Назад
Company hidden
4 дня назад

Principal IAM Engineer (Microsoft Entra ID)

175 000 - 225 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal IAM Engineer (Microsoft Entra ID): Owns and automates Lantern’s identity control plane for regulated healthcare systems, with an accent on Conditional Access, phishing-resistant MFA, lifecycle automation, federation, secrets, and privileged access. Focus on verifying enforcement across every access path, building identity-as-code with Terraform and policy-as-code, and preventing recurring access-control failures.

Location: New York, NY; hybrid with at least 3 days per week in the office

Salary: $175,000–$225,000 annually, plus an annual bonus

Company

hirify.global is a specialty care platform connecting people with high-quality, affordable care through a nationwide network of specialists and dedicated care teams.

What you will do

  • Own the identity lifecycle, including automated joiner, mover, and leaver provisioning and deprovisioning across cloud, SaaS, and privileged systems.
  • Design and enforce Conditional Access, phishing-resistant MFA, privileged access, least privilege, and just-in-time elevation on a Zero Trust model.
  • Manage directory and federation capabilities across Microsoft Entra ID, SSO, SAML, OIDC, and OAuth2.
  • Govern secrets and non-human identities, including API keys, service accounts, workload identities, and key ownership registries.
  • Build identity automation and identity-as-code using Terraform, policy-as-code, scripting, and source-controlled workflows.
  • Set identity-verification standards for password resets, MFA resets, and device enrollment while partnering with security, cloud, platform, service delivery, HR, and GRC teams.

Requirements

  • At least 8 years of IAM experience, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID experience with Conditional Access, phishing-resistant MFA, SSO, federation, and enforcement verification across all access paths.
  • Experience with RBAC/ABAC lifecycle automation, IGA, PAM, Zero Trust, least privilege, JIT access, and adaptive access controls.
  • Automation and scripting skills with PowerShell, Python, or similar; experience with Terraform, policy-as-code, and source-controlled change management.
  • Experience managing secrets, API keys, service accounts, workload identities, key access governance, and separation of duties.
  • Bachelor’s degree in a relevant field or equivalent professional experience, with the ability to act as a technical authority without formal people-management responsibility.

Nice to have

  • Healthcare or other regulated-environment experience involving protected health information.
  • Experience with Saviynt, PAM, Azure PIM, Keeper, passkeys, FIDO2, or phishing-resistant authenticators.
  • Experience remediating Conditional Access or deprovisioning failures and implementing structural fixes.
  • Microsoft Identity and Access Administrator certification, CIMP, or equivalent.
  • Experience expanding a technical scope into a broader leadership remit.

Culture & Benefits

  • Open-by-default, secure-by-design security philosophy with automated and transparent guardrails.
  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance and life insurance.
  • 401(k) with company match, flexible time off, and paid parental leave.
  • Collaborative environment centered on inclusion, integrity, customer focus, and practical execution.

Hiring process

  • Submit an application and connect with the Talent Acquisition team to discuss the opportunity and next steps.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →