> Markdown version of [/jobs/ext/1101445-staff-enterprise-and-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/1101445-staff-enterprise-and-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Enterprise and Cloud Engineer - **Company:** Zocdoc, Inc. - **Location:** New York, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - $270,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Systems Engineering, JIRA, Software as a Service, Cyber Security, Software Debugging, Programming Tools, Domain Name System (DNS), Human Resources Information System (HRIS), Github, Identity and Access Management, Python (Programming Language), Automation of Marketing, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Systems Integration, AWS Cdk, Google Cloud, Enterprise Software Applications, Load Balancing, Software Distribution, Large Language Models, Snowflake, Generative AI, Amazon Virtual Private Cloud (VPC), Microsoft InTune, Falcon Platform, AI Platforms, Performance Monitor, Enterprise Integration, Casper Suite, Gsuite, CIS Benchmarks, Terraform, Workday, Unified Endpoint Management - **Published:** June 1, 2026 - **Apply:** https://www.dice.com/job-detail/2c6baa2e-7dba-453b-a629-c4d653cf5f76 ## About the Role * Influence Without Authority: Demonstrated ability to drive adoption of standards across teams through RFCs, design reviews, and architectural pattern-setting. * Architectural Leadership & Influence: 10+ years in IT/Systems (mid-to-large scale) as a "player-coach" with a proven track record of defining adoption-ready standards and writing the design docs/RFCs that become the organization's source of truth. * Entra ID & Identity Governance: Deep expertise in Microsoft Entra ID (Conditional Access, PIM, Identity Governance) and the ability to own the entire identity lifecycle, including onboarding/offboarding flows and permission hygiene. * Scalable Integration Engineering: Extensive experience delivering SSO and SCIM integrations (SAML, OIDC/OAuth) across a massive SaaS estate, with a focus on replacing manual access work with programmatic or self-service provisioning. * Process Automation & Toil Reduction: A systems-thinker comfortable being measured by toil eliminated; expert at automating workflows across IdP, HRIS (Workday), and SaaS platforms via APIs to remove repetitive manual tasks. * Modern AI & Ecosystem Management: Experience governing IAM, spend, and quotas for AI platforms (OpenAI, Anthropic) and fluency in using Generative AI tools (Claude Code, LLMs) to accelerate engineering velocity. * Compliance & Security Hygiene: Experience in audit-sensitive environments ( HITRUST/SOC2 evidence collection) and owning the security hygiene of the identity certificate and token lifecycle. * Enterprise Platform Oversight: Familiarity with the broader endpoint and security ecosystem, including Intune, Jamf, Google Workspace, and CrowdStrike, to ensure a cohesive identity posture across all platforms. * Infrastructure-as-Code & AWS: Hands-on experience with AWS infrastructure and networking primitives (VPC, DNS, Load Balancing) to debug connectivity, utilizing AWS CDK, Terraform, Python, or PowerShell for automation. ## Description * Technical Domain Expert: Deeply fluent in Microsoft Entra ID (Identity Governance, Access Packages), SSO/SCIM standards (SAML, OIDC), and custom integrations for a diverse SaaS and AI estate. * AI Governance Pioneer: Excited to scale AI platforms like OpenAI and Anthropic through thoughtful RBAC, tiered spend/quota governance, and secure, consumable access patterns. * Outcome-Oriented Automationist: Comfortable working the access queue to identify patterns, with a relentless focus on building the automation and self-service tools that retire repetitive manual work. * Collaborative Leader & Mentor: A cross-functional partner who models Staff-level behaviors by mentoring engineers, aligning stakeholders, and setting the technical standards that drive adoption across the organization. * Autonomous & Curious Professional: An outcome-driven leader who brings humility, curiosity, and a sense of humor to solving challenging problems in a growing, high-scale environment. Your day to day is... * Strategic IAM Vision & Authority: Own the multi-year technical roadmap and architectural standards for Corporate and Cloud IAM (centered on Entra ID), acting as the technical authority who uplevels the team through design reviews and RFCs. * Scalable SSO & AI Governance: Architect secure SSO, SCIM, and JIT provisioning patterns for all enterprise tools, specifically owning the access posture, spend governance, and automated approval workflows for AI platforms (OpenAI, Claude, Google Cloud Platform). * Enterprise SaaS Architecture: Define configuration standards, security baselines, and lifecycle management patterns that scale across dozens of SaaS platforms. Drive consolidation and rationalization initiatives, and proactively close governance gaps before they become audit findings or incidents. * Automation & Toil Elimination: Field escalated tickets to identify and eliminate repeating manual work-converting complex access requests into self-service paths or automated workflows using Terraform, Python, or PowerShell. * Access Incident Response & On-Call: Participate in a tiered on-call rotation for triaging functional area outages, conditional access failures, compromised accounts, and break-glass events, and convert recurring pages into automated detections, runbooks, and self-healing workflows to reduce toil over time. * Endpoint Lifecycle & Software Distribution: Own the architectural engineering of endpoint configuration, software distribution, and provisioning workflows across Jamf (macOS) and Intune (Windows), partnering with InfoSec on hardening baselines and rolling out enterprise software (including AI developer tools) at scale. * Identity Hygiene & Infrastructure: Hands-on ownership of identity certificate and token lifecycles, GitHub access pipelines, and AWS landing-zone governance (Control Tower/IAM baselines) to ensure proactive monitoring and prevent configuration drift. * Zero Trust & Device Posture: Partner with Security to drive Zero Trust initiatives, integrating Conditional Access with device posture data from Intune, Jamf, and CrowdStrike across the broader SaaS estate (Snowflake, Jira, Google Workspace). * Compliance & Audit Engineering: Lead IAM workstreams for HITRUST and SOC2 cycles by translating audit requirements into reusable engineering patterns and participating in a critical on-call rotation for access-related incidents. * Trusted Cross-Functional Partner: Serve as a trusted technical partner to InfoSec, People Systems, Compliance, and Engineering leadership. Influence roadmap priorities based on deep understanding of stakeholder needs, and represent IT Engineering in strategic planning, audit cycles, and incident response. * Org-Level Visibility: Lead initiatives whose impact is recognized at the organizational level identity governance transformation, least-privilege enforcement at scale, or AI access governance translating business goals into actionable plans and aligning multiple teams behind them., * Scope of Prior Ownership: Track record leading identity or enterprise platform initiatives at a multi-thousand-employee organization, with measurable outcomes (toil eliminated, audit findings reduced, time-to-access shortened, or comparable business metrics). ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Empowering Thousands of Developers: Our Journey to an Internal Developer Platform](https://www.wearedevelopers.com/videos/1519-empowering-thousands-of-developers-our-journey-to-an-internal-developer-platform) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Let developers develop again](https://www.wearedevelopers.com/videos/463-let-developers-develop-again) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)