Principal IAM Engineer (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: Dallas, Texas, United States β hybrid, with at least 3 days per week in the office
Company
is a specialty care platform connecting members with high-quality specialist care while operating in a regulated healthcare environment handling protected health information at scale.
What you will do
- Own the identity lifecycle, including automated joiner, mover, and leaver provisioning and deprovisioning using RBAC and ABAC models.
- Design and enforce Conditional Access, phishing-resistant MFA, privileged access, least privilege, and just-in-time elevation using a Zero Trust model.
- Manage directory and federation capabilities across Microsoft Entra ID, SSO, SAML, OIDC, and OAuth2.
- Govern secrets and non-human identities, including API keys, service accounts, workload identity, and key-to-owner registries.
- Build identity automation, identity-as-code, and policy-as-code with Terraform and source-controlled workflows.
- Set identity-verification standards for password resets, MFA resets, and device enrollment while partnering with platform, cloud, service delivery, HR, and GRC teams.
Requirements
- 8+ years of experience in identity and access management, including principal- or staff-level ownership of an identity control plane.
- Deep Microsoft Entra ID engineering experience, including Conditional Access, phishing-resistant MFA, SSO, and SAML, OIDC, and OAuth2 federation.
- Experience with identity lifecycle automation, IGA, PAM, RBAC/ABAC, Zero Trust, least privilege, JIT access, and risk-based controls.
- Automation and scripting experience with PowerShell, Python, or similar tools, plus custom connector development.
- Experience with Terraform, identity-as-code, policy-as-code, and source-controlled change management.
- Bachelorβs degree in a relevant field or equivalent professional experience, with the ability to act as a technical authority without formal people-management responsibility.
Nice to have
- Healthcare or other regulated-environment experience involving PHI or comparable sensitive data.
- Hands-on experience with Saviynt, PAM, Azure PIM, Keeper, or comparable platforms.
- Experience with passkeys, FIDO2, phishing-resistant authenticators, or NIST SP 800-63 Rev. 4.
- Microsoft Identity and Access Administrator certification, CIMP, or equivalent.
- Experience expanding a technical function into a broader leadership remit.
Culture & Benefits
- Open-by-default, secure-by-design security philosophy focused on automated and transparent guardrails.
- Medical, dental, and vision insurance.
- Short- and long-term disability insurance and life insurance.
- 401(k) with company match.
- Flexible time off and paid parental leave.
- Collaborative environment emphasizing verified enforcement, automation, structural fixes, clear boundaries, and independent governance.
Hiring process
- Apply for the role; a Talent Acquisition team member will contact candidates to discuss the interview process.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β