IAM Engineer - Cloud Platform

Florida Blue•United States,
•$109,300 - $177,600•Hybrid

About The Position

GuideWell is migrating to AWS across commercial and GovCloud partitions. The IAM Engineer owns how identity works in that environment: federation from the enterprise identity provider, access lifecycle into cloud accounts, and the authorization model application teams build against. The enterprise identity team owns the identity provider and governance platform. This role owns the cloud side of the integration and the entitlement design within it.

Requirements

  • 6+ years related work experience in IAM, security, or platform engineering, with 3+ years focused on cloud identity
  • Related Bachelor's degree required
  • Strong AWS/Azure IAM skills, including cross-account access, federation, and permission boundaries.
  • Hands-on experience with SSO and federation platforms.
  • Experience integrating an enterprise identity provider such as Okta, Entra ID, or Ping with cloud.
  • Hands-on Terraform.
  • Working knowledge of SAML, OIDC, and SCIM.
  • Experience in an environment governed by HIPAA, HITRUST, SOC 2, FedRAMP, or NIST 800-53.

Nice To Haves

  • Identity engineering across a mix of GovCloud and commercial, including the cross-partition trust boundary.
  • Healthcare payer experience.
  • Privileged access management tooling such as CyberArk.
  • Identity governance and administration tooling such as SailPoint or Saviynt, and lifecycle automation.
  • Machine identity at scale, including workload federation and secrets management.
  • Python or equivalent scripting for identity automation.
  • Cloud Security Specialty, CCSP, or an identity-focused certification.

Responsibilities

  • Design and operate federation and the entitlement model across accounts
  • Automate access lifecycle: joiner, mover, leaver
  • Build workload identity patterns; eliminate long-lived keys and standing access
  • Build access recertification and produce audit evidence
  • Onboard applications to SSO and review access designs with application teams
  • Integrate cloud entitlements with the enterprise identity governance platform.
  • Build access recertification for cloud entitlements and produce evidence for audit.
  • Design workload and machine identity patterns, including roles for services and OIDC for pipelines.

Benefits

  • Medical, dental, vision, life and global travel health insurance
  • Income protection benefits: life insurance, short- and long-term disability programs
  • Leave programs to support personal circumstances
  • Retirement Savings Plan including employer match
  • Paid time off, volunteer time off, 10 holidays and 2 well-being days
  • Additional voluntary benefits available; and a comprehensive wellness program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service