Lantern

Principal IAM Engineer

Lantern
Apply
9 hours ago

Base Salary

$175k - $225k/yr

Responsibilities

  • Own joiner, mover, and leaver provisioning and deprovisioning using automated role- and attribute-based models, with verification against an entitlement inventory.
  • Own Conditional Access, phishing-resistant MFA, privileged access, Zero Trust identity controls, least privilege, just-in-time elevation, and enforcement verification across access paths.
  • Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
  • Manage secrets and non-human identities, including API keys, service accounts, workload identity, and an owner registry.
  • Govern key access and separation of duties while another team operates the key management system.
  • Build identity automation, identity-as-code, and policy-as-code with Terraform and version-controlled infrastructure.
  • Own identity-verification standards and runbooks for password resets, MFA resets, and device enrollment.
  • Set identity standards while partnering with platform, cloud, service delivery, HR, and Governance, Risk & Compliance teams.

Requirements

  • At least 8 years of identity and access management experience, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering experience, including Conditional Access, phishing-resistant MFA, single sign-on, federation, and verification of enforcement across access paths.
  • Experience automating identity lifecycles across cloud, SaaS, and privileged systems using RBAC/ABAC and entitlement-based deprovisioning verification.
  • Experience designing Zero Trust identity controls, least privilege, just-in-time access, and risk-based or adaptive access controls.
  • Experience engineering identity governance and administration platforms, including privileged access management.
  • PowerShell, Python, or similar scripting experience for lifecycle workflows and custom connectors.
  • Experience with identity-as-code and policy-as-code using Terraform and source-controlled change management such as GitHub.
  • Experience managing secrets, API keys, service accounts, workload identity, owner registries, key access governance, and separation of duties.
  • Ability to act as a technical authority without formal people-management responsibility and work directly with a CISO.
  • Bachelor’s degree in a relevant field or equivalent professional experience.
  • Preferred qualifications include healthcare or regulated-environment experience, Saviynt, PAM, Azure PIM, Keeper, passkeys, FIDO2, NIST SP 800-63 Rev. 4, Microsoft Identity and Access Administrator certification, CIMP, or equivalent credentials and experience.

Benefits

  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance and life insurance.
  • 401(k) with company match.
  • Flexible time off and paid parental leave.
  • Hybrid work arrangement requiring at least 3 days per week in the New York City office.

Tech Stack

PowerShellPythonTerraform

Categories

Lantern

About Lantern

501-1,000 employees

Lantern builds a specialty care platform that connects members of self-insured employers and labor funds with a nationwide Network of Excellence for surgery, cancer care, infusions, and other planned procedures. It sells bundled-case surgical and specialty benefits, pairing each member with care advocates and nurses to navigate treatment and reduce medical spend. The privately held company was founded in 2011 and is headquartered in Dallas, Texas.

Contact me