Sr IAM Cloud Engineer

Job Locations
US-Remote

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview

How you can make a difference  

Join our team as an IAM Cloud Security Engineer. This role combines expertise in Identity and Access Management (IAM), cloud security, and Generative AI (GenAI) to design, secure, and operate AI-driven systems in our cloud environments. This is a game-changing role driving innovation with AI to identify non-standard cloud access, standardize through remediation, and automate IAM cloud functions. Innovate with AI by leading the development of advanced tools that summarize complex issues and recommend remediation plans, while continuously refining automated and manual administration while reducing the need for human intervention.

 

You will build and deploy cutting-edge AI agents using platforms like Azure and Langchain, creating intelligent systems that can autonomously detect anomalous activities. This role sits at the intersection of IAM engineering and IAM cloud security. It provides a unique opportunity to collaborate and lead cross-functional efforts with internal business and technical application owners, various lines of business within the organization, and governance and compliance teams by constantly evolving and maturing identity and access processes with the use of AI. As organizations adopt AI at scale in the cloud, securing both the infrastructure and the AI workloads is critical. This role ensures that identity, access, and security controls are embedded into AI/ML systems, protecting sensitive data, preventing unauthorized access, and maintaining compliance.

 

What you’ll be doing 

  • Design, implement, and maintain IAM frameworks (SSO, MFA, RBAC, PAM) across multi-cloud environments (AWS, Azure, GCP). Harden cloud environments using IAM policies, KMS, WAF, GuardDuty, Defender for Cloud, and compliance tools. Automate identity lifecycle management, provisioning, and deprovisioning.
  • Define and standardize IAM cloud access structures and secure cloud configurations. Build detection pipelines, automate compliance checks, and integrate CEIM tools
  • Support the secure use of Generative AI capabilities within IAM environments, including use cases related to access analysis, anomaly detection, issue summarization, remediation recommendations, and operational workflow automation.
  • Contribute to the design, testing, and refinement of AI-enabled IAM tools, prompts, retrieval strategies, and automation workflows that improve detection of non-standard access and support governance activities.
  • Partner with senior engineers, architects, and security teams to ensure AI-enabled IAM solutions align with model governance, data protection, API security, access control, and compliance expectations.
  • Collaborate with the AI COE and AI Engineering team for best practices, technology, and AI support needs. 
  • Support cloud non-human identity hygiene, including discovery, inventory review, ownership validation, credential and secret rotation support, stale or orphaned identity cleanup, privilege right-sizing, and key or policy review.
  • Strengthen authentication security by supporting modern authentication architecture, account fencing, reduction of legacy or non-standard authentication paths, and detection of risky sign-in behavior.
  • Configure and maintain authentication and authorization controls to ensure secure access to internal, external, cloud, and hybrid systems.
  • Automate IAM processes and workflows using scripting, integrations, and approved tooling to improve consistency, reduce manual work, and strengthen control execution.
  • Define, implement, and support Conditional Access and adaptive access policies, including Microsoft Entra ID controls, to advance Zero Trust principles.
  • Support the modernization and migration of IAM capabilities across cloud environments, including access policy design, entitlement governance, identity federation, and integration between on-premises and cloud systems.
  • Assess authentication and authorization baselines, identify non-standard or risky access patterns, and support risk-based remediation plans.
  • Support Cloud Infrastructure Entitlement Management and related cloud access governance activities, including visibility into permissions, excessive access, and entitlement risk.
  • Collaborate with internal teams, application owners, governance, audit, compliance, and business stakeholders to define access requirements, user roles, permissions, and remediation actions.
  • Develop and maintain documentation, procedures, dashboards, KPIs, KRIs, and reporting to support IAM operations, access governance, remediation tracking, and control effectiveness.
  • Stay current with IAM, cloud security, authentication, automation, AI security, and regulatory trends to continuously improve IAM practices and reduce risk.

What you will need to be successful

 

Education and Experience:

  • Bachelor’s degree in computer science, information technology, cybersecurity, data science, or a related field, or equivalent practical experience.
  • 8-10 years years in IAM engineering, cloud security, or GenAI/ML engineering. 
  • Experience supporting IAM capabilities in cloud or hybrid environments, including Microsoft Entra ID, Okta, Azure, AWS, GCP, or similar platforms.
  • Experience implementing, supporting, or automating identity lifecycle management, access controls, authentication policies, and entitlement governance.
  • Experience applying automation, scripting, or AI-enabled tools to improve IAM operations, access governance, or security workflows preferred.

 

Specialized Knowledge, Skills, and Abilities:

  • Strong knowledge of IAM concepts, including SSO, MFA, RBAC, PAM, identity federation, access governance, provisioning, deprovisioning, and periodic access reviews.
  • Knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, LDAP, and JWT.
  • Experience with Microsoft Entra ID, Okta, Azure AD, or similar IAM platforms.
  • Familiarity with cloud security concepts and tooling, including IAM policies, KMS, SIEM, Defender for Cloud, cloud logging, policy enforcement, and compliance monitoring.
  • Experience with scripting or automation using PowerShell, Python, Bash, SQL, or similar tools.
  • Understanding of non-human identities, service accounts, secrets, keys, privileged access, and cloud entitlement risk.
  • Familiarity with AI-enabled automation, retrieval-augmented generation, prompt design considerations, AI model security risks, or secure use of GenAI in enterprise environments.
  • Ability to assess IAM risks, analyze complex access patterns, and translate findings into clear remediation actions.
  • Strong analytical, troubleshooting, and problem-solving skills with attention to detail.
  • Effective communication skills, with the ability to partner across technical teams, business stakeholders, governance, compliance, and audit.
  • Knowledge of regulatory and compliance frameworks such as HIPAA, SOX, GDPR, and related security standards.

 

Certifications:

  • CISSP, CIPP, or IAM-specific certs. Cloud Security: AWS Security Specialty, Azure Security Engineer Associate (AZ-500), CKS. GenAI/ML: MLOps tools (MLflow), LLM frameworks (LangChain, Llama), RAG, GPTs.

 

 

#LI-Remote

This is a remote position.

Salary Range

$115000.00 To $149500.00 / year

Benefits & Perks

The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education & tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives

 

Onboarding & Travel

This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.

 

This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

 

HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.

Why work with HealthEquity 

HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more. 

 

You belong at HealthEquity!

HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.

 

HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.

 

At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.

 

As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills.  For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.

 

HealthEquity is committed to your privacy as an applicant for employment.  For information on our privacy policies and practices, please visit HealthEquity Privacy.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed