> Markdown version of [/jobs/ext/1958141-sr-iam-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/1958141-sr-iam-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr IAM Cloud Engineer - **Company:** HealthEquity Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Machine Learning, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Cloud Services, Zero Trust Network Access, JSON Web Token, Security Assertion Markup Language (SAML), SQL Databases, User Provisioning Software, Scripting, Google Cloud, Cloud Platform System, Okta, Multi-Cloud, Generative AI, Information Technology, Machine Learning Operations - **Published:** August 6, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/sr-iam-cloud-engineer-usa-58811781 ## About the Role or regulatory trends Tasks * Bachelor's degree in computer science, information technology, cybersecurity, data science, or related field (or equivalent practical experience) * 8-10 years in IAM engineering, cloud security, or GenAI/ML engineering * Experience with Microsoft Entra ID, Okta, Azure AD, AWS, GCP, or similar IAM platforms * Experience implementing or automating identity lifecycle management, access controls, and entitlement governance * Automation or AI-enabled tooling experience to improve IAM operations or security workflows * Strong knowledge of IAM concepts (SSO, MFA, RBAC, PAM) and related protocols (SAML, OAuth, OIDC, LDAP, JWT) * Scripting/automation skills (PowerShell, Python, Bash, SQL) * Understanding of non-human identities, service accounts, secrets, keys, and cloud entitlement risk * Familiarity with GenAI in enterprise security and AI-enabled automation * Knowledge of regulatory frameworks (HIPAA, SOX, GDPR) and model governance * Certifications such as CISSP, a aaP_ Azure Security Engineer (AZ-500), AWS Security Specialty, CKS * Experience with LangChain, Llama, MLflow or similar GenAI/ML tools is a plus Key requirements * Remote work * Medical, dental, and vision * 401(k) match * Unlimited PTO * Education assistance * Wellness programs ## Description Experteer Overview As an IAM Cloud Security Engineer, you will design, secure, and operate AI-driven IAM systems across multi-cloud environments, leveraging GenAI to detect non-standard access and automate remediation. You'll build AI-enabled tools and intelligent agents to summarize issues and guide actions, while ensuring model governance, data protection, and compliance. This remote role requires collaboration with cross-functional teams to mature identity and access processes in AI-enhanced cloud workloads. You help secure both infrastructure and AI workloads at scale, delivering Zero Trust-aligned controls and governance. Compensation / Benefits * Design, implement, and maintain IAM frameworks (SSO, MFA, RBAC, PAM) across AWS, Azure, and GCP * Harden cloud environments with IAM policies, KMS, WAF, Defender for Cloud, and compliance tooling * Automate identity lifecycle management, provisioning, and deprovisioning * Define and standardize IAM cloud access structures and secure configurations * Build detection pipelines and automate compliance checks; integrate CEIM tools * Support secure use of Generative AI within IAM, including anomaly detection and remediation recommendations * Contribute to AI-enabled IAM tools, prompts, and automation workflows; improve non-standard access detection * Collaborate with senior engineers, governance, and security teams to ensure model governance and data protection * Support non-human identity hygiene, credential rotation, and privilege right-sizing * Strengthen authentication security through modern architecture and risk-based sign-in detection * Configure and maintain Conditional Access and adaptive policies to advance Zero Trust * Modernize and migrate IAM capabilities across cloud environments; entitlements governance * Assess baselines, identify risky access patterns, and define remediation actions * Develop and maintain IAM documentation, dashboards, KPIs, and reporting * Stay current with IAM, cloud security, AI security, and regulatory trends Tasks * Bachelor's degree in computer science, information technology, cybersecurity, data science, or related field (or equivalent practical experience) * 8-10 years in IAM engineering, cloud security, or GenAI/ML engineering * Experience with Microsoft Entra ID, Okta, Azure AD, AWS, GCP, or similar IAM platforms * Experience implementing or automating identity lifecycle management, access controls, and entitlement governance * Automation or AI-enabled tooling experience to improve IAM operations or security workflows * Strong knowledge of IAM concepts (SSO, MFA, RBAC, PAM) and related protocols (SAML, OAuth, OIDC, LDAP, JWT) * Scripting/automation skills (PowerShell, Python, Bash, SQL) * Understanding of non-human identities, service accounts, secrets, keys, and cloud entitlement risk * Familiarity with GenAI in enterprise security and AI-enabled automation * Knowledge of regulatory frameworks (HIPAA, SOX, GDPR) and model governance * Certifications such as CISSP, CIPP, Azure Security Engineer (AZ-500), AWS Security Specialty, CKS * Experience with LangChain, Llama, MLflow or similar GenAI/ML tools is a plus Key requirements * Remote work * Medical, dental, and vision * 401(k) match * Unlimited PTO * Education assistance * Wellness programs ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)