Sr. Staff IAM Engineer

OpenLoop Health, Inc.

Northern (KY)

Hybrid

USD 180,000 - 240,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision plans
Flexible PTO
401(k) + Company Match

Job summary

OpenLoop Health is hiring a Sr. Staff IAM Engineer(Architect) to be the design authority for identity across workforce, non-employee, customer, partner, non-human, and AI agent identities. You will write decisions, own Auth0 and Okta-related architectures, and drive consolidation of identities into a unified platform.

This hands-on role requires deep CIAM experience, architectural influence without direct authority, and the ability to communicate tradeoffs to staff engineers and CISOs alike.

Qualifications

  • 8+ years in identity and access management, security engineering, or platform architecture.
  • Hands-on CIAM platform experience, ideally on Auth0, including tenant and organization modelling.
  • Strong command of federation and authentication protocols: SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, FIDO2.
  • Enterprise workforce IdP architecture experience, on Okta or equivalent.
  • Demonstrated ability to set architectural direction and get engineering teams to adopt it without direct authority.
  • Clear written communication, including architecture decision records and reference designs.

Responsibilities

  • Own the target-state identity architecture across workforce, non-employee, external, non-human, and AI identity types, and set the standards and decision records.
  • Own our Auth0 customer identity architecture end to end, including tenant and organization modelling, MFA, and m-to-m authentication.
  • Keep the customer and patient identity plane separate from the workforce plane and define interfaces for external/partner identities.
  • Own the architecture for consolidating remaining authentication paths onto a single workforce IdP.
  • Design SSO, SCIM provisioning, and automated deprovisioning patterns with audit evidence.
  • Define federation and directory architecture across Okta, Entra ID, AWS, and GCP.
  • Build Identity Security Posture Management and extend the posture warehouse and remediation engine.
  • Partner with Security Operations to design identity threat detection into SIEM.
  • Design access controls that satisfy HIPAA, HITRUST, and SOC 2 requirements.
  • Serve as the design authority between identity risk and remediation teams.

Skills

IAM architecture
Hands-on architect
Written communication

Tools

Auth0
Okta
SailPoint ISC
Britive
Terraform
Entra ID

Job description

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About The Role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Identity and Access Management team governs how every person, partner, and system proves who they are and what they can reach.

We are hiring a Sr. Staff IAM Engineer(Architect) to be the design authority for identity across the company: workforce, non‑employee, customer, partner, non‑human, and AI agent.

That last one is not filler. Service accounts and AI agents are on track to outnumber the people we govern, and very few companies have a real architecture for them yet. You would own ours.

The platforms are chosen and in flight. Okta is our workforce IdP. SailPoint ISC and NERM are deploying for identity governance and non‑employee records. Britive is deploying for privileged just‑in‑time access. Auth0 is our customer identity platform, procured with machine‑to‑machine flows in production and the interactive login experience in active build. iam-ops-hub, our identity posture and remediation platform, is built in house and deployed. What we do not have is a single design authority tying them together. Architecture currently gets decided project by project, under delivery pressure. This role exists to change that.

This is a hands‑on architecture role, and we mean that concretely. Expect to write Auth0 Actions, Okta Workflows, and Terraform, and to query the posture warehouse yourself. Identity controls here carry HIPAA, HITRUST, and SOC 2 weight. The person who does well in this role is comfortable in ambiguity, writes decisions down, and can explain a design tradeoff to a staff engineer and to a CISO in the same week.

What You’ll Do:
  • Own the target‑state identity architecture across workforce, non‑employee, external, non‑human, and AI agent identity types, and set the standards, reference patterns, and decision records that make platform choices consistent rather than improvised per project.

  • Own our Auth0 customer identity architecture end to end, including tenant and organization modelling, MFA and phishing‑resistant authentication, and machine‑to‑machine patterns, taking it from partially live to fully architected and governed across our external and partner use cases.

  • Keep the customer and patient identity plane deliberately separate from the workforce plane, define the interfaces where the two must meet, and design the external and partner identity models for third‑party developers and B2B customers.

  • Own the architecture for consolidating our remaining authentication paths onto a single workforce IdP, including the sequencing and patterns our engineers build against.

  • Design SSO, SCIM provisioning, and automated deprovisioning patterns for applications handling sensitive data, with audit evidence produced as a byproduct of the design rather than as a manual exercise.

  • Define the federation and directory architecture across Okta, Entra ID, AWS, and GCP, including subsidiary and acquisition integration patterns.

  • Build out Identity Security Posture Management, extending the posture warehouse and remediation engine we built in house, and define the metrics that tell us whether identity posture is actually improving.

  • Partner with Security Operations and Security Architecture to design identity threat detection and response into our existing SIEM rather than a parallel stack.

  • Design access controls that satisfy HIPAA, HITRUST, and SOC 2 requirements without adding manual overhead, and keep architecture documentation and control mappings current enough that supporting an audit is a lookup rather than a project.

  • Serve as the design authority between the function that surfaces identity risk and the function that builds, so that every finding has a clear architectural path to remediation.

Who You Are:
  • An architect who still builds. You would rather write the reference implementation than describe it.

  • A writer. You document decisions so they survive your absence, and you would rather be disagreed with in writing than agreed with in a hallway.

  • Comfortable owning direction without owning headcount, and effective at getting engineering teams to adopt your patterns because they are good, not because you outrank anyone.

  • Energized by finishing half‑built things. Much of this estate is in flight, not greenfield.

Required Qualifications
  • 8+ years in identity and access management, security engineering, or platform architecture, with at least 3 years at a staff, principal, or architect level.

  • Deep, hands‑on customer identity experience. You have designed and delivered a CIAM platform end to end, ideally on Auth0, including tenant and organization modelling, MFA, and machine‑to‑machine authentication.

  • Strong command of federation and authentication protocols: SAML, OIDC, OAuth 2.0, SCIM, WebAuthn and FIDO2.

  • Enterprise workforce IdP architecture experience, on Okta or equivalent, including migrations off legacy or fragmented authentication sources.

  • Demonstrated ability to set architectural direction and get engineering teams to adopt it without direct authority.

  • Clear written communication, including architecture decision records and reference designs.

Preferred Qualifications
  • Designing for HIPAA and PHI safeguards, or comparable regulated‑industry access requirements.

  • Identity governance depth: joiner‑mover‑leaver lifecycle, RBAC, access certification, segregation of duties. Experience with SailPoint ISC and NERM or comparable IGA and non‑employee lifecycle platforms.

  • Cloud PAM and zero standing privilege models, particularly Britive or similar just‑in‑time access tooling.

  • Cloud‑native identity across AWS, GCP, and Azure, including migrations off cloud‑provider user pools such as AWS Cognito, or off social and directory sign‑in such as Google Sign‑In.

  • Building Identity Security Posture Management or identity threat detection capability, including SIEM integration for identity telemetry.

  • Non‑human identity, service account governance, secrets management, or AI agent identity.

  • Infrastructure as code for identity, including Terraform.

  • HITRUST, SOC 2, or SOX access controls.

  • Certifications such as CISSP or CISSP‑ISSAP, CISM, TOGAF or SABSA, Okta Certified Consultant or Architect, Auth0, SailPoint, or a professional‑level cloud architect certification.

  • Digital health, telehealth, or another regulated high‑growth environment.

What Success Looks Like:
  • A target‑state identity architecture approved, published, and adopted, with decision records for every material choice.

  • Remarkably, this sentence says our customer identity architecture complete, and the interactive login plane delivered to production across external and partner use cases.
  • A published consolidation architecture that engineering builds against, with measurable movement of our application portfolio onto a single workforce IdP.

  • An Identity Security Posture Management baseline in production: metrics defined and instrumented, continuous drift alerting live, and the highest‑severity findings shrinking.

  • Audit evidence produced as a byproduct of design, with control mappings traceable directly to architecture documents.

Our Benefits

In addition, for salaried positions you would also be eligible for:

  • Medical, Dental, and Vision plans

  • Flexible Spending/Health Savings Accounts

  • Flexible PTO

  • 401(k) + Company Match

  • Life Insurance, Pet insurance, and more

Our Company

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Staff Security Engineer
Sr. Staff Security Engineer

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 170,000 - 260,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings
Flexible PTO
+2
Sr. Staff IAM Engineer
Sr. Staff IAM Engineer

Jobgether • United States

On-site
USD 180,000 - 230,000
Medical, dental, and vision insurance
FSA/HSA
Flexible PTO
+4
IT Platform Staff Product Manager
IT Platform Staff Product Manager

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 140,000 - 190,000
Staff Software Engineer (Tech Lead)
Staff Software Engineer (Tech Lead)

OpenLoop Health • United States

Hybrid
USD 180,000 - 230,000
M-series Macs
Linear
GitHub
+3
IT Platform Staff Product Manager
IT Platform Staff Product Manager

OpenLoop • United States

On-site
USD 140,000 - 190,000
Staff Software Engineer (Tech Lead)
Staff Software Engineer (Tech Lead)

OpenLoop Health, Inc. • United States

Hybrid
USD 180,000 - 260,000
Equity
Flexible Bay Area Hybrid
M-series Macs
Enterprise Applications Engineering Manager
Enterprise Applications Engineering Manager

OpenLoop Health, Inc. • United States

Hybrid
USD 120,000 - 150,000
Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match
Okta on Okta Identity Architect
Okta on Okta Identity Architect

Okta • Sydney Township (ND)

Hybrid
USD 150,000 - 210,000
Systems Engineer
Systems Engineer

WorkOS • San Francisco (CA)

Hybrid
USD 140,000 - 210,000
401k matching
Equity
Healthcare, dental and vision
+5
Staff Designer & Creative Technologist
Staff Designer & Creative Technologist

OpenLoop • United States

Remote
USD 90,000 - 140,000
Medical, Dental, Vision plans
Flexible Spending/Health Savings
Flexible PTO
+2