Principal Security Access Engineer
HealthEquity · United States · $133K–$173K/yr
Financial Services · 1,001-5,000 employees
About the role
The Principal Security Access Engineer will design, implement, and manage identity and privileged access management systems for human and non-human identities. This role involves developing IAM strategies, governing AI agents, and providing technical leadership to the security team.
What they look for
Requirements
Candidates must have at least 5 years of IAM experience, including hands-on expertise with SailPoint ISC, BeyondTrust, and Microsoft Entra. A bachelor's degree in a related field or equivalent practical experience is required, along with strong analytical and communication skills.
Benefits
Full description
Our Mission
Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.
Overview
How you can make a difference
HealthEquity is seeking an experienced and highly motivated Principal IAM Security Access Engineer to join our Security & IT team. This role is critical to the design, implementation, and management of our identity, access, and privileged access management (IAM/PAM) systems — spanning human, non-employee, service, and AI agent identities. The ideal candidate has deep, hands-on experience with SailPoint Identity Security Cloud (ISC) and Non-Employee Risk Management (NERM), BeyondTrust, Microsoft Entra (including Conditional Access), and Silverfort, along with a strong point of view on how identity security must evolve to govern AI agents, non-human identities, and machine-to-machine access. This role requires a deep understanding of IAM principles, excellent problem-solving skills, and the ability to mentor and guide team members while exercising indirect leadership and influence across all levels of the organization.
What you’ll be doing
Engineering and Strategy:
- Implementation of robust IAM/PAM solutions using SailPoint Identity Security Cloud, BeyondTrust, Microsoft Entra, Silverfort, and other IAM tools/platforms.
- Help develop and maintain IAM strategies; including governance for AI agents, non-human identities (NHIs), and machine-to-machine access — that align with organizational goals and industry best practices.
- Function as a subject matter expert for IAM technologies and processes, including emerging practices for agentic AI identity, authorization, and lifecycle management.
- Clearly articulate strategic initiatives, gain buy-in, and establish a shared understanding with key decision makers at the leadership level.
System Management and Implementation:
- Manage the configuration and administration of SailPoint ISC (including NERM for non-employee identity risk), BeyondTrust, Microsoft Entra, and Silverfort.
- Design and manage Conditional Access policies within Microsoft Entra to enforce risk-based, adaptive access controls across users, devices, and workloads.
- Partner closely with the IAM Governance team to implement IAM policies, standards, and procedures using IAM & PAM tools and processes.
- Ensure seamless integration of IAM systems with applications, services, secrets management/vaulting platforms, and CI/CD pipelines.
- Implement governance models for AI agents and service accounts, including credential issuance, scoped permissions, rotation, and decommissioning.
- Drive timely execution of IAM & PAM initiatives in alignment with strategic and tactical plans.
AI and Agentic Identity Enablement:
- Establish identity and access frameworks for AI agents and autonomous workflows, ensuring least-privilege access, auditability, and policy enforcement equivalent to human identity controls.
- Evaluate and integrate secrets management solutions to secure credentials, API keys, and tokens used by AI agents, automations, and service-to-service connections.
- Assess and pilot AI-assisted capabilities within IAM tooling (e.g., SailPoint AI, Entra ID Protection risk signals, Silverfort risk analytics) to improve access certification accuracy, anomaly detection, and operational efficiency.
- Program Management Support:
- Help IAM projects go from initiation to completion, ensuring timely delivery and alignment with project goals.
- Coordinate with cross-functional teams, including IT, HR, Security, and business units, to gather requirements and ensure successful project outcomes.
- Manage project timelines and resources effectively.
Team Development:
- Provide indirect leadership and guidance to IAM engineers and other IAM team members.
- Conduct training sessions and workshops — including on AI/agentic identity risk — to enhance the skills and knowledge of the team.
- Foster the culture of continuous improvement and professional development within the IAM team.
Troubleshooting and Support:
- Provide advanced troubleshooting and support for IAM-related issues, including scripting/automation via APIs and PowerShell.
- Develop and maintain documentation for IAM processes, configurations, and troubleshooting procedures.
- Stay current with industry trends and emerging technologies, particularly around AI, agentic systems, and non-human identity security, to continually enhance the IAM landscape.
What you will need to be successful
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.
- Minimum of 5 years of experience in IAM, with at least 3 years in a senior or principal engineer role.
- Extensive, hands-on experience with SailPoint Identity Security Cloud (ISC); experience with Non-Employee Risk Management (NERM) strongly preferred.
- Strong understanding of Privileged Access Management (PAM) and hands-on experience with BeyondTrust.
- Proficiency with Microsoft Entra (formerly Azure AD), including Conditional Access policy design and administration.
- Zero Trust expertise with technologies such as Silverfort.
- Working knowledge of secrets management and vaulting platforms for securing credentials, keys, and tokens used by applications, service accounts, and automations.
- Familiarity with identity considerations for AI agents and non-human identities — authentication patterns, scoped authorization, credential lifecycle, and monitoring for agentic/automated access.
- Proficiency in scripting and automation (e.g., REST APIs, PowerShell) for IAM tasks.
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication and interpersonal skills, with the ability to work effectively with and influence stakeholders at all levels.
- Relevant certifications such as CISSP, CISM, or IAM-related certifications are highly desirable.
#LI-Remote
This is a remote position.
Salary Range
$133000.00 To $173000 / year Benefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.
Why work with HealthEquity
HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more.
You belong at HealthEquity!
HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.
HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.
At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.
As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.
HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visit HealthEquity Privacy.