> Markdown version of [/jobs/ext/1954832-principal-security-access-engineer](https://www.wearedevelopers.com/jobs/ext/1954832-principal-security-access-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Access Engineer - **Company:** HealthEquity Inc. - **Location:** Draper, UT, United States (Remote available) - **Experience:** Expert - **Salary:** $133,000.0 - $173,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Audit Trail, Cloud Computing Security, Identity and Access Management, Key Management, Windows PowerShell, Azure Active Directory, Zero Trust Network Access, Information Technology, Virtual Agents, SailPoint, Restful APIs - **Published:** August 6, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17835775?backUrl=%2Fcareer%2F17835775%2FPrincipal-Security-Access-Engineer-Utah-Draper ## About the Role HealthEquity is seeking an experienced and highly motivated Principal IAM Security Access Engineer to join our Security & IT team. This role is critical to the design, implementation, and management of our identity, access, and privileged access management (IAM/PAM) systems - spanning human, non-employee, service, and AI agent identities. The ideal candidate has deep, hands-on experience with SailPoint Identity Security Cloud (ISC) and Non-Employee Risk Management (NERM), BeyondTrust, Microsoft Entra (including Conditional Access), and Silverfort, along with a strong point of view on how identity security must evolve to govern AI agents, non-human identities, and machine-to-machine access. This role requires a deep understanding of IAM principles, excellent problem-solving skills, and the ability to mentor and guide team members while exercising indirect leadership and influence across all levels of the organization., * Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent practical experience. * Minimum of 5 years of experience in IAM, with at least 3 years in a senior or principal engineer role. * Extensive, hands-on experience with SailPoint Identity Security Cloud (ISC); experience with Non-Employee Risk Management (NERM) strongly preferred. * Strong understanding of Privileged Access Management (PAM) and hands-on experience with BeyondTrust. * Proficiency with Microsoft Entra (formerly Azure AD), including Conditional Access policy design and administration. * Zero Trust expertise with technologies such as Silverfort. * Working knowledge of secrets management and vaulting platforms for securing credentials, keys, and tokens used by applications, service accounts, and automations. * Familiarity with identity considerations for AI agents and non-human identities - authentication patterns, scoped authorization, credential lifecycle, and monitoring for agentic/automated access. * Proficiency in scripting and automation (e.g., REST APIs, PowerShell) for IAM tasks. * Excellent analytical, problem-solving, and decision-making skills. * Strong communication and interpersonal skills, with the ability to work effectively with and influence stakeholders at all levels. * Relevant certifications such as CISSP, CISM, or IAM-related certifications are highly desirable. ## Description Implementation of robust IAM/PAM solutions using SailPoint Identity Security Cloud, BeyondTrust, Microsoft Entra, Silverfort, and other IAM tools/platforms. * Help develop and maintain IAM strategies; including governance for AI agents, non-human identities (NHIs), and machine-to-machine access - that align with organizational goals and industry best practices. * Function as a subject matter expert for IAM technologies and processes, including emerging practices for agentic AI identity, authorization, and lifecycle management. * Clearly articulate strategic initiatives, gain buy-in, and establish a shared understanding with key decision makers at the leadership level. System Management and Implementation: * Manage the configuration and administration of SailPoint ISC (including NERM for non-employee identity risk), BeyondTrust, Microsoft Entra, and Silverfort. * Design and manage Conditional Access policies within Microsoft Entra to enforce risk-based, adaptive access controls across users, devices, and workloads. * Partner closely with the IAM Governance team to implement IAM policies, standards, and procedures using IAM & PAM tools and processes. * Ensure seamless integration of IAM systems with applications, services, secrets management/vaulting platforms, and CI/CD pipelines. * Implement governance models for AI agents and service accounts, including credential issuance, scoped permissions, rotation, and decommissioning. * Drive timely execution of IAM & PAM initiatives in alignment with strategic and tactical plans. AI and Agentic Identity Enablement: * Establish identity and access frameworks for AI agents and autonomous workflows, ensuring least-privilege access, auditability, and policy enforcement equivalent to human identity controls. * Evaluate and integrate secrets management solutions to secure credentials, API keys, and tokens used by AI agents, automations, and service-to-service connections. * Assess and pilot AI-assisted capabilities within IAM tooling (e.g., SailPoint AI, Entra ID Protection risk signals, Silverfort risk analytics) to improve access certification accuracy, anomaly detection, and operational efficiency. * Program Management Support: * Help IAM projects go from initiation to completion, ensuring timely delivery and alignment with project goals. * Coordinate with cross-functional teams, including IT, HR, Security, and business units, to gather requirements and ensure successful project outcomes. * Manage project timelines and resources effectively. Team Development: * Provide indirect leadership and guidance to IAM engineers and other IAM team members. * Conduct training sessions and workshops - including on AI/agentic identity risk - to enhance the skills and knowledge of the team. * Foster the culture of continuous improvement and professional development within the IAM team. Troubleshooting and Support: * Provide advanced troubleshooting and support for IAM-related issues, including scripting/automation via APIs and PowerShell. * Develop and maintain documentation for IAM processes, configurations, and troubleshooting procedures. * Stay current with industry trends and emerging technologies, particularly around AI, agentic systems, and non-human identity security, to continually enhance the IAM landscape. ## Related Videos - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [The AI-Native Engineering Org: What’s Real, What’s Hype, What’s Next](https://www.wearedevelopers.com/videos/100004-the-ai-native-engineering-org-what-s-real-what-s-hype-what-s-next) - [REST In Peace: Why LLMs Can't CRUD](https://www.wearedevelopers.com/videos/100272-rest-in-peace-why-llms-can-t-crud) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)