IAM Engineer- Irvine, CA or Irving, TX or Henderson, NV (Onsite)

Stellent IT LLC
Irving, TX, United States
18 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$108,701.0 - $120,786.0
Working hours
Regular working hours

Tech stack

Cerner Microsoft Access Application Programming Interfaces (APIs) Health Informatics Cloud Computing Security Digital Assets Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell
+9 more
Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) Systems Integration Enterprise Software Applications Okta Cyberark SailPoint Restful APIs

Job description

Client needs a senior hands-on IAM Engineer III who can become the internal technical owner for a new IGA platform. They do not have IGA in production today and are evaluating solutions like Saviynt and ObserveID. This person will support implementation with the vendor, then own configuration, integrations, operations, access reviews, lifecycle workflows, governance, and compliance long-term. The strongest candidates will have true IGA platform ownership, API-heavy integration experience, PowerShell/Python automation, ISO/HIPAA exposure, and a proven ability to operate in a very fast-paced onsite environment. Important

  • The right candidate will be the technical product owner and primary system owner for the IGA platform.

  • This hire will support implementation, integrations, access governance, day-to-day operations, compliance, and stakeholder management.

Core Responsibilities

  • Act as the technical product owner and system owner for the chosen IGA platform.

  • Partner with the selected IGA vendor and implementation team to deploy IGA across PDS.

  • Own configuration, ongoing maintenance, upgrades, enhancements, and operational support after go-live.

  • Build, manage, and troubleshoot application integrations into the IGA platform.

  • Develop and maintain APIs required for IGA integrations across enterprise applications.

  • Support user lifecycle management workflows, including joiner, mover, and leaver processes.

  • Coordinate and execute access reviews and certification campaigns across the organization.

  • Support RBAC, entitlement governance, least-privilege access models, and segregation-of-duties controls.

  • Participate heavily in change control, governance, approvals, and compliance workflows.

  • Partner with application owners, Security, IAM, Compliance, Privacy, Clinical Informatics, and broader IT stakeholders.

  • Maintain documentation, workflow maps, control evidence, SOPs, and operational procedures.

  • Help operationalize controls tied to HIPAA, ISO, and other applicable security/compliance frameworks., The strongest candidate is a senior hands-on IAM/IGA engineer who has owned a platform, not merely supported one as a narrow team contributor. PDS needs someone who can operate as an engineer during implementation and then transition into technical product owner/system owner after implementation.
  • Mid-sized or mid-market enterprise background preferred.

  • Enough scale and complexity to have varied applications, compliance, governance, and stakeholder needs.

  • Not so large that the candidate only owned a tiny piece of the stack.

  • Healthcare or regulated enterprise exposure preferred.

  • Comfort wearing multiple hats: engineer, platform owner, implementation partner, integration owner, support escalation point, and governance partner.

Candidate Profiles to Avoid

  • Generic IAM engineers without meaningful IGA depth.

  • Provisioning/helpdesk-only IAM candidates.

  • Architect-only or advisory-only candidates who are not hands-on.

  • Candidates from very small shops with limited complexity.

  • Candidates from massive enterprises who only owned a narrow function.

  • Candidates who cannot interview in person.

  • Candidates without API/integration and automation depth.

  • Candidates who only used IGA tools lightly but never owned or administered them., Join a leading organization dedicated to safeguarding digital assets and ensuring robust security across its platforms. We are partnering with Aquent to find top talent to enhance …
  • 3 hours ago, Hands-on Senior Identity and Access Management Engineer to join a growing cybersecurity team supporting a large enterprise environment. This individual will serve as the dedicated …
  • 12 days ago +

Requirements

  • 6+ years of enterprise IAM experience, with meaningful hands-on identity governance exposure.

  • Direct IGA platform experience, ideally Saviynt, ObserveID, SailPoint, Okta Lifecycle Management, Microsoft Entra Identity Governance, or similar.

  • Experience as a technical system owner, primary admin, or major implementation contributor for an IGA platform.

  • Strong understanding of identity lifecycle management, access governance, RBAC, access certifications, and entitlement management.

  • Hands-on IGA integration experience using REST APIs, SCIM, SAML, OAuth/OIDC, LDAP, or related standards.

  • Strong PowerShell, Python, or equivalent automation experience applied to IAM/IGA workflows.

  • Comfort building, maintaining, and troubleshooting APIs for application integrations.

  • Experience supporting compliance-driven environments, especially ISO and HIPAA.

  • Ability to work in a fast-paced, high-volume, multi-stakeholder environment.

  • Comfort being the internal go-to SME where the buck stops for IGA.

  • Ability to work onsite full-time in Irvine, Dallas, or Henderson.

  • No current or future H-1B sponsorship requirement.

Strong Nice-to-Haves

  • Previous IGA platform implementation from the ground up.

  • Saviynt experience.

  • ObserveID experience.

  • SailPoint or other transferable enterprise IGA experience.

  • Healthcare, dental, medical, life sciences, or other regulated enterprise background.

  • EHR/EMR exposure such as Epic or Cerner.

  • Experience with SaaS security posture tools such as Grip Security, Valence Security, or similar.

  • PAM exposure, especially CyberArk.

  • CISSP, CISM, CISA, Okta certifications, Microsoft Entra SC-300, or vendor-specific IGA certifications.

  • Experience supporting ISO 27001 audit evidence, especially access control evidence.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all