Sr IAM Security Engineer
HealthEquity, Inc.1 month ago
Remote, United StatesSenior
Base Salary
$115k - $150k/yr
Responsibilities
- Lead the design, implementation, administration, and continuous improvement of IAM solutions using SailPoint Identity Security Cloud, Microsoft Entra, Silverfort, and related technologies.
- Maintain IAM strategies and roadmaps and serve as a subject matter expert on identity lifecycle processes, access governance, authentication controls, and enterprise integrations.
- Integrate IAM systems with enterprise applications, cloud services, access-request workflows, provisioning processes, and authentication services.
- Develop automation for access requests, lifecycle processing, provisioning triage, certification support, application onboarding, and operational reporting.
- Build and deploy secure GenAI-enabled IAM solutions, including retrieval-augmented tools, intelligent summaries, access-pattern analysis, and AI-assisted workflows.
- Refine prompts, retrieval strategies, and supporting data structures for AI-assisted IAM insights and remediation recommendations.
- Support SailPoint, Microsoft Entra, and cloud identity use cases including access governance, SSO/SCIM validation, conditional access, MFA/passkey review, app registration analysis, and identity hygiene.
- Monitor IAM environments for vulnerabilities, configuration issues, anomalous access, and compliance gaps, and implement corrective actions.
- Conduct IAM security audits, access reviews, assessments, and control validation activities.
- Develop KPIs, KRIs, reports, and data-driven insights related to access governance, provisioning, authentication, and identity lifecycle processes.
- Apply appropriate judgment regarding AI model security, prompt risks, data handling, review requirements, and formal governance controls.
- Collaborate with IAM, cloud, AI, security, audit, compliance, application, infrastructure, and business stakeholders.
Requirements
- Bachelor’s degree or equivalent years of related experience.
- 10+ years of experience in information security, specifically identity and access management.
- Experience with automation, analytics, AI-assisted capabilities, or emerging technologies in cybersecurity, IAM, or cloud environments.
- Experience using scripting, APIs, reporting tools, and automation technologies to improve operational effectiveness.
- Proficiency in Python, SQL, Azure, OpenAI, Anthropic Claude frameworks, LangChain, and retrieval-augmented generation patterns.
- Experience with AI development lifecycle concepts, including Claude Code skills, commands, and sub-agents.
- Knowledge of Model Context Protocol, Agent-to-Agent Protocol, and AI agent design patterns.
- Strong knowledge of IAM lifecycle management, access requests, certifications, entitlement management, and governance.
- Experience with SailPoint Identity Security Cloud, including identity profiles, sources, applications, access profiles, roles, dimensions, lifecycle states, certifications, workflows, and governance reporting.
- Working knowledge of Microsoft Entra identity services, including enterprise applications, SSO, SCIM provisioning, conditional access, authentication methods, MFA, passkeys, app registrations, service principals, and cloud identity governance.
- Experience with Azure or Microsoft Entra cloud identity engineering, including configuration review, automation, policy analysis, and integration support.
- Experience with secrets management concepts and platforms such as HashiCorp Vault.
- Ability to analyze APIs, logs, configuration exports, identity datasets, access models, and platform reporting data.
- Strong stakeholder partnership, problem-solving, judgment, and ability to distinguish AI recommendations from engineer-reviewed or formally governed changes.
- Relevant certifications such as CISSP, CISM, or IAM-related certifications are highly desirable.
Benefits
- Remote position.
- Base salary range of $115,000 to $149,500 per year plus performance-based incentives.
- Medical, dental, and vision coverage.
- HSA contribution and match and dependent care FSA match.
- Uncapped paid time off and paid parental leave.
- 401(k) match.
- Personal and healthcare financial literacy programs.
- Ongoing education and tuition assistance.
- Gym and fitness reimbursement and wellness program incentives.
- In-person Trailhead onboarding is held onsite at headquarters once per quarter; required travel and accommodations are covered, and onboarding may begin virtually.
- Reasonable accommodations are available for qualifying disabilities.