Назад
Company hidden
13 часов Π½Π°Π·Π°Π΄

Principal IAM Engineer (Cybersecurity)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
hybrid
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
US
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Principal IAM Engineer (Cybersecurity): Owning and automating Lantern’s identity control plane for regulated healthcare systems with an accent on Microsoft Entra ID, Conditional Access, phishing-resistant MFA, lifecycle governance, and privileged access. Focus on verifying enforcement across every access path, building identity-as-code and secrets golden paths, and solving structural deprovisioning and account-takeover risks.

Location: Dallas, Texas, United States β€” hybrid, with at least 3 days per week in the office

Company

hirify.global is a specialty care platform connecting members with high-quality specialist care while operating in a regulated healthcare environment handling protected health information at scale.

What you will do

  • Own the identity lifecycle, including automated joiner, mover, and leaver provisioning and deprovisioning using RBAC and ABAC models.
  • Design and enforce Conditional Access, phishing-resistant MFA, privileged access, least privilege, and just-in-time elevation using a Zero Trust model.
  • Manage directory and federation capabilities across Microsoft Entra ID, SSO, SAML, OIDC, and OAuth2.
  • Govern secrets and non-human identities, including API keys, service accounts, workload identity, and key-to-owner registries.
  • Build identity automation, identity-as-code, and policy-as-code with Terraform and source-controlled workflows.
  • Set identity-verification standards for password resets, MFA resets, and device enrollment while partnering with platform, cloud, service delivery, HR, and GRC teams.

Requirements

  • 8+ years of experience in identity and access management, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering experience, including Conditional Access, phishing-resistant MFA, SSO, and SAML, OIDC, and OAuth2 federation.
  • Experience with identity lifecycle automation, IGA, PAM, RBAC/ABAC, Zero Trust, least privilege, JIT access, and risk-based controls.
  • Automation and scripting experience with PowerShell, Python, or similar tools, plus custom connector development.
  • Experience with Terraform, identity-as-code, policy-as-code, and source-controlled change management.
  • Bachelor’s degree in a relevant field or equivalent professional experience, with the ability to act as a technical authority without formal people-management responsibility.

Nice to have

  • Healthcare or other regulated-environment experience involving PHI or comparable sensitive data.
  • Hands-on experience with Saviynt, PAM, Azure PIM, Keeper, or comparable platforms.
  • Experience with passkeys, FIDO2, phishing-resistant authenticators, or NIST SP 800-63 Rev. 4.
  • Microsoft Identity and Access Administrator certification, CIMP, or equivalent.
  • Experience expanding a technical function into a broader leadership remit.

Culture & Benefits

  • Open-by-default, secure-by-design security philosophy focused on automated and transparent guardrails.
  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance and life insurance.
  • 401(k) with company match.
  • Flexible time off and paid parental leave.
  • Collaborative environment emphasizing verified enforcement, automation, structural fixes, clear boundaries, and independent governance.

Hiring process

  • Apply for the role; a Talent Acquisition team member will contact candidates to discuss the interview process.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’