Sr. Identity and Access Management Engineer

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

NJ

Posted

88 days ago

Salary

$127K - $160K / year

Seniority

Senior

Job Description

Sr. Identity and Access Management Engineer

Zelis

At Zelis, we Get Stuff Done. So, let’s get to it! A Little About Us Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients. A Little About You You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are. Position Overview Lead for Single Sign One (SSO) and cloud-based authentication and multi-factor authentication (MFA) policy management. Overview We are seeking a highly skilled and motivated Senior IAM Engineer to join the Identity and Access Management (IAM) team. This is a hands-on technical engineering role focused on designing, implementing, and supporting enterprise Single Sign-On (SSO) integrations, Multi-Factor Authentication (MFA), and access control policies within Microsoft Azure (Entra ID). This role is ideal for someone who thrives in dynamic environments and is passionate about Security, Identity Architecture, Authentication Protocols, and Automation. The position will work closely with IAM peers across Identity Governance (SailPoint) and Privileged Access Management (CyberArk) to ensure cohesive and secure identity operations across the enterprise. Key Responsibilities - Lead the design, implementation, and ongoing management of enterprise Single Sign-On (SSO) integrations within Microsoft Entra ID (Azure AD), including SAML, OAuth, and OpenID Connect (OIDC) configurations. - Configure and manage application provisioning integrations using SCIM and Just-In-Time (JIT) methodologies, including attribute mappings, profile transformations, and lifecycle alignment with upstream identity sources. - Manage and evolve the organization’s Multi-Factor Authentication (MFA) strategy. Ensure secure configuration, policy enforcement, and user experience optimization. - Assist in the configuration and ongoing management of Conditional Access Policies, including risk-based access controls, device compliance requirements, location-based controls, and Zero Trust alignment. - Support and manage Azure App Registrations in alignment with enterprise standards, including delegated and application permissions, client secrets/certificates, API exposure, and service principal configurations. - Partner closely with the Identity Governance (IGA) and Privileged Access Management (PAM) teams to ensure SSO integrations, application onboarding, access provisioning, and privileged access controls are properly aligned. - Troubleshoot authentication, federation, and token-related issues across SAML/OIDC flows, performing root cause analysis and implementing durable engineering solutions. - Drive automation and process improvement initiatives using PowerShell, Microsoft Graph API, and related tools to enhance operational efficiency and scalability. - Develop and maintain comprehensive knowledge articles, architecture diagrams, and SOPs related to SSO, MFA, Conditional Access, and Azure identity configurations. - Stay current on emerging identity security threats, authentication standards, and Microsoft roadmap updates to proactively strengthen enterprise authentication posture. Qualifications - Proven technical experience implementing and managing enterprise Single Sign-On (SSO) solutions in Microsoft Entra ID (Azure AD). - Strong hands-on experience with authentication and federation protocols including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and SCIM. - Experience configuring and managing Multi-Factor Authentication (MFA) solutions (Duo and/or Microsoft Authenticator preferred). - Working knowledge of Conditional Access Policy design and implementation within Azure. - Experience with Azure App Registrations, service principals, and API permission management. - Proficiency in PowerShell scripting and experience leveraging Microsoft Graph API for automation and identity management tasks. - Strong troubleshooting skills related to authentication flows, token issuance, federation errors, and provisioning integrations. - Excellent communication and collaboration skills with the ability to work cross-functionally across security, infrastructure, development, and governance teams. Preferred Qualifications - Microsoft certifications (e.g., SC-300: Identity and Access Administrator Associate). - Experience with identity governance platforms (e.g., SailPoint) and privileged access management tools (e.g., CyberArk). - Experience supporting enterprise MFA migrations or modernization initiatives. - Familiarity with compliance frameworks such as SOX, HIPAA, or other regulated industry requirements. #LI-REMOTE Please note at this time we are unable to proceed with candidates who require visa sponsorship now or in the future. Location and Workplace Flexibility We have offices in Atlanta GA, Boston MA, Morristown NJ, Plano TX, St. Louis MO, St. Petersburg FL, and Hyderabad, India. We foster a hybrid and remote friendly culture, and all our employee's work locations are based on the needs of the position and determined by the Leadership team. In-office work and activities, if applicable, vary based on the work and team objectives in accordance with Company policies. Base Salary Range $127,000.00 - $160,550.00 At Zelis we are committed to providing fair and equitable compensation packages. The base salary range allows us to make an offer that considers multiple individualized factors, including experience, education, qualifications, as well as job-related and industry-related knowledge and skills, etc. Base pay is just one part of our Total Rewards package, which may also include discretionary bonus plans, commissions, or other incentives depending on the role. Zelis’ full-time associates are eligible for a highly competitive benefits package as well, which demonstrates our commitment to our employees’ health, well-being, and financial protection. The US-based benefits include a 401k plan with employer match, flexible paid time off, holidays, parental leaves, life and disability insurance, and health benefits including medical, dental, vision, and prescription drug coverage. Equal Employment Opportunity Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. We welcome applicants from all backgrounds and encourage you to apply even if you don’t meet 100% of the qualifications for the role. We believe in the value of diverse perspectives and experiences and are committed to building an inclusive workplace for all. Accessibility Support We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email TalentAcquisition@zelis.com. Disclaimer The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities, duties, and skills from time to time.

Related Categories

Related Job Pages

More Security Engineer Jobs

Binary Defense logo

Strategic Account Manager – Managed Security Services

Binary Defense

Real people detecting real threats in real time.

OtherRemoteTeam 51-200Since 2014H1B No Sponsor

• Building relationships with your existing enterprise client base to ensure they are engaged with their service and finding value in overall partnership for accounts equal or more than $250K+ in spend • Ensuring your clients are getting the highest return on their investment from their service • Strategically partnering with your clients to understand their key security related business challenges, roadmapping related services, and initiatives • Partnering with internal teams to manage and retain client relationships and build client loyalty • Ensuring client satisfaction, retention, operational efficiency and quality of service for strategic and Tier 1 accounts. (CV = $5-10M) • Growing existing business with product portfolio and additional services based on annual recurring revenue to meet monthly, quartetly, and annual quotas • Acquiring new business for through current client referrals • Onboarding new clients and continuing to engage on a regular basis (weekly/monthly/quarterly) with business reviews and regular proactive outreach. • Traveling quarterly to each client to present business reviews with executive sponsorship. • Supporting the strategic account plan delivery model with white glove service and proactively partnering. • Contributing to the sales team and customer success team for business iniatives and training support.

Texas
Job Closed
Veeam Software logo

Senior Account Executive – Security & Defense

Veeam Software

Your Single Backup and Data Management Platform for Cloud, Virtual and Physical

ContractRemoteTeam 1,001-5,000Since 2006H1B Sponsor

• Own the book of business inlcluing new business development, renewals and expansion opportunities • Drive solution selling across existing customer base and new prospects • Build and execute strategic account plans, executive level engagement and ELPs • Generate and maintain healthy pipeline and development is part of daily routine • Maintain renewal and generate up-sell and cross-sell to the existing customer base  • Forecast on revenue expectations and report on activities coming from accounts • Weekly field meetings with customers

Saudi Arabia
Zimperium logo

Senior Software Engineer – Network Security

Zimperium

The leader in enterprise mobile endpoint protection and mobile app protection for Android, iOS and Chromebooks threats

Full TimeRemoteTeam 201-500Since 2010H1B Sponsor

• Design, develop, debug, while ensuring scalability, performance and security. • Perform development on complex systems, requiring an understanding of both business objectives and technical architecture. • Adapt and respond quickly to changing requirements and provide deliverables in a timely manner. • Collaborate with cross functional team members, including Product Management, Customer Success, QA, DevOps and Site Reliability Engineering to ensure we meet the business needs in a timely fashion.

Latvia
Job Closed
Jobgether logo

Staff Corporate Security Engineer

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteH1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role offers an exciting opportunity to safeguard enterprise systems and employees in a dynamic, high-growth technology environment. You will be a key player in defending corporate infrastructure from malware, phishing, and unauthorized access while driving the development and deployment of advanced security controls. The position combines hands-on technical work with strategic security initiatives, including incident response, threat hunting, digital forensics, and tool development. You will collaborate across teams to strengthen identity, endpoint, and network security, while continuously improving detection and response workflows. This is an ideal position for a self-motivated security professional who thrives in a fast-paced, innovative environment and wants to make a measurable impact on organizational security. - Lead incident response efforts, including malware, phishing, and digital forensics investigations. - Design, deploy, test, and evaluate corporate security controls across endpoints, identity providers, and networks. - Hunt threats and analyze logs to detect vulnerabilities or security breaches. - Implement and optimize security alerts, workflows, and automated processes to enhance the incident response lifecycle. - Deploy, configure, and manage security tooling with a focus on measurable impact. - Collaborate with internal teams to remediate vulnerabilities and strengthen corporate IT infrastructure. - Maintain documentation, reports, and security metrics to support continuous improvement and compliance initiatives. Qualifications - Bachelor’s degree in Computer Science, Cybersecurity, or related field. - 7+ years of experience in security engineering, incident response, or related technical security roles within a tech company. - Proficiency with security monitoring tools such as Crowdstrike, Splunk, or equivalents. - In-depth understanding of attacker tools, techniques, detection, prevention, and incident response methodologies. - Experience securing endpoints with MDM tooling (Kandji, Intune) and cloud-based identity solutions (Okta, Google Workspace). - Familiarity with cloud platforms such as GCP or Alibaba Cloud is preferred. - Strong scripting skills in Python, Bash, or Powershell for automation and tool development. - Excellent communication skills to explain technical concepts to non-technical stakeholders. - Self-motivated, curious, and able to operate in a fast-paced, high-growth startup environment. Benefits - Competitive salary and potential equity opportunities. - Comprehensive medical, dental, and vision coverage. - Remote-first work environment with flexibility for work location. - Professional development and training opportunities. - Paid time off, sick leave, and company-recognized holidays. - Access to wellness stipends and technology allowances.

United States
Job Closed