> Markdown version of [/jobs/ext/2103331-iam-engineer-irvine-ca-or-irving-tx-or-henderson-nv-onsite](https://www.wearedevelopers.com/jobs/ext/2103331-iam-engineer-irvine-ca-or-irving-tx-or-henderson-nv-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer- Irvine, CA or Irving, TX or Henderson, NV (Onsite) - **Company:** Stellent IT LLC - **Location:** Irving, TX, United States - **Experience:** Expert - **Salary:** $108,701.0 - $120,786.0 - **Contract:** Permanent contract - **Skills:** Cerner, Microsoft Access, Application Programming Interfaces (APIs), Health Informatics, Cloud Computing Security, Digital Assets, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Systems Integration, Enterprise Software Applications, Okta, Cyberark, SailPoint, Restful APIs - **Published:** August 18, 2026 - **Apply:** https://www.careerjet.com/jobad/usa4f6988c6588adfbcd3fd046c0b53677 ## About the Role * 6+ years of enterprise IAM experience, with meaningful hands-on identity governance exposure. * Direct IGA platform experience, ideally Saviynt, ObserveID, SailPoint, Okta Lifecycle Management, Microsoft Entra Identity Governance, or similar. * Experience as a technical system owner, primary admin, or major implementation contributor for an IGA platform. * Strong understanding of identity lifecycle management, access governance, RBAC, access certifications, and entitlement management. * Hands-on IGA integration experience using REST APIs, SCIM, SAML, OAuth/OIDC, LDAP, or related standards. * Strong PowerShell, Python, or equivalent automation experience applied to IAM/IGA workflows. * Comfort building, maintaining, and troubleshooting APIs for application integrations. * Experience supporting compliance-driven environments, especially ISO and HIPAA. * Ability to work in a fast-paced, high-volume, multi-stakeholder environment. * Comfort being the internal go-to SME where the buck stops for IGA. * Ability to work onsite full-time in Irvine, Dallas, or Henderson. * No current or future H-1B sponsorship requirement. Strong Nice-to-Haves * Previous IGA platform implementation from the ground up. * Saviynt experience. * ObserveID experience. * SailPoint or other transferable enterprise IGA experience. * Healthcare, dental, medical, life sciences, or other regulated enterprise background. * EHR/EMR exposure such as Epic or Cerner. * Experience with SaaS security posture tools such as Grip Security, Valence Security, or similar. * PAM exposure, especially CyberArk. * CISSP, CISM, CISA, Okta certifications, Microsoft Entra SC-300, or vendor-specific IGA certifications. * Experience supporting ISO 27001 audit evidence, especially access control evidence. ## Description Client needs a senior hands-on IAM Engineer III who can become the internal technical owner for a new IGA platform. They do not have IGA in production today and are evaluating solutions like Saviynt and ObserveID. This person will support implementation with the vendor, then own configuration, integrations, operations, access reviews, lifecycle workflows, governance, and compliance long-term. The strongest candidates will have true IGA platform ownership, API-heavy integration experience, PowerShell/Python automation, ISO/HIPAA exposure, and a proven ability to operate in a very fast-paced onsite environment. Important * The right candidate will be the technical product owner and primary system owner for the IGA platform. * This hire will support implementation, integrations, access governance, day-to-day operations, compliance, and stakeholder management. Core Responsibilities * Act as the technical product owner and system owner for the chosen IGA platform. * Partner with the selected IGA vendor and implementation team to deploy IGA across PDS. * Own configuration, ongoing maintenance, upgrades, enhancements, and operational support after go-live. * Build, manage, and troubleshoot application integrations into the IGA platform. * Develop and maintain APIs required for IGA integrations across enterprise applications. * Support user lifecycle management workflows, including joiner, mover, and leaver processes. * Coordinate and execute access reviews and certification campaigns across the organization. * Support RBAC, entitlement governance, least-privilege access models, and segregation-of-duties controls. * Participate heavily in change control, governance, approvals, and compliance workflows. * Partner with application owners, Security, IAM, Compliance, Privacy, Clinical Informatics, and broader IT stakeholders. * Maintain documentation, workflow maps, control evidence, SOPs, and operational procedures. * Help operationalize controls tied to HIPAA, ISO, and other applicable security/compliance frameworks., The strongest candidate is a senior hands-on IAM/IGA engineer who has owned a platform, not merely supported one as a narrow team contributor. PDS needs someone who can operate as an engineer during implementation and then transition into technical product owner/system owner after implementation. * Mid-sized or mid-market enterprise background preferred. * Enough scale and complexity to have varied applications, compliance, governance, and stakeholder needs. * Not so large that the candidate only owned a tiny piece of the stack. * Healthcare or regulated enterprise exposure preferred. * Comfort wearing multiple hats: engineer, platform owner, implementation partner, integration owner, support escalation point, and governance partner. Candidate Profiles to Avoid * Generic IAM engineers without meaningful IGA depth. * Provisioning/helpdesk-only IAM candidates. * Architect-only or advisory-only candidates who are not hands-on. * Candidates from very small shops with limited complexity. * Candidates from massive enterprises who only owned a narrow function. * Candidates who cannot interview in person. * Candidates without API/integration and automation depth. * Candidates who only used IGA tools lightly but never owned or administered them., Join a leading organization dedicated to safeguarding digital assets and ensuring robust security across its platforms. We are partnering with Aquent to find top talent to enhance … + 3 hours ago, Hands-on Senior Identity and Access Management Engineer to join a growing cybersecurity team supporting a large enterprise environment. This individual will serve as the dedicated … + 12 days ago + ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)