Principal IAM Engineer

employerdirecthealthcare

Dallas (TX)

Hybrid

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lantern, the specialty care platform, is hiring a Principal IAM Engineer to own the identity control plane end to end within a security-first, open-by-default environment. You will set identity standards, automate controls, and ensure secure access to PHI across the platform.

You will report to the CISO and collaborate with IAM, Platform, Cloud Engineering, and Service Delivery teams. This is a hands-on role with a path to leadership as the identity function scales.

Responsibilities

  • Own the identity lifecycle: joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models (RBAC/ABAC).
  • Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time elevation.

Job description

About Lantern

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com.

Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC 2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.

This Principal IAM Engineer is a senior level, individual-contributor role and the technical authority for identity at Lantern. In an organization where the security perimeter is effectively identity, you will own the identity control plane end to end, and you will determine who can reach PHI and under what conditions. You will set the identity standard, build the automation behind it, and hold the verification bar that other teams operate against.

You will report to the CISO and partner closely with our IAM engineer and with the platform, cloud, and service delivery teams that execute alongside you. This is a hands-on principal seat, not a people-management role today, with a clear path to expand into a leadership role as the identity function grows.

Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is "yes, safely," because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent.

Location: Hybrid - at least 3 days/wk in our Dallas, TX offices

Responsibilities:
  • Own the identity lifecycle: joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models (RBAC/ABAC), with deprovisioning verified against an entitlement inventory rather than assumed.
  • Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time (JIT) elevation, and enforcement confirmed on every access path rather than only saved.
  • Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
  • Own secrets and non-human identity, including API keys, service accounts, and workload identity, and maintain an owner registry for them.
  • Own key access governance and separation of duties in a model where another team operates the key management system.
  • Own identity automation and identity-as-code, building lifecycle and access controls as reviewable, version-controlled infrastructure (Terraform and policy-as-code) rather than manual configuration.
  • Own the identity-verification standard the service desk follows for password resets, MFA resets, and device enrollment. This is a hands-on control point, because helpdesk-initiated resets are a leading account-takeover vector.
Key Deliverables in Your First Year:
  • Conditional Access enforced by default on PHI-facing applications, with enforcement verified.
  • Automated joiner, mover, and leaver provisioning and deprovisioning that meets its SLA every time.
  • A secrets golden path, with vaulted secrets, none in code, and a populated key-to-owner registry.
  • Strong, phishing-resistant MFA coverage on privileged accounts.
  • Documented runbooks and depth across the control plane, so no critical control depends on a single person.
How You Will Work:

You will set standards that partner teams execute. Service Delivery performs provisioning tasks and resets against the verification bar you own. Cloud Engineering carries cloud access, workload identity, and key-management operations, with key access governed by you. HR events are the sole trigger for lifecycle changes. The Governance, Risk & Compliance team independently attests to the entitlements you produce, and access certification deliberately sits outside this role so that the team reviewing access is not the team granting it. Holding those boundaries cleanly is central to the job.

Requirements:
  • Eight or more years in identity and access management, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishi
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal IAM Engineer
Principal IAM Engineer

Employer Direct Healthcare • Dallas (TX)

Hybrid
USD 140,000 - 210,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Principal IAM Engineer
Principal IAM Engineer

Lantern • Dallas (TX)

Hybrid
USD 150,000 - 230,000
Medical Insurance
Vision Insurance
Disability Insurance
+3
Senior Identity & Access Architect
Senior Identity & Access Architect

Employer Direct Healthcare • Dallas (TX)

Hybrid
USD 140,000 - 210,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Principal IAM Engineer: Identity Control Plane Leader
Principal IAM Engineer: Identity Control Plane Leader

employerdirecthealthcare • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Director, Application & AI Security
Director, Application & AI Security

employerdirecthealthcare • Dallas (TX)

Hybrid
USD 180,000 - 240,000
Director, Application & AI Security
Director, Application & AI Security

Employer Direct Healthcare • Dallas (TX)

Hybrid
USD 180,000 - 290,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Senior IAM Architect — Zero-Trust & Automation
Senior IAM Architect — Zero-Trust & Automation

Lantern • Dallas (TX)

Hybrid
USD 150,000 - 230,000
Medical Insurance
Vision Insurance
Disability Insurance
+3
Director, Application & AI Security
Director, Application & AI Security

Lantern • Dallas (TX)

On-site
USD 180,000 - 280,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Senior Network Security Engineer
Senior Network Security Engineer

Lantern • Dallas (TX)

Hybrid
USD 140,000 - 190,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Principal, Identity Management
Principal, Identity Management

itron • Austin (TX)

On-site
USD 150,000 - 230,000