> Markdown version of [/jobs/ext/541102-director-of-identity-access-management-iam-11071](https://www.wearedevelopers.com/jobs/ext/541102-director-of-identity-access-management-iam-11071). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Identity & Access Management (IAM)-11071 - **Company:** NOR HEALTHCARE SYSTEMS CORP - **Location:** Culver City, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - **Contract:** Permanent contract - **Skills:** Cerner, Active Directory, Health Informatics, Business Systems, Cyber Security, Identity and Access Management, OAuth, OpenID, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Systems Integration, Electronic Medical Records, Information Technology, SailPoint, Meditech, Allscripts - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e47c13b48eb83b49 ## About the Role Do you have experience in Senior leadership?, Do you have a Bachelor's degree?, * Bachelor's degree in information technology, Computer Science, Cybersecurity, or related field * Master's degree preferred but not required, * 8-12+ years of progressive IT experience * 5+ years in IAM leadership or senior IAM architecture roles * Strong experience in healthcare, regulated industries, or large enterprises * Proven experience supporting audits and regulatory compliance Technical Skills * Deep knowledge of IAM concepts and frameworks * Hands-on understanding of: * + Active Directory / Azure AD + SSO, MFA, Federation + Role and entitlement management + Privileged access controls * Familiarity with EHR/EMR access models (Allscripts, Cerner, Meditech, etc. a plus), * Healthcare IT experience in hospital or multi-entity environments * Familiarity with EHR/EMR access models * Security or IAM certifications (CISSP, CISM, IAM-related) Soft SkillsCompetencies * Strong leadership and cross-functional collaboration * Ability to translate access risk into operational and compliance impact * Process-driven, detail-oriented, and highly organized * Calm, decisive decision-making during audits and incidents ## Description The Director of IdentityAccess Management (IAM) is responsible for the strategic leadership, governance, and operational oversight of identity and access services across NOR and its supported entities, including hospitals, business units, and affiliated organizations. This role ensures appropriate, secure, and timely access to systems and data for workforce members, clinicians, contractors, vendors, and partners while maintaining compliance with healthcare regulations, internal policies, and audit requirements. The Director serves as the primary authority for identity lifecycle management, access governance, and privileged access controls across the enterprise., StrategyLeadership * Define and maintain NOR's enterprise IAM strategy, roadmap, and long-term vision aligned with business and security objectives * Lead and mentor IAM managers, engineers, analysts, and offshore/onshore support teams * Serve as the escalation point for identity-related risks, incidents, and access failures * Partner closely with IT Security, Compliance, HR, Clinical Informatics, and Legal teams GovernanceCompliance * Establish and enforce IAM governance frameworks, policies, and standard operating procedures (SOPs) * Create, maintain, and regularly review IAM SOPs to ensure consistent, compliant access management practices * Ensure compliance with HIPAA, HITECH, SOX, and other regulatory requirements * Lead access reviews, user attestations, and audit responses * Maintain segregation of duties (SoD) and privileged access governance controls Identity Lifecycle Management * Oversee end-to-end identity lifecycle processes: * + Joiner / Mover / Leaver (JML) + Employee, contractor, vendor, and third-party access * Ensure timely provisioning and deprovisioning across clinical and business systems * Reduce access risk through automation and standardized workflows AccessPrivileged Identity Management * Lead implementation and optimization of: * + Role-based access control (RBAC) + Attribute-based access control (ABAC) where applicable + Privileged Access Management (PAM) * Ensure secure access to high-risk systems such as EHR/EMR, financial, and infrastructure platforms TechnologyArchitecture * Own IAM platforms and integrations (examples): * + Active Directory / Azure AD / Entra ID + SSO, MFA, Federation (SAML, OAuth, OpenID) + IGA tools (e.g., SailPoint, Saviynt, etc.) * Monitor service performance, SLAs, and key risk indicators * Evaluate and implement IAM solutions aligned with NOR standards * Ensure IAM processes and workflows are documented through clear, audit-ready SOPs IncidentRisk Management * Participate in identity-related incident root cause analysis * Remediate identified access risks per Security team's direction * Monitor IAM KPIs and risk indicators VendorStakeholder Management * Manage IAM vendors, contracts, and SLAs * Coordinate with third-party partners and affiliates on secure access * Communicate IAM initiatives and risks clearly to executive leadership ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)