Sr IAM Security Engineer
HealthEquity · United States · $115K–$150K/yr
Financial Services · 1,001-5,000 employees
About the role
Lead the design and implementation of robust IAM solutions while integrating GenAI-enabled tools to automate identity lifecycle processes and access governance. Collaborate with cross-functional teams to improve cloud identity hygiene, secrets management, and security compliance across the organization.
What they look for
Requirements
Requires a bachelor's degree or equivalent experience and over 10 years of experience in Information Security with a focus on IAM. Candidates must possess strong technical proficiency in Python, SQL, Azure, and AI-assisted development frameworks.
Benefits
Full description
Our Mission
Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.
Overview
How you can make a difference
Join our team as an Sr IAM Engineer and help design next-generation detection, prevention, automation, and governance capabilities for identity and access management, cybersecurity, and cloud identity operations. This role will drive innovation by building GenAI-enabled tools and AI agents that identify access patterns, detect anomalous activity, summarize complex issues, and recommend remediation before risk impacts the organization.
You will help advance IAM automation across core platforms including SailPoint Identity Security Cloud, Microsoft Entra, cloud identity services, and secrets management. The role will focus on improving access governance, application onboarding, identity lifecycle processes, access request support, secrets lifecycle visibility, and cloud identity hygiene through intelligent automation and data-driven insights.
This position provides an opportunity to collaborate with IAM engineering, cloud engineering, security, audit, compliance, application owners, and business stakeholders to mature identity and access processes while reducing manual effort and improving operational effectiveness.
What you’ll be doing
Leadership and Strategy
- Lead the design, implementation, and ongoing improvement of robust IAM solutions using SailPoint Identity Security Cloud, Microsoft Entra, Silverfort, and related IAM technologies.
- Maintain IAM strategies and roadmaps to ensure alignment with organizational goals, security requirements, regulatory expectations, and industry best practices.
- Function as a subject matter expert for IAM technologies, identity lifecycle processes, access governance, authentication controls, and enterprise IAM integrations.
- Clearly articulate IAM initiatives, technical recommendations, risks, and implementation considerations to stakeholders and decision makers at leadership levels.
- Identify opportunities to responsibly apply AI-assisted automation, analytics, and summaries to improve IAM operations, governance visibility, and decision support without replacing required engineer review or formal approval processes.
System Management, Implementation, and Automation
- Configure, administer, and support IAM platforms including SailPoint Identity Security Cloud, Microsoft Entra, Silverfort, and related identity services.
- Partner closely with the IAM Governance team to implement IAM policies, standards, procedures, controls, and workflows using enterprise IAM tools and processes.
- Ensure seamless integration of IAM systems with enterprise applications, cloud services, access request workflows, provisioning processes, and authentication services.
- Drive timely execution of IAM initiatives in alignment with strategic and tactical plans.
- Develop and support automation that improves access request support, lifecycle event processing, provisioning issue triage, certification support, source/application onboarding, and IAM operational reporting.
- Use scripting, APIs, platform reporting, logs, configuration exports, and identity datasets to identify issues, improve IAM processes, and recommend enhancements.
AI-Enabled IAM Engineering
- Utilize secure Generative AI technologies and AI-assisted tools in enterprise IAM environments to support identity administration, access governance, authentication analysis, authorization review, and operational efficiency.
- Design, build, and deploy AI solutions that enhance IAM administration, governance, provisioning, authentication, and access management capabilities.
- Develop or configure retrieval-augmented tools, intelligent summaries, or AI-assisted workflows that help answer IAM queries, summarize observations, identify access patterns, and recommend potential remediation actions for engineer review.
- Refine prompts, retrieval strategies, and supporting data structures to improve the quality and precision of AI-assisted IAM insights, including identification of non-standard access, configuration issues, access model gaps, and governance opportunities.
- Support AI-assisted use cases for SailPoint Identity Security Cloud, including access request insights, entitlement cleanup, role and access model analysis, certification support, source/application onboarding, and governance configuration review.
- Support AI-assisted workflows for Microsoft Entra and related cloud identity services, including enterprise application review, SSO/SCIM validation, conditional access analysis, authentication method insights, MFA/passkey review, app registration analysis, and cloud identity hygiene.
- Apply appropriate judgment regarding AI model security, prompt engineering risks, data handling, review requirements, and mitigation techniques when using AI tools in IAM environments.
- Collaborate with the AI COE and AI Engineering team for best practices, technology, and AI support needs.
Security, Compliance, and Governance
- Monitor IAM systems for security vulnerabilities, configuration issues, anomalous access patterns, and compliance with relevant regulations and internal standards.
- Conduct regular IAM security audits, access reviews, assessments, and control validation activities, and implement corrective actions as needed.
- Collaborate with compliance teams, internal audit, enterprise risk management, security, and IAM Governance to ensure IAM processes meet regulatory requirements and internal control expectations.
- Partner with functional owners, business stakeholders, and technical teams to develop reporting, KPIs, KRIs, and data-driven insights related to access governance, access hygiene, provisioning, authentication, and identity lifecycle processes.
What you will need to be successful
Education and Experience:
- Bachelor’s degree, or the equivalent years related experience required.
- 10+ years of experience in Information Security, specifically in IAM.
- Experience leveraging automation, analytics, AI-assisted capabilities, or emerging technologies within cybersecurity, IAM, or cloud environments.
- Experience using scripting, APIs, reporting tools, and automation technologies to improve operational efficiency and effectiveness.
Specialized Knowledge, Skills, and Abilities:
- Familiarity with secure implementation and governance of AI-enabled solutions in enterprise environments.
- Ability to evaluate emerging technologies and apply them appropriately to business and security challenges.
- Proficiency in Python, SQL, Azure, OpenAI and Anthropic (Claude) frameworks, Langchain, and retrieval-augmented generation patterns.
- Experience with AI development lifecycle (e.g. Claude.code) using skills, commands, and sub-agents
- Knowledge of Model Context Protocol, Agent-to-Agent Protocol, and AI agent design patterns.
- Strong understanding of IAM concepts, including lifecycle management, access requests, certifications, and entitlement management.
- Experience with or working knowledge of SailPoint ISC, including identity profiles, sources, applications, access profiles, roles, dimensions, lifecycle states, certifications, workflows, and governance reporting.
- Working knowledge of Microsoft Entra identity services, including enterprise applications, SSO, SCIM provisioning, conditional access, authentication methods, MFA, passkeys, app registrations, service principals, and cloud identity governance.
- Experience with cloud identity engineering tasks in Azure or Microsoft Entra environments, including configuration review, automation, policy analysis, and integration support.
- Experience with secrets management concepts and platforms such as HashiCorp Vault, including secrets lifecycle, access policies, vault paths, ownership, rotation, privileged access, and secure application integration patterns.
- Ability to work with APIs, logs, configuration exports, identity datasets, access models, and platform reporting data to identify issues and recommend improvements.
- Ability to partner with IAM engineering, cloud engineering, application owners, audit, compliance, security operations, infrastructure, and business stakeholders to translate identity and access challenges into actionable solutions.
- Excellent problem-solving skills and judgment, including the ability to distinguish AI-assisted recommendations from engineer-reviewed actions and changes requiring formal governance, change management, or audit validation.
Certifications, Licenses, Registrations:
Relevant certifications such as CISSP, CISM, or IAM-related certifications are highly desirable
#LI-Remote
This is a remote position.
Salary Range
$115000.00 To $149500 / year Benefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.
Why work with HealthEquity
HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more.
You belong at HealthEquity!
HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.
HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.
At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.
As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.
HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visit HealthEquity Privacy.