Identity and Access Management Engineer

Hi, We're Oscar
New York, NY, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$163,944.0 - $215,176.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services User Authentication BigQuery Software as a Service Custom Software Identity and Access Management Intrusion Detection and Prevention Lightweight Directory Access Protocols (LDAP) OAuth OpenID Role-Based Access Control Security Assertion Markup Language (SAML)
+10 more
Security Information and Event Management Software Engineering Google Cloud Enterprise Software Applications Cloud Platform System Okta Data Lakes Enterprise Integration Data Management Gsuite

Job description

As an Identity and Access Management Engineer, you will build Oscar’s identity and access management disciplines across internally built applications, standard identity platforms such as Okta and Google Workspace Identity, AWS-hosted systems, and the BigQuery data lake. You will design least privilege access models, create enterprise identity architectures, and build identity threat detection and response capabilities that protect workforce, internal application, and customer identity surfaces.

You will report to the Associate Director, Platform Security.

Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule.

Pay Transparency: The base pay for this role is: $163,944 per year - $215,176 per year. You are also eligible for employee benefits, participation in Oscar’s unlimited vacation program, company equity grants and annual performance bonuses.

Requirements

  • 4+ years of relevant experience in Identity engineering.
  • Experience designing or implementing identity and access management controls for enterprise systems, cloud environments, SaaS platforms, or internally built applications.
  • Strong understanding of least privilege, role-based and attribute-based access control, privileged access patterns, identity lifecycle management, and access review processes.
  • Hands-on experience with identity platforms such as Okta, Google Workspace Identity, and Google Cloud permission models.
  • Working knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, SCIM, LDAP, and related session, token, and federation patterns.
  • Experience partnering with software engineering teams to review permission models, design secure authorization patterns, and improve access controls in custom applications.
  • Ability to reason about identity telemetry, detection logic, high-risk configuration states, and incident response workflows.
  • Strong written and verbal communication skills, including the ability to explain identity risk and architecture tradeoffs to technical and non-technical audiences.

Bonus Points:

  • Experience building identity controls in AWS environments and data platforms such as BigQuery.
  • Experience building or operating ITDR, UEBA, SIEM, SOAR, or other security detection and response capabilities.
  • Experience in healthcare, insurance, fintech, or another regulated technology environment.
  • Experience writing automation, queries, or production-quality code to support identity workflows, detections, or platform integrations.

Benefits & conditions

This is an authentic Oscar Health job opportunity. Learn more about how you can safeguard yourself from recruitment fraud here.

At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We’re on a mission to change health care – an experience made whole by our unique backgrounds and perspectives.

Pay Transparency: Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.

About the company

Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves-one that behaves like a doctor in the family.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

Videos

See all

Related articles

See all