Principal Security Access Engineer

HealthEquityRemote,
$133,000 - $173,000Remote

About The Position

HealthEquity is seeking an experienced and highly motivated Principal IAM Security Access Engineer to join our Security & IT team. This role is critical to the design, implementation, and management of our identity, access, and privileged access management (IAM/PAM) systems — spanning human, non-employee, service, and AI agent identities. The ideal candidate has deep, hands-on experience with SailPoint Identity Security Cloud (ISC) and Non-Employee Risk Management (NERM), BeyondTrust, Microsoft Entra (including Conditional Access), and Silverfort, along with a strong point of view on how identity security must evolve to govern AI agents, non-human identities, and machine-to-machine access. This role requires a deep understanding of IAM principles, excellent problem-solving skills, and the ability to mentor and guide team members while exercising indirect leadership and influence across all levels of the organization.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • Minimum of 5 years of experience in IAM, with at least 3 years in a senior or principal engineer role.
  • Extensive, hands-on experience with SailPoint Identity Security Cloud (ISC); experience with Non-Employee Risk Management (NERM) strongly preferred.
  • Strong understanding of Privileged Access Management (PAM) and hands-on experience with BeyondTrust.
  • Proficiency with Microsoft Entra (formerly Azure AD), including Conditional Access policy design and administration.
  • Zero Trust expertise with technologies such as Silverfort.
  • Working knowledge of secrets management and vaulting platforms for securing credentials, keys, and tokens used by applications, service accounts, and automations.
  • Familiarity with identity considerations for AI agents and non-human identities — authentication patterns, scoped authorization, credential lifecycle, and monitoring for agentic/automated access.
  • Proficiency in scripting and automation (e.g., REST APIs, PowerShell) for IAM tasks.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Strong communication and interpersonal skills, with the ability to work effectively with and influence stakeholders at all levels.

Nice To Haves

  • Relevant certifications such as CISSP, CISM, or IAM-related certifications are highly desirable.

Responsibilities

  • Implementation of robust IAM/PAM solutions using SailPoint Identity Security Cloud, BeyondTrust, Microsoft Entra, Silverfort, and other IAM tools/platforms.
  • Help develop and maintain IAM strategies; including governance for AI agents, non-human identities (NHIs), and machine-to-machine access — that align with organizational goals and industry best practices.
  • Function as a subject matter expert for IAM technologies and processes, including emerging practices for agentic AI identity, authorization, and lifecycle management.
  • Clearly articulate strategic initiatives, gain buy-in, and establish a shared understanding with key decision makers at the leadership level.
  • Manage the configuration and administration of SailPoint ISC (including NERM for non-employee identity risk), BeyondTrust, Microsoft Entra, and Silverfort.
  • Design and manage Conditional Access policies within Microsoft Entra to enforce risk-based, adaptive access controls across users, devices, and workloads.
  • Partner closely with the IAM Governance team to implement IAM policies, standards, and procedures using IAM & PAM tools and processes.
  • Ensure seamless integration of IAM systems with applications, services, secrets management/vaulting platforms, and CI/CD pipelines.
  • Implement governance models for AI agents and service accounts, including credential issuance, scoped permissions, rotation, and decommissioning.
  • Drive timely execution of IAM & PAM initiatives in alignment with strategic and tactical plans.
  • Establish identity and access frameworks for AI agents and autonomous workflows, ensuring least-privilege access, auditability, and policy enforcement equivalent to human identity controls.
  • Evaluate and integrate secrets management solutions to secure credentials, API keys, and tokens used by AI agents, automations, and service-to-service connections.
  • Assess and pilot AI-assisted capabilities within IAM tooling (e.g., SailPoint AI, Entra ID Protection risk signals, Silverfort risk analytics) to improve access certification accuracy, anomaly detection, and operational efficiency.
  • Help IAM projects go from initiation to completion, ensuring timely delivery and alignment with project goals.
  • Coordinate with cross-functional teams, including IT, HR, Security, and business units, to gather requirements and ensure successful project outcomes.
  • Manage project timelines and resources effectively.
  • Provide indirect leadership and guidance to IAM engineers and other IAM team members.
  • Conduct training sessions and workshops — including on AI/agentic identity risk — to enhance the skills and knowledge of the team.
  • Foster the culture of continuous improvement and professional development within the IAM team.
  • Provide advanced troubleshooting and support for IAM-related issues, including scripting/automation via APIs and PowerShell.
  • Develop and maintain documentation for IAM processes, configurations, and troubleshooting procedures.
  • Stay current with industry trends and emerging technologies, particularly around AI, agentic systems, and non-human identity security, to continually enhance the IAM landscape.

Benefits

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education & tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service