Associate IAM Engineer

Tempus AIChicago, IL
$70,000 - $95,000Hybrid

About The Position

Passionate about precision medicine and advancing the healthcare industry? Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time. As an Associate IAM Engineer, you will be the frontline defender and administrator of our identity perimeter. You will focus on day-to-day identity operations, single sign-on (SSO) integrations, device assurance, and troubleshooting authentication issues. This role is perfect for someone with a strong foundational understanding of identity protocols (SAML, OIDC) who wants to grow their hands-on skills in enterprise automation, identity governance, and cloud identity management using Okta.

Requirements

  • 1–3 years of experience in an IT, Security, or Systems Administration role, with at least 1 year of dedicated hands-on exposure to Okta administration.
  • A solid conceptual understanding of the "Identity Trinity": SAML 2.0: Understanding assertions, entity IDs, and ACS URLs.
  • OpenID Connect: Basic understanding of tokens (ID, Access, Refresh), scopes, and authorization flows.
  • SCIM: Familiarity with how automated provisioning works.
  • Directory Services: Comfortable navigating and managing Universal Directory (managing users, groups, and basic OU structures).
  • RESTful APIs: Foundational understanding of REST API concepts (HTTP methods like GET, POST, PUT, DELETE, and status codes) and comfort using OKTA Workflows.
  • Security Mindset: Understanding of basic security principles like Multi-Factor Authentication (MFA), Least Privilege, and Zero Trust.
  • The "Log Detective": You enjoy digging into event logs and browser developer tools (SAML tracers) to find out exactly why a login failed.
  • Clear Communicator: Ability to guide non-technical employees (or partners in HR) through password resets, MFA setups, or access requests with patience and clarity.
  • Hungry to Learn: The identity space moves fast. You are excited to learn advanced tools like Okta Workflows, Terraform, or API management on the job.

Nice To Haves

  • Prior exposure to configuring Okta Device Assurance policies and a basic understanding of how they interface with MDM tools (e.g., Jamf, Intune) to check device posture.
  • Hands-on exposure to Okta Identity Governance (OIG) for managing access requests, approvals, and access certification campaigns.
  • Foundational knowledge or exposure to Okta Workflows (or similar low-code automation platforms) used to orchestrate lifecycle management.
  • Okta Certified Professional or Okta Certified Administrator.

Responsibilities

  • Configure, test, and deploy standard SAML 2.0 and OIDC/OAuth 2.0 integrations for onboarding new SaaS applications.
  • Serve as the Tier 2/3 point of contact for identity-related tickets.
  • Deep-dive into system logs and protocol traces to resolve authentication, MFA, and provisioning failures.
  • Monitor and maintain automated user provisioning (Joiner/Mover/Leaver processes) across HRIS, Active Directory, and downstream applications.
  • Help triage Okta Workflow errors.
  • Assist in configuring and monitoring Okta Device Assurance policies to ensure only secure, compliant devices can access corporate resources.
  • Support user access reviews and regular entitlement certifications using Okta Identity Governance (OIG) to ensure alignment with SOC2, ISO 27001, and SOX frameworks.

Benefits

  • incentive compensation
  • restricted stock units
  • medical and other benefits depending on the position
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service