HealthEquity logo
HealthEquityPosted 3 weeks ago

Sr IAM Cloud Engineer

$115,000–$115,000 year

RemoteUnited States

Full TimeSenior LevelLarge

Job Summary

Design and maintain IAM frameworks (SSO, MFA, RBAC, PAM) across multi-cloud environments (AWS, Azure, GCP), hardening cloud configurations with policies, KMS, and compliance tools. Build detection pipelines and automate identity lifecycle management while supporting the secure use of Generative AI for access analysis, anomaly detection, and remediation recommendations. Partner with cross-functional teams to define access requirements, implement Conditional Access policies, and execute risk-based remediation for non-standard access patterns. Manage cloud non-human identity hygiene, including discovery, credential rotation, and privilege right-sizing, while developing documentation and dashboards to track control effectiveness.

Required Qualifications

  • Bachelor's degree in computer science, information technology, cybersecurity, data science, or a related field, or equivalent practical experience
  • 8-10 years in IAM engineering, cloud security, or GenAI/ML engineering
  • Experience supporting IAM capabilities in cloud or hybrid environments, including Microsoft Entra ID, Okta, Azure, AWS, GCP, or similar platforms
  • Experience implementing, supporting, or automating identity lifecycle management, access controls, authentication policies, and entitlement governance
  • Strong knowledge of IAM concepts, including SSO, MFA, RBAC, PAM, identity federation, access governance, provisioning, deprovisioning, and periodic access reviews
  • Knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, LDAP, and JWT
  • Experience with Microsoft Entra ID, Okta, Azure AD, or similar IAM platforms
  • Familiarity with cloud security concepts and tooling, including IAM policies, KMS, SIEM, Defender for Cloud, cloud logging, policy enforcement, and compliance monitoring
  • Experience with scripting or automation using PowerShell, Python, Bash, SQL, or similar tools
  • Understanding of non-human identities, service accounts, secrets, keys, privileged access, and cloud entitlement risk
  • Ability to assess IAM risks, analyze complex access patterns, and translate findings into clear remediation actions
  • Strong analytical, troubleshooting, and problem-solving skills with attention to detail
  • Effective communication skills, with the ability to partner across technical teams, business stakeholders, governance, compliance, and audit
  • Knowledge of regulatory and compliance frameworks such as HIPAA, SOX, GDPR, and related security standards
  • CISSP, CIPP, or IAM-specific certs
  • Cloud Security: AWS Security Specialty, Azure Security Engineer Associate (AZ-500), CKS
  • GenAI/ML: MLOps tools (MLflow), LLM frameworks (LangChain, Llama), RAG, GPTs
  • Must be able to participate in Trailhead, HealthEquity's immersive onboarding experience
  • Must be available for an in-person onboarding training component
  • Must participate in a mandatory onsite Trailhead session at a later date
  • Must consent to Microsoft Copilot's AI technology recording and transcribing interview with Talent Partner

Desired Qualifications

  • Experience applying automation, scripting, or AI-enabled tools to improve IAM operations, access governance, or security workflows preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce