Senior IAM Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
ZipStaff is seeking a Senior Identity and Access Management (IAM) Specialist to support enterprise identity platforms at a large, leading healthcare and pharmacy services organization.
This is a senior, hands-on role focused on designing, implementing, and operating hybrid identity, privileged access, and cloud IAM solutions in a highly regulated environment. You will serve as a technical subject matter expert, partnering with Security, Infrastructure, Compliance, and Application teams to strengthen access controls, support audit readiness, and reduce identity-related risk.
What You’ll Do
- Design, implement, and support IAM solutions across hybrid identity environments and GCP landing zones
- Administer and optimize Microsoft Entra ID and Active Directory, including federation, synchronization, authentication, GPOs, and delegated administration
- Configure and manage Privileged Access Management (PAM) for administrative and elevated access
- Define and enforce IAM standards, RBAC models, group strategies, and least-privilege / Zero Trust principles
- Lead identity lifecycle processes (joiner/mover/leaver), access reviews, and entitlement remediation
- Troubleshoot complex authentication, authorization, provisioning, and federation issues across platforms
- Support compliance and audit activities (HIPAA, SOX) by providing evidence, documentation, and remediation support
- Provide advanced operational support, including on-call response for critical identity services
- Develop and maintain technical documentation, runbooks, and operational procedures
- Mentor junior IAM engineers and contribute to standards, automation, and continuous improvement initiatives
Requirements
- 5+ years of progressive experience in Identity and Access Management, Directory Services, or Information Security
- Strong hands-on expertise with Microsoft Active Directory and Microsoft Entra ID in enterprise environments
- Proven experience supporting hybrid identity architectures, federation, and modern authentication
- Hands-on experience with GCP IAM (or equivalent cloud identity platforms)
- Experience implementing and supporting Privileged Access Management (PAM) controls and processes
- Deep understanding of identity lifecycle management, RBAC, access governance, and least-privilege principles
- Working knowledge of authentication protocols (SAML, OAuth, OIDC, LDAP, Kerberos)
- Experience supporting compliance and audit requirements in regulated environments
- Strong troubleshooting, documentation, and stakeholder communication skills
- Ability to contribute at a senior level with minimal ramp-up time
- Must be legally authorized to work in the United States without sponsorship now or in the future, * Hands-on experience with CyberArk, HashiCorp Vault, Delinea, BeyondTrust, or similar PAM platforms
- Experience with Identity Governance and Administration (IGA) tools
- Automation/scripting skills (PowerShell, Python, Terraform, or Infrastructure-as-Code)
- Relevant certifications (SC-300, AZ-500, CISSP, CISM, Security+, or GCP Security Engineer)
- Prior experience in healthcare or other highly regulated industries, * Are you legally authorized to work in the United States?
- Will you now or in the future require employer sponsorship for employment authorization?
- Do you have experience supporting hybrid identity environments, federation services, and modern authentication protocols (SAML, OAuth, OIDC, etc.)?
- Do you have hands-on experience with Privileged Access Management (PAM) solutions or privileged access controls?
- Do you have experience with Google Cloud Platform (GCP) IAM or other cloud identity platforms?
- Do you have at least 5 years of hands-on Identity and Access Management experience, including administration of Microsoft Active Directory and Microsoft Entra ID?
Benefits & conditions
$54 - $56 an hour - Permanent, Full-time, Pulled from the full job description
- Referral program
- 401(k)
- 401(k) matching
- Paid time off, * 401(k)
- 401(k) matching
- Paid time off
- Referral program
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Upskilling And Reskilling is Important For Developers
The Best Job Search Websites of 2025