Senior Access Management Analyst IGA

GoHealth Urgent CareRochester, MN
Onsite

About The Position

The Senior Access Management Analyst is responsible for managing and enhancing our Identity Governance and Administration (IGA) processes. This role ensures secure, compliant, and efficient access to critical systems across the Company and our network of urgent care centers. The Senior Access Management Analyst will collaborate with teams across the Company such as urgent care center teams, Operations, People, Finance and IT to maintain a secure and efficient identity and access management (IAM) framework, supporting multi-market onboarding and application specific access management needs.

Requirements

  • Bachelor’s degree in computer science, Information Technology, or related field
  • Experience may be accepted in lieu of a degree.
  • Certifications such as SailPoint Certified Engineer, Okta Certified Professional, or equivalent
  • 3+ years of experience in Identity Governance and Administration (IGA), including user lifecycle management.
  • Strong working knowledge of IGA platforms such as SailPoint, Saviynt, or similar tools.
  • Experience with IAM solutions such as Okta and Microsoft Entra, including workflows and integrations.
  • This role involves interaction and collaboration with other departments and requires excellent judgment and interpersonal skills.
  • Deep knowledge of Identity Governance and Administration (IGA) concepts and practices, including user lifecycle management, access certifications, segregation of duties, and access risk remediation in regulated environments.
  • Strong skill in designing, implementing, and maintaining Role-Based Access Control (RBAC) models.
  • Ability to integrate and manage access for SaaS, cloud, and on‑premise applications, leveraging IGA platforms, SCIM-based provisioning, and standard authentication protocols (e.g., SAML, OAuth, OIDC).
  • Working knowledge of healthcare and regulatory compliance requirements (e.g., HIPAA, SOX, GDPR) as they relate to identity, access controls, audits, and access certification programs.
  • Strong analytical and problem‑solving skills, with the ability to assess access risks, identify gaps in IAM controls, and recommend practical, compliant improvements in a fast‑paced environment.
  • Demonstrated ability to collaborate cross‑functionally, partnering effectively with IT, People, Operations, Compliance, Finance, and application owners.
  • Effective communication and documentation skills, including the ability to clearly document IAM processes, access models, and integrations, and to explain complex access governance concepts to non‑technical stakeholders.
  • Ability to drive continuous improvement and automation, applying judgment and initiative to enhance IAM efficiency, access accuracy, and governance maturity while supporting secure customer care operations.

Nice To Haves

  • Experience working in the healthcare industry with systems like EMRs (Electronic Medical Records) or other clinical applications.
  • Knowledge of Active Directory, Azure AD, and cloud security best practices.
  • Familiarity with NIST Cybersecurity Framework and Zero Trust Architecture.

Responsibilities

  • Develop, implement, and maintain IGA frameworks, policies, and access controls.
  • Manage user lifecycle processes including provisioning, deprovisioning, role changes, and terminations.
  • Implement and maintain RBAC models and RBAC-based provisioning rules for enterprise and clinical applications, including EMRs.
  • Optimize IGA configurations and integrations with Okta, SailPoint, EMRs, and enterprise applications.
  • Continuously improve IAM automation, access accuracy, and governance practices to support secure patient care operations.
  • Ensure IAM compliance with applicable regulations, including HIPAA, SOX, and GDPR.
  • Design, deploy, and manage access certification campaigns for managers and application owners in collaboration with GRC.
  • Support audits, access reviews, reporting, and remediation of access risks.
  • Apply Zero Trust security principles to protect critical systems and sensitive data.
  • Integrate IGA platforms with SaaS applications and cloud platforms (AWS, Azure, GCP) using out-of-box connectors and SCIM-enabled integrations.
  • Partner with application owners to define access requirements and design appropriate RBAC models.
  • Collaborate cross-functionally with IT, People, EMR, Operations, Finance, and Compliance teams to support onboarding, role changes, and multi-market growth.
  • Maintain clear documentation for IAM processes, access models, integrations, and configurations.
  • Provide guidance and training to stakeholders on IAM best practices and access governance.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service