Sr IAM Cloud Engineer

HealthEquity

United States

On-site

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HealthEquity seeks an accomplished IAM Cloud Security Engineer to design, secure, and operate AI-driven IAM systems across AWS, Azure, and GCP. You will implement robust authentication architectures, automate identity lifecycles, and ensure governance and compliance in cloud environments.

You will partner with cross‑functional teams to advance Zero Trust, secure AI workloads, and drive improvements in IAM controls through automation and AI-enabled tooling.

Qualifications

  • Bachelor’s degree or equivalent practical experience.
  • 8–10 years in IAM engineering, cloud security, or GenAI/ML engineering.
  • Experience with cloud platforms (Microsoft Entra ID, Okta, Azure, AWS, GCP) and IAM automation.
  • Experience automating identity lifecycle management and entitlement governance.
  • Experience applying automation or AI-enabled tools to IAM operations.

Responsibilities

  • Design, implement, and maintain IAM across multi-cloud environments (AWS, Azure, GCP).
  • Automate identity lifecycle management, provisioning, and deprovisioning.
  • Define secure IAM cloud access structures and standardize configurations.
  • Support Generative AI capabilities within IAM, including anomaly detection and remediation recommendations.
  • Collaborate with security teams to align IAM with governance and compliance.
  • Develop and maintain documentation, dashboards, KPIs, and reporting for IAM operations.

Skills

IAM Frameworks
Multi-Cloud
AWS
Azure
GCP
RBAC
PAM
MFA
KMS
WAF
Security Automation
GenAI Security

Education

Bachelor’s degree in computer science, information technology, cybersecurity, data science, or related field

Tools

Okta
Microsoft Entra ID
Azure
AWS
GCP

Job description

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview

How you can make a difference

Join our team as an IAM Cloud Security Engineer. This role combines expertise in Identity and Access Management (IAM), cloud security, and Generative AI (GenAI) to design, secure, and operate AI-driven systems in our cloud environments. This is a game-changing role driving innovation with AI to identify non-standard cloud access, standardize through remediation, and automate IAM cloud functions. Innovate with AI by leading the development of advanced tools that summarize complex issues and recommend remediation plans, while continuously refining automated and manual administration while reducing the need for human intervention. You will build and deploy cutting-edge AI agents using platforms like Azure and Langchain, creating intelligent systems that can autonomously detect anomalous activities. This role sits at the intersection of IAM engineering and IAM cloud security. It provides a unique opportunity to collaborate and lead cross-functional efforts with internal business and technical application owners, various lines of business within the organization, and governance and compliance teams by constantly evolving and maturing identity and access processes with the use of AI. As organizations adopt AI at scale in the cloud, securing both the infrastructure and the AI workloads is critical. This role ensures that identity, access, and security controls are embedded into AI/ML systems, protecting sensitive data, preventing unauthorized access, and maintaining compliance.

What you’ll be doing
  • Design, implement, and maintain IAM frameworks (SSO, MFA, RBAC, PAM) across multi-cloud environments (AWS, Azure, GCP). Harden cloud environments using IAM policies, KMS, WAF, GuardDuty, Defender for Cloud, and compliance tools. Automate identity lifecycle management, provisioning, and deprovisioning.
  • Define and standardize IAM cloud access structures and secure cloud configurations. Build detection pipelines, automate compliance checks, and integrate CEIM tools
  • Support the secure use of Generative AI capabilities within IAM environments, including use cases related to access analysis, anomaly detection, issue summarization, remediation recommendations, and operational workflow automation.
  • Contribute to the design, testing, and refinement of AI-enabled IAM tools, prompts, retrieval strategies, and automation workflows that improve detection of non-standard access and support governance activities.
  • Partner with senior engineers, architects, and security teams to ensure AI-enabled IAM solutions align with model governance, data protection, API security, access control, and compliance expectations.
  • Collaborate with the AI COE and AI Engineering team for best practices, technology, and AI support needs.
  • Support cloud non-human identity hygiene, including discovery, inventory review, ownership validation, credential and secret rotation support, stale or orphaned identity cleanup, privilege right-sizing, and key or policy review.
  • Strengthen authentication security by supporting modern authentication architecture, account fencing, reduction of legacy or non-standard authentication paths, and detection of risky sign‑in behavior.
  • Configure and maintain authentication and authorization controls to ensure secure access to internal, external, cloud, and hybrid systems.
  • Automate IAM processes and workflows using scripting, integrations, and approved tooling to improve consistency, reduce manual work, and strengthen control execution.
  • Define, implement, and support Conditional Access and adaptive access policies, including Microsoft Entra ID controls, to advance Zero Trust principles.
  • Support the modernization and migration of IAM capabilities across cloud environments, including access policy design, entitlement governance, identity federation, and integration between on‑premises and cloud systems.
  • Assess authentication and authorization baselines, identify non‑standard or risky access patterns, and support risk‑based remediation plans.
  • Support Cloud Infrastructure Entitlement Management and related cloud access governance activities, including visibility into permissions, excessive access, and entitlement risk.
  • Collaborate with internal teams, application owners, governance, audit, compliance, and business stakeholders to define access requirements, user roles, permissions, and remediation actions.
  • Develop and maintain documentation, procedures, dashboards, KPIs, KRIs, and reporting to support IAM operations, access governance, remediation tracking, and control effectiveness.
  • Stay current with IAM, cloud security, authentication, automation, AI security, and regulatory trends to continuously improve IAM practices and reduce risk.
What you will need to be successful
Education And Experience
  • Bachelor’s degree in computer science, information technology, cybersecurity, data science, or a related field, or equivalent practical experience.
  • 8‑10 years years in IAM engineering, cloud security, or GenAI/ML engineering.
  • Experience supporting IAM capabilities in cloud or hybrid environments, including Microsoft Entra ID, Okta, Azure, AWS, GCP, or similar platforms.
  • Experience implementing, supporting, or automating identity lifecycle management, access controls, authentication policies, and entitlement governance.
  • Experience applying automation, scripting, or AI-enabled tools to improve IAM operations, access governance, or security workflows preferred.
Specialized Knowledge, Skills, And Abilities
  • Strong knowledge
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)

Bank of America • Denver (CO)

On-site
USD 180,000 - 230,000
Senior Identity and Access Management (IAM) Consultant
Senior Identity and Access Management (IAM) Consultant

Jobtailor • Colorado

On-site
USD 140,000 - 210,000
Senior Identity and Access Management (IAM) Access Controls & Entitlement Specialist, Cloud Security
Senior Identity and Access Management (IAM) Access Controls & Entitlement Specialist, Cloud Security

Jobtailor • Massachusetts

On-site
USD 150,000 - 230,000
IAM Solutions Architect
IAM Solutions Architect

Compunnel, Inc. • Chicago (IL)

On-site
USD 120,000 - 160,000
AI-Driven IAM Architect for Cloud Identities
AI-Driven IAM Architect for Cloud Identities

Compunnel, Inc. • Chicago (IL)

On-site
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

National Black MBA Association • United States

On-site
USD 140,000 - 200,000
Discretionary incentive
Benefits eligible
Annual discretionary plan
Remote IAM Cloud Security Engineer (GenAI Innovator)
Remote IAM Cloud Security Engineer (GenAI Innovator)

United States Digital Space LLC • United States

Remote
USD 115,000 - 150,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000