Lantern

Principal IAM Engineer

Lantern
Apply
2 hours ago
Dallas, TX, USAStaff+
H1B Sponsor

Responsibilities

  • Own automated joiner, mover, and leaver provisioning and deprovisioning across cloud, SaaS, and privileged systems using RBAC and ABAC models.
  • Own Conditional Access, phishing-resistant MFA, privileged access, Zero Trust controls, least privilege, just-in-time elevation, and enforcement verification across all access paths.
  • Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
  • Govern secrets and non-human identities, including API keys, service accounts, workload identity, vaulted secrets, and an identity owner registry.
  • Own key access governance and separation of duties while another team operates the key management system.
  • Build reviewable, version-controlled identity automation and policy-as-code using Terraform.
  • Define identity-verification standards and runbooks for password resets, MFA resets, and device enrollment.
  • Establish documented controls and operational depth so critical identity functions do not depend on a single person.

Requirements

  • At least eight years of identity and access management experience, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering experience with Conditional Access, phishing-resistant MFA, single sign-on, federation, and enforcement verification.
  • Experience automating identity lifecycle management with RBAC/ABAC provisioning and entitlement-inventory-verified deprovisioning.
  • Experience designing Zero Trust identity controls, including least privilege, just-in-time access, and risk-based or adaptive access.
  • Experience engineering identity governance and administration platforms, including privileged access management.
  • PowerShell, Python, or similar scripting experience for lifecycle workflows and custom connectors.
  • Experience with identity-as-code and policy-as-code using Terraform and source-controlled change management such as GitHub.
  • Experience managing secrets and non-human identities, including API keys, service accounts, workload identity, and owner registries.
  • Experience with key access governance and separation of duties.
  • Ability to act as a technical authority without formal people-management responsibility and work directly with a CISO.
  • Bachelor’s degree in a relevant field or equivalent professional experience.
  • Healthcare or other regulated-environment experience is preferred.
  • Hands-on Saviynt with PAM, Azure PIM, and Keeper, or comparable platform experience, is preferred.
  • Passkeys, FIDO2, phishing-resistant authenticators, NIST SP 800-63 Rev. 4, relevant certifications, or experience expanding technical scope into leadership are preferred.

Benefits

  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance and life insurance.
  • 401(k) with company match.
  • Flexible time off.
  • Paid parental leave.
  • Hybrid schedule requiring at least three days per week in the Dallas, Texas office.

Tech Stack

PowerShellPythonTerraform

Categories

Lantern

About Lantern

501-1,000 employees

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation’s top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and labor funds. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation’s largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com.

Contact me