Identity and Access Administrator

Ellis MedicineSchenectady, NY

About The Position

Working independently, the Identity and Access Administrator is responsible for provisioning, modifying, and deprovisioning user accounts across enterprise systems and for administering the organization’s Identity and Access Management (IAM) platform, security group memberships, and clinical system access. This role executes role-based access provisioning driven by HR records, supports system-specific access across clinical and business applications, builds provider and non-employee/contractor profiles following credentialing and confidentiality requirements, and ensures secure access management, compliance with organizational policies, and efficient delivery of messaging and collaboration services.

Requirements

  • Associate’s degree in Information Technology, Management of Information Systems, or a related field; or Three or more years of experience administering Active Directory and/or managing the user account lifecycle and IAM role-based provisioning.

Responsibilities

  • Creates, modifies, disables, and removes user accounts based on approved requests, managing employee onboarding, transfers, and offboarding account activities.
  • Processes new-hire and role changes originating in HR systems, updating access when HR changes a user’s role.
  • Builds and maintains role-based access using IAM role templates, such as RN, PCT, and physician templates, so users receive standard access appropriate to their job role.
  • Ensures accurate user attribute management, account lifecycle administration, and compliance with access governance and security policies.
  • Troubleshoots account access and authentication issues.
  • Processes extended or non-standard access requests, such as finance access and appointment management.
  • Handles one-off and miscellaneous access changes while maintaining proper authorization controls.
  • Routes requests for access outside standard roles to the appropriate manager or director for approval before processing in IAM.
  • Builds provider access upon EHIS credentialing notifications from the Medical Staff Office, using IAM templates and specialty folders.
  • Supports external and business-arrangement practices that allow credentialed providers to access systems, coordinating with staff who maintain approved-practice lists.
  • Creates non-employee profiles for external credentialed providers and contractors after required confidentiality forms and paperwork are received and validated.
  • Creates, modifies, and manages security and distribution groups and reviews group memberships according to business requirements.
  • Manages shared calendar access through group membership and performs periodic access audits and certification reviews.
  • Implements role-based access controls (RBAC) and ensures least-privilege access principles are followed.
  • Disables accounts across Active Directory, IAM, Cerner, and other systems upon receipt of HR termination lists.
  • Maintains and updates IAM role templates to add or remove access groups as business needs evolve, applying specialized knowledge to modify templates and manage groups not always visible within IAM.
  • Documents procedures, standards, and technical configurations and provides Tier 2/3 support for identity and messaging-related incidents and requests.
  • Collaborates with Security, Infrastructure, HR, the Medical Staff Office, and Application teams and participates in system upgrades, migrations, and projects.
  • Adheres to established department security policies and follows procedures in addressing security violations.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service