Senior IAM Specialist

Zip Staff Inc.
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$112,320.0 - $116,480.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory User Authentication Authentication Protocols CompTIA Security+ Cyber Security Identity and Access Management Python (Programming Language) Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell
+10 more
Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Scripting Google Cloud Cyberark Software Troubleshooting Hashicorp Terraform

Job description

ZipStaff is seeking a Senior Identity and Access Management (IAM) Specialist to support enterprise identity platforms at a large, leading healthcare and pharmacy services organization.

This is a senior, hands-on role focused on designing, implementing, and operating hybrid identity, privileged access, and cloud IAM solutions in a highly regulated environment. You will serve as a technical subject matter expert, partnering with Security, Infrastructure, Compliance, and Application teams to strengthen access controls, support audit readiness, and reduce identity-related risk.

What You’ll Do

  • Design, implement, and support IAM solutions across hybrid identity environments and GCP landing zones
  • Administer and optimize Microsoft Entra ID and Active Directory, including federation, synchronization, authentication, GPOs, and delegated administration
  • Configure and manage Privileged Access Management (PAM) for administrative and elevated access
  • Define and enforce IAM standards, RBAC models, group strategies, and least-privilege / Zero Trust principles
  • Lead identity lifecycle processes (joiner/mover/leaver), access reviews, and entitlement remediation
  • Troubleshoot complex authentication, authorization, provisioning, and federation issues across platforms
  • Support compliance and audit activities (HIPAA, SOX) by providing evidence, documentation, and remediation support
  • Provide advanced operational support, including on-call response for critical identity services
  • Develop and maintain technical documentation, runbooks, and operational procedures
  • Mentor junior IAM engineers and contribute to standards, automation, and continuous improvement initiatives

Requirements

  • 5+ years of progressive experience in Identity and Access Management, Directory Services, or Information Security
  • Strong hands-on expertise with Microsoft Active Directory and Microsoft Entra ID in enterprise environments
  • Proven experience supporting hybrid identity architectures, federation, and modern authentication
  • Hands-on experience with GCP IAM (or equivalent cloud identity platforms)
  • Experience implementing and supporting Privileged Access Management (PAM) controls and processes
  • Deep understanding of identity lifecycle management, RBAC, access governance, and least-privilege principles
  • Working knowledge of authentication protocols (SAML, OAuth, OIDC, LDAP, Kerberos)
  • Experience supporting compliance and audit requirements in regulated environments
  • Strong troubleshooting, documentation, and stakeholder communication skills
  • Ability to contribute at a senior level with minimal ramp-up time
  • Must be legally authorized to work in the United States without sponsorship now or in the future, * Hands-on experience with CyberArk, HashiCorp Vault, Delinea, BeyondTrust, or similar PAM platforms
  • Experience with Identity Governance and Administration (IGA) tools
  • Automation/scripting skills (PowerShell, Python, Terraform, or Infrastructure-as-Code)
  • Relevant certifications (SC-300, AZ-500, CISSP, CISM, Security+, or GCP Security Engineer)
  • Prior experience in healthcare or other highly regulated industries, * Are you legally authorized to work in the United States?
  • Will you now or in the future require employer sponsorship for employment authorization?
  • Do you have experience supporting hybrid identity environments, federation services, and modern authentication protocols (SAML, OAuth, OIDC, etc.)?
  • Do you have hands-on experience with Privileged Access Management (PAM) solutions or privileged access controls?
  • Do you have experience with Google Cloud Platform (GCP) IAM or other cloud identity platforms?
  • Do you have at least 5 years of hands-on Identity and Access Management experience, including administration of Microsoft Active Directory and Microsoft Entra ID?

Benefits & conditions

$54 - $56 an hour - Permanent, Full-time, Pulled from the full job description

  • Referral program
  • 401(k)
  • 401(k) matching
  • Paid time off, * 401(k)
  • 401(k) matching
  • Paid time off
  • Referral program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all