals Unit

Blue Cross & Blue Shield of Rhode Island • United States

Hybrid
USD 60,000 - 90,000
Flexible work arrangements (remote/hy‑
Paid time off
Tuition reimbursement
+5
Senior EPMO Project Manager
Senior EPMO Project Manager

Blue Cross & Blue Shield of Rhode Island • United States

Hybrid
USD 102,000 - 164,000
Flexible work arrangements (remote &hy
Paid time off
Tuition reimbursement
+5
Senior EPMO Project Manager
Senior EPMO Project Manager

Blue Cross & Blue Shield of Rhode Island • Providence (RI), Northern (KY)

Hybrid
USD 102,000 - 164,000
Flexible work arrangements (remote &hy
Tuition reimbursement
Paid time off
+3