Sr IAM Cloud Engineer

HealthEquity Inc.
United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) Machine Learning
+19 more
OAuth OpenID Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Zero Trust Network Access JSON Web Token Security Assertion Markup Language (SAML) SQL Databases User Provisioning Software Scripting Google Cloud Cloud Platform System Okta Multi-Cloud Generative AI Information Technology Machine Learning Operations

Job description

Experteer Overview As an IAM Cloud Security Engineer, you will design, secure, and operate AI-driven IAM systems across multi-cloud environments, leveraging GenAI to detect non-standard access and automate remediation. You’ll build AI-enabled tools and intelligent agents to summarize issues and guide actions, while ensuring model governance, data protection, and compliance. This remote role requires collaboration with cross-functional teams to mature identity and access processes in AI-enhanced cloud workloads. You help secure both infrastructure and AI workloads at scale, delivering Zero Trust-aligned controls and governance. Compensation / Benefits * Design, implement, and maintain IAM frameworks (SSO, MFA, RBAC, PAM) across AWS, Azure, and GCP * Harden cloud environments with IAM policies, KMS, WAF, Defender for Cloud, and compliance tooling * Automate identity lifecycle management, provisioning, and deprovisioning * Define and standardize IAM cloud access structures and secure configurations * Build detection pipelines and automate compliance checks; integrate CEIM tools * Support secure use of Generative AI within IAM, including anomaly detection and remediation recommendations * Contribute to AI-enabled IAM tools, prompts, and automation workflows; improve non-standard access detection * Collaborate with senior engineers, governance, and security teams to ensure model governance and data protection * Support non-human identity hygiene, credential rotation, and privilege right-sizing * Strengthen authentication security through modern architecture and risk-based sign-in detection * Configure and maintain Conditional Access and adaptive policies to advance Zero Trust * Modernize and migrate IAM capabilities across cloud environments; entitlements governance * Assess baselines, identify risky access patterns, and define remediation actions * Develop and maintain IAM documentation, dashboards, KPIs, and reporting * Stay current with IAM, cloud security, AI security, and regulatory trends Tasks * Bachelor’s degree in computer science, information technology, cybersecurity, data science, or related field (or equivalent practical experience) * 8-10 years in IAM engineering, cloud security, or GenAI/ML engineering * Experience with Microsoft Entra ID, Okta, Azure AD, AWS, GCP, or similar IAM platforms * Experience implementing or automating identity lifecycle management, access controls, and entitlement governance * Automation or AI-enabled tooling experience to improve IAM operations or security workflows * Strong knowledge of IAM concepts (SSO, MFA, RBAC, PAM) and related protocols (SAML, OAuth, OIDC, LDAP, JWT) * Scripting/automation skills (PowerShell, Python, Bash, SQL) * Understanding of non-human identities, service accounts, secrets, keys, and cloud entitlement risk * Familiarity with GenAI in enterprise security and AI-enabled automation * Knowledge of regulatory frameworks (HIPAA, SOX, GDPR) and model governance * Certifications such as CISSP, CIPP, Azure Security Engineer (AZ-500), AWS Security Specialty, CKS * Experience with LangChain, Llama, MLflow or similar GenAI/ML tools is a plus Key requirements * Remote work * Medical, dental, and vision * 401(k) match * Unlimited PTO * Education assistance * Wellness programs

Requirements

or regulatory trends Tasks * Bachelor’s degree in computer science, information technology, cybersecurity, data science, or related field (or equivalent practical experience) * 8-10 years in IAM engineering, cloud security, or GenAI/ML engineering * Experience with Microsoft Entra ID, Okta, Azure AD, AWS, GCP, or similar IAM platforms * Experience implementing or automating identity lifecycle management, access controls, and entitlement governance * Automation or AI-enabled tooling experience to improve IAM operations or security workflows * Strong knowledge of IAM concepts (SSO, MFA, RBAC, PAM) and related protocols (SAML, OAuth, OIDC, LDAP, JWT) * Scripting/automation skills (PowerShell, Python, Bash, SQL) * Understanding of non-human identities, service accounts, secrets, keys, and cloud entitlement risk * Familiarity with GenAI in enterprise security and AI-enabled automation * Knowledge of regulatory frameworks (HIPAA, SOX, GDPR) and model governance * Certifications such as CISSP, a aaP_ Azure Security Engineer (AZ-500), AWS Security Specialty, CKS * Experience with LangChain, Llama, MLflow or similar GenAI/ML tools is a plus Key requirements * Remote work * Medical, dental, and vision * 401(k) match * Unlimited PTO * Education assistance * Wellness programs

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all