Principal IAM Engineer

Lantern

New York (NY)

Hybrid

USD 175,000 - 225,000

Full time

22 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
Disability Insurance
Life Insurance
401k with company match
Flexible Time Off
Paid Parental Leave

Job summary

Lantern in New York is seeking an accomplished Identity and Access Management leader to own the identity control plane, automation, and governance across Entra ID, SAML/OIDC, and OAuth2. You will implement RBAC/ABAC, define least-privilege access, and shape policy-as-code using Terraform while collaborating with security, cloud engineering, and HR events to keep PHI safe.

This hybrid role offers medical, dental, and 401k benefits, with a salary range of $175,000–$225,000 and annual bonus

Qualifications

  • 8+ years in identity and access management with ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering including CA, MFA, SSO, and federation across SAML/OIDC/OAuth2.
  • Identity lifecycle automation across cloud, SaaS, and privileged systems.
  • Zero Trust identity design with least-privilege and Just-in-Time access.
  • IGA platform engineering including privileged access management.
  • Automation and scripting to build lifecycle workflows and custom connectors.
  • Identity-as-code and policy-as-code using Terraform with GitHub.
  • Secrets and non-human identity management with an owner registry.
  • Key access governance with separation of duties when another team operates the key management system.
  • Technical authority for a function reporting to a CISO.
  • Bachelor’s degree or equivalent professional experience.

Responsibilities

  • Own the identity lifecycle provisioning from joiner to leaver, automated from RBAC/ABAC models.
  • Own access management, including Conditional Access and phishing-resistant MFA in a Zero Trust model.
  • Oversee directory and federation across Entra ID, SSO, SAML, OIDC, OAuth2.
  • Manage secrets and non-human identities with an owner registry.
  • Maintain key access governance with separation of duties in a split-key model.
  • Develop identity automation and identity-as-code with Terraform and policy-as-code.
  • Own the verification standards for password resets, MFA resets, and device enrollment.

Skills

Zero Trust
RBAC/ABAC
Just-in-time
Automation scripting
Policy-as-code
Identity governance
Technical leadership

Education

Bachelor’s degree in a relevant field

Tools

Microsoft Entra ID
Conditional Access
SAML
OIDC
OAuth2
Terraform
GitHub
Keeper
Saviynt PAM
Azure PIM

Job description

About Lantern

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation’s top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com.

Location: Hybrid - at least 3 days/wk in our NYC, NY offices

Responsibilities
  • Own the identity lifecycle: joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models (RBAC/ABAC), with deprovisioning verified against an entitlement inventory rather than assumed.
  • Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time (JIT) elevation, and enforcement confirmed on every access path rather than only saved.
  • Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
  • Own secrets and non-human identity, including API keys, service accounts, and workload identity, and maintain an owner registry for them.
  • Own key access governance and separation of duties in a model where another team operates the key management system.
  • Own identity automation and identity-as-code, building lifecycle and access controls as reviewable, version-controlled infrastructure (Terraform and policy-as-code) rather than manual configuration.
  • Own the identity-verification standard the service desk follows for password resets, MFA resets, and device enrollment. This is a hands-on control point, because helpdesk-initiated resets are a leading account-takeover vector.
Key Deliverables in Your First Year
  • Conditional Access enforced by default on PHI-facing applications, with enforcement verified.
  • Automated joiner, mover, and leaver provisioning and deprovisioning that meets its SLA every time.
  • A secrets golden path, with vaulted secrets, none in code, and a populated key-to-owner registry.
  • Strong, phishing-resistant MFA coverage on privileged accounts.
  • Documented runbooks and depth across the control plane, so no critical control depends on a single person.
How You Will Work

You will set standards that partner teams execute. Service Delivery performs provisioning tasks and resets against the verification bar you own. Cloud Engineering carries cloud access, workload identity, and key-management operations, with key access governed by you. HR events are the sole trigger for lifecycle changes. The Governance, Risk & Compliance team independently attests to the entitlements you produce, and access certification deliberately sits outside this role so that the team reviewing access is not the team granting it. Holding those boundaries cleanly is central to the job.

Requirements
  • A minimum of 8 years in identity and access management, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishing-resistant MFA, single sign-on, and federation across SAML, OIDC, and OAuth2, and verifying that enforcement takes effect across every access path, not only the expected one.
  • Identity lifecycle automation across cloud, SaaS, and privileged systems, with role- and attribute-based provisioning (RBAC/ABAC) and deprovisioning verified against an entitlement inventory.
  • Zero Trust identity design, including least-privilege, just-in-time (JIT) access, and risk-based or adaptive access controls.
  • Identity governance and administration (IGA) platform engineering, including privileged access management.
  • Automation and scripting (PowerShell, Python, or similar) to build lifecycle workflows and custom connectors.
  • Identity-as-code and policy-as-code practice, using Terraform with source-controlled change management (for example, GitHub).
  • Secrets and non-human identity (API keys, service accounts, workload identity), and maintaining an owner registry for them.
  • Key access governance and separation of duties in a model where another team operates the key management system.
  • The ability to act as the technical authority for a function without formal people-management authority, working directly to a CISO.
  • Bachelor’s degree in a relevant field, or equivalent professional experience.
Strong Candidates Will
  • Healthcare or another regulated environment where identity controls gate access to PHI.
  • Hands-on Saviynt with PAM, Azure PIM, and Keeper, or transferable depth in comparable platforms.
  • Experience remediating a Conditional Access enforcement gap or a deprovisioning failure, and making the structural change that prevented recurrence.
  • Passkeys and FIDO2, or phishing-resistant authenticator experience, aligned with NIST SP 800-63 Rev. 4.
  • Experience growing a technical scope into a broader leadership remit.
  • Microsoft Identity and Access Administrator certification, CIMP, or equivalent.
Who Thrives in This Role
  • Verified enforcement. You do not consider a control done until you have seen it working on every path.
  • Automation bias. You remove the manual step rather than documenting it more carefully.
  • Structural fixes. You solve the class of failure, not the instance.
  • Boundary clarity. You hold the standard with partner teams without taking over their execution.
  • Governance respect. You keep access certification independent rather than absorbing it.
Benefits
  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Short & Long Term Disability
  • Life Insurance
  • 401k with company match
  • Flexible Time Off
  • Paid Parental Leave

The salary range for this position is $175,000 - $225,000 annually, based on experience, skills, and qualifications. This position is also eligible for an annual bonus, separate from and in addition to the base salary range listed above. Lantern provides this range in good faith in compliance with New York's pay transparency requirements.

About You
  • You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins.
  • INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with.
  • You have the GRIT, drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas.
  • You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers aren’t just the individuals using your product. They are the driving factor in your motivation to make a change.
  • Integrity guides you in life. Focusing on the TRUTH vs. giving people the answers they want to hear.
  • You thrive in a Team Environment. Collaboration is key in innovation and creating change.

These pillars of LIGHT are a reminder to our team that we are making a difference by providing guidance and support in navigating the often complex and confusing landscape of healthcare. We hope that through this LIGHT, individuals can find their way to the best care, resources, and support they need to get back to life.

Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal IAM Engineer
Principal IAM Engineer

Lantern • Dallas (TX)

On-site
USD 150,000 - 230,000
Medical Insurance
Vision Insurance
Disability Insurance
+3
Director, Application & AI Security
Director, Application & AI Security

Lantern • New York (NY)

Hybrid
USD 200,000 - 275,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Director, Application & AI Security
Director, Application & AI Security

Lantern • Dallas (TX)

On-site
USD 180,000 - 280,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Member Services Supervisor
Member Services Supervisor

Socket.dev • Dallas (TX)

On-site
USD 70,000 - 90,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Director, Healthcare Economics
Director, Healthcare Economics

Lantern • Dallas (TX), New York (NY)

On-site
USD 230,000 - 250,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Infusion Care Specialist (LVN)
Infusion Care Specialist (LVN)

Lantern • Dallas (TX)

Hybrid
USD 75,000 - 85,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Senior Cloud Platform Engineer New Dallas, TX - Hybrid (3x in office/week)
Senior Cloud Platform Engineer New Dallas, TX - Hybrid (3x in office/week)

Lantern • Dallas (TX), Northern (KY)

On-site
USD 140,000 - 190,000
Medical Insurance
Vision Insurance
Short & Long Term Disability
+3
Client Success Manager
Client Success Manager

Lantern • Dallas (TX)

On-site
USD 90,000 - 130,000
Senior Cloud Platform Engineer
Senior Cloud Platform Engineer

Lantern • Dallas (TX)

Hybrid
USD 130,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Manager, Client Success (Emerging Market) New Dallas, TX - Hybrid (3x in office/week)
Manager, Client Success (Emerging Market) New Dallas, TX - Hybrid (3x in office/week)

Lantern • Dallas (TX), Northern (KY)

On-site
USD 100,000 - 120,000