Principal Cloud Engineer, Technology & Digital, FT, 8:30A - 5P

Baptist Health

Coral Gables (FL)

On-site

USD 122,475 - 159,217

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Baptist Health is seeking a Principal Cloud IAM Engineer to design, implement, and govern a multi-cloud IAM ecosystem. You will be the primary architect for cloud security boundaries, ensuring least-privilege access across cloud environments and productivity suites.

Responsibilities include leading IAM architecture, SSO across AWS, Azure Entra, and Google Workspace, and defining an enterprise-wide delegation model. Strong IaC and scripting skills, HIPAA/compliance experience preferred.

Qualifications

  • Master's degree in computer science or related fields.
  • 10+ years of dedicated cloud engineering experience, with at least 5 years focused on Cloud IAM.
  • Hands-on administration with AWS IAM Identity Center, Azure Entra ID, Google Workspace.
  • Experience designing IAM delegation models for mid-to-large engineering organizations.
  • Deep understanding of SAML 2.0, OAuth 2.0, and OIDC.

Responsibilities

  • Multi-Cloud IAM Architecture & Administration.
  • AWS IAM Identity Center: Architect and manage centralized SSO, permission sets, and multi-account access.
  • Azure Entra ID: Configure Enterprise Apps, App Registrations, conditional access policies, and group management.
  • Google Workspace: Govern admin controls, OUs, third-party app permissions, and API scopes.
  • IAM Delegation Model: Define an enterprise-wide delegation model between central security, platform, and product squads.
  • Access Control Patterns: Implement RBAC and ABAC using tags and directory attributes.
  • Guardrails at Scale: Design and enforce SCPs, Management Group policies, and Organization Policies.
  • Federation, Provisioning & Automation: SSO, SCIM-based provisioning, and automation pipelines.
  • IaC: Treat IAM as code using Terraform or OpenTofu.
  • Automation Scripting: Write scripts (Python, Go, Bash) for audits and cleanup.

Skills

Cloud IAM
Identity Federation
RBAC/ABAC
SAML 2.0/OIDC/OAuth 2.0
Security Best Practices

Education

Masters degree in computer science or related fields

Tools

Terraform
OpenTofu
Python
Go
Bash

Job description

Baptist Health is the region's largest not-for-profit healthcare organization, with 12 hospitals, over 29,000 employees, 4,500 physicians and 200 outpatient centers, urgent care facilities and physician practices across Miami-Dade, Monroe, Broward and Palm Beach counties. With internationally renowned centers of excellence in cancer, cardiovascular care, orthopedics and sports medicine, and neurosciences, Baptist Health is supported by philanthropy and driven by its faith-based mission of medical excellence. For 26 years, we've been named one of Fortune's 100 Best Companies to Work For, and in the 2025-2026 U.S. News & World Report Best Hospital Rankings, Baptist Health was the most awarded healthcare system in South Florida, earning 63 high‑performing honors.

Benefits
  • Career growth and development opportunities, with clear pathways and ongoing support
  • Comprehensive health and wellness resources that go beyond traditional benefits
  • A wellness program that can help employees eliminate their medical plan deductible, reducing out‑of‑pocket healthcare costs
  • Tuition reimbursement to support continued learning and advancement
  • And so much more
Description

We are seeking a Principal Cloud IAM Engineer to design, implement, and govern our multi‑cloud identity and access management (IAM) ecosystem. In this role, you will be the primary architect of our cloud security boundaries, ensuring that our workforce and automated systems have precise, least‑privilege access across our cloud environments and productivity suites.

  • Multi‑Cloud IAM Architecture & Administration
  • AWS IAM Identity Center: Architect and manage centralized single sign‑on (SSO), permission sets, and multi‑account access strategies across AWS Organizations.
  • Azure Entra ID: Configure and maintain Enterprise Applications, App Registrations, conditional access policies, and group management.
  • Google Workspace: Govern administrative controls, organizational units (OUs), third‑party app permissions, and API scopes.
  • IAM Delegation Model & Policy Design
  • Delegation Design: Define and roll out an enterprise‑wide IAM delegation model, establishing clear boundaries between central security teams, platform engineering, and product development squads.
  • Access Control Patterns: Implement Role‑Based Access Control (RBAC) and Attribute‑Based Access Control (ABAC) using resource tags, AWS Session Tags, or Azure directory attributes.
  • Guardrails at Scale: Design and enforce Service Control Policies (SCPs) in AWS, Management Group policies in Azure, and Organization Policies in GCP to limit the blast radius of delegated privileges.
  • Federation, Provisioning & Automation
  • SSO & Federation: Implement and troubleshoot SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0 integrations between identity providers (IdPs) and cloud services.
  • Automated Provisioning (SCIM): Configure SCIM‑based user provisioning pipelines to automate user lifecycle management (joiners, movers, leavers) from Google Workspace or Entra ID into cloud environments.
  • Infrastructure as Code (IaC): Treat IAM as code. Author, test, and deploy IAM roles, policies, and directory group mappings using tools like Terraform or OpenTofu.
  • Automation Scripting: Write utility scripts (Python, Go, or Bash) to automate access audits, discover unused credentials, and clean up over‑privileged roles.
  • Governance, Compliance & Auditing
  • Access Reviews: Establish continuous monitoring and automated periodic access reviews (Attestation) to satisfy industry compliance frameworks (e.g., SOC 2, HIPAA, ISO 27001).
  • Audit Trail Analysis: Monitor and analyze identity activity logs (AWS CloudTrail, Azure Activity Logs, Google Workspace Audit logs) to detect potential credential abuse, privilege escalations, or policy violations.

Estimated salary range for this position is $122 475.25 – $159 217.83 / year depending on experience.

Qualifications
  • Master's degree in computer science or related fields
  • Experience: 10+ years of dedicated experience in cloud engineering, with at least 5 years focused heavily on Cloud IAM
  • Identity Platform Expertise: Proven, hands‑on administration experience with:
  • AWS IAM Identity Center (SSO configuration, Permission Sets, AWS Organizations integrations)
  • Azure Entra ID (Conditional Access, Directory Roles, Enterprise Apps)
  • Google Workspace (Directory Management, SSO integration, SAML/OIDC setup)
  • Architectural Experience: Experience designing and documenting an IAM delegation model for mid‑to‑large‑size engineering organizations
  • Federation Standards: Deep understanding of identity federation protocols: SAML 2.0, OAuth 2.0, and OIDC
Preferred & Expanded Qualifications
  • IaC Skills: Strong experience managing IAM configurations using Terraform or an equivalent infrastructure‑as‑code tool
  • Programming/Scripting: Proficiency in Python or Go for building custom IAM governance tools and integrations
  • Compliance Knowledge: Experience implementing least‑privilege frameworks in highly regulated environments (e.g., Healthcare/HIPAA, Finance/SOC 2)
  • Security Certifications: Certified Information Systems Security Professional (CISSP), AWS Certified Security – Specialty, or Microsoft Certified: Identity and Access Administrator Associate

Minimum Required Experience: 10 Years

EOE, including disability/vets

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud IAM Architect: Multi-Cloud Security & SSO
Senior Cloud IAM Architect: Multi-Cloud Security & SSO

Baptist Health • Coral Gables (FL)

On-site
USD 122,000 - 160,000
IAM Manager - NJ
IAM Manager - NJ

IT Accel, Inc. • Mount Laurel Township (NJ)

On-site
USD 140,000 - 190,000
Sr IAM Cloud Engineer
Sr IAM Cloud Engineer

HealthEquity • United States

On-site
USD 130,000 - 180,000
Identity and Access Management (IAM) Security Administration Senior Engineer (Infrastructure Ar[...]
Identity and Access Management (IAM) Security Administration Senior Engineer (Infrastructure Ar[...]

Bank of America • Washington

On-site
USD 120,000 - 150,000
Lead IAM Engineer
Lead IAM Engineer

Blue Cross and Blue Shield of Massachusetts, Inc. • Boston (MA)

On-site
USD 163,000 - 200,000
Paid time off
Medical insurance
Dental insurance
+2
Systems Engineer I - IAM
Systems Engineer I - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 104,000 - 113,000
Health, Dental, Vision, Life Insurance
Paid Time Off
401(k) and Profit-Sharing Plans
IAM Architect
IAM Architect

KTek Resourcing • Dallas (TX)

On-site
USD 120,000 - 150,000
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Platform Engineer - Identity & Access Management
Platform Engineer - Identity & Access Management

Winning Edge Solutions LLC • Navy (VA)

On-site
USD 80,000 - 120,000
Principal Security Access Engineer
Principal Security Access Engineer

HealthEquity, Inc. • United States

Remote
USD 150,000 - 210,000