Lead IAM Engineer

Blue Cross and Blue shield of Massachusetts, Inc.
Boston, MA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$163,530.0 - $199,870.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Software as a Service Code Review Software Design Patterns Identity and Access Management Python (Programming Language) OAuth Ping (Networking Utility) Windows PowerShell Openid Connect
+10 more
Zero Trust Network Access Security Assertion Markup Language (SAML) Secure Coding Scripting Google Cloud Enterprise Software Applications Multi-Cloud SailPoint Terraform Devsecops

Job description

We are seeking a highly experienced Lead IAM Engineer to serve as the senior technical authority for enterprise Identity and Access Management. This role will lead the design, engineering, automation, and operational maturity of IAM capabilities across workforce, privileged, machine, application, and cloud identities.

The ideal candidate combines deep technical expertise with architectural thinking and hands-on engineering execution. This individual will drive modernization initiatives, mentor engineers, establish engineering standards, and partner with business and technology teams to strengthen the organization’s identity security posture.

This role is eligible for our Flex persona, with candidates local to our Boston, MA or Hingham, MA offices preferred.

Your Day to Day:

  • Design and implement IAM solutions across SSO, MFA, IGA, PAM, and cloud identity platforms.
  • Build integrations between IAM platforms and enterprise applications.
  • Support onboarding applications into IAM services.
  • Create reference architectures and design patterns.
  • Review application architectures and provide IAM guidance.
  • Develop enterprise standards for authentication, authorization, and privileged access.
  • Support Zero Trust initiatives.
  • Develop automation using Python, PowerShell, Terraform, APIs, and workflow engines.
  • Act as escalation point for IAM production issues.
  • Lead troubleshooting of complex authentication and provisioning failures.
  • Perform root cause analysis and remediation.
  • Improve platform resiliency and automation.
  • Mentor IAM engineers and administrators.
  • Conduct design reviews and code reviews.
  • Establish engineering standards and best practices.
  • Guide teams on IAM implementation patterns.
  • Support audits and compliance initiatives.
  • Assist with risk remediation efforts.
  • Evaluate emerging IAM technologies and develop IAM roadmaps
  • Identify automation opportunities and drive modernization efforts.

This document is not an exhaustive list of all responsibilities, skills, duties, requirements, or working conditions associated with the job. Employees may be required to perform other job-related duties.

We’re Looking for Someone Who:

  • Acts as the principal technical expert and subject matter expert for the IAM engineering team.
  • Leads the technical design and hands-on implementation of identity solutions across SSO, MFA, IGA, and PAM platforms.
  • Drives the technical execution of Zero Trust architecture and the integration of identity controls directly into CI/CD pipelines (DevSecOps).
  • Secures complex federated identities, APIs, and non-human workload identities across multi-cloud environments (AWS, Azure, GCP).
  • Provides formal mentorship, technical oversight, and architectural guidance to all other IAM engineers on the team.
  • Leads the engineering response to critical identity platform outages, performing deep root cause analysis on systemic bugs and performance issues.
  • Demonstrates Influence and Business Skills by serving as the principal technical expert, driving complex architectural decisions, and leading advanced identity methodologies without carrying direct people-management responsibilities.
  • Establishes and evangelizes IAM engineering best practices, including secure coding standards, design patterns, and reusable automation libraries

Requirements

  • Bachelor’s in CS/Engineering preferred, with 8+ years of dedicated IAM engineering experience.
  • Demonstrated experience leading complex IAM initiatives supporting hybrid, multi-cloud, and SaaS environments.
  • Expert-level knowledge of modern identity protocols (SAML, OAuth 2.0, OpenID Connect).
  • Advanced, hands-on experience engineering leading platforms (e.g., Ping, Delinea, SailPoint, Entra ID) for enterprise-wide scale.
  • Deep expertise in automating Identity Governance (JML processes) and deploying modern PAM controls (credential vaulting, Just-in-Time access).
  • Strong proficiency in scripting/automation (Python, PowerShell, Terraform).
  • Relevant industry certifications (e.g., CISSP, CISM, CCSP, or vendor-specific IAM certs) are strongly preferred

Minimum Education Requirements:

High school degree or equivalent required unless otherwise noted above

Benefits & conditions

vision insurance, paid time off, 401(k), We offer comprehensive package of benefits including paid time off, medical/dental/vision insurance, 401(k), and a suite of well-being benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company’s sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

WHY Blue Cross Blue Shield of MA?

We understand that theconfidence gapandimposter syndromecan prevent amazing candidates coming our way, so please don’t hesitate to apply. We’d love to hear from you. You might be just what we need for this role or possibly another one at Blue Cross Blue Shield of MA. The more voices we have represented and amplified in our business, the more we will all thrive, contribute, and be brilliant. We encourage you to bring us your true colors, , your perspectives, and your experiences. It’s in our differences that we will remain relentless in our pursuit to transform healthcare for ALL.

As an employer, we are committed to investing in your development and providing the necessary resources to enable your success. Learn how we are dedicated to creating an inclusive and rewarding workplace that promotes excellence and provides opportunities for employees to forge their unique career path by visiting ourCompany Culturepage. If this sounds like something you’d like to be a part of, we’d love to hear from you. You can also join ourTalent Communityto stay “in the know” on all things Blue.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all