Senior Identity Engineer

Versant Health•Troy, NY
•$150,000 - $160,000•Remote

About The Position

The Sr. Identity Engineer is a senior technical leader within Information Security's Identity & Access Management function, responsible for designing, implementing, and evolving identity security capabilities across workforce users, privileged accounts, external users, application identities, service accounts, AI-enabled agents, and automation identities. This role serves as a senior hands-on engineer and technical lead for complex identity security initiatives that protect enterprise systems and sensitive healthcare data through lifecycle automation, privileged access management, access governance, identity telemetry, customer identity services, and integration security controls. While remaining a hands-on engineering role, this position also provides technical leadership, engineering direction, and subject matter expertise for enterprise identity security initiatives. The engineer is expected to lead complex technical implementations, contribute to identity engineering standards, patterns, and operational practices, and provide technical recommendations and engineering expertise supporting the organization's identity security roadmap while continuing to support operational excellence. Partners with Security Engineering teams responsible for enterprise authentication and access protection controls, providing identity platform expertise, integrations, provisioning services, and governance automation. This role reports to the Senior Manager of Identity and Access Management and partners closely with service owners, security engineering, infrastructure, application teams, compliance, and business stakeholders to deliver secure, resilient, and audit-ready identity capabilities.

Requirements

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field preferred; equivalent engineering experience considered.
  • 7+ years of IAM, identity security, security engineering, or related enterprise technology experience; healthcare or other regulated industry experience preferred.
  • Demonstrated experience leading complex IAM or identity security initiatives from design through implementation in enterprise environments.
  • Hands-on experience with Microsoft Entra ID and Active Directory required; experience with Entra ID Governance preferred, including lifecycle workflows, entitlement management, access packages, access reviews, and PIM.
  • Proficiency with PowerShell and Microsoft Graph API required; Python, REST API, SCIM, LDAP, and ServiceNow workflow experience preferred.
  • Experience with privileged access management, vaulting concepts, and non-human identity governance including service accounts, app registrations, service principals, managed identities, API keys, webhook secrets, and certificates.
  • Familiarity with SIEM/log management, identity event correlation, detection tuning, and identity-related incident response activities.
  • Understanding of HIPAA, HITECH, HITRUST, NIST, and audit/evidence expectations in identity and access management environments.
  • Strong written and verbal communication skills with the ability to explain technical identity concepts to security, compliance, audit, application, infrastructure, and business stakeholders.

Nice To Haves

  • healthcare or other regulated industry experience preferred
  • experience with Entra ID Governance preferred, including lifecycle workflows, entitlement management, access packages, access reviews, and PIM
  • Python, REST API, SCIM, LDAP, and ServiceNow workflow experience preferred

Responsibilities

  • Maintain authoritative records, ownership information, classification, and lifecycle status for enterprise human and non-human identities.
  • Lead the design, implementation, and support of enterprise identity lifecycle automation across joiner, mover, leaver, transfer, and termination processes.
  • Engineer HRIS-driven identity lifecycle workflows integrating the enterprise HR platform with Active Directory, Microsoft Entra ID, Entra ID Governance, ServiceNow, and downstream business applications.
  • Build and maintain automated provisioning, modification, and deprovisioning processes using Microsoft Graph API, PowerShell, SCIM, REST APIs, access packages, lifecycle workflows, group-based automation, and documented request/evidence records.
  • Develop reusable automation patterns that improve accuracy, reduce manual access handling, and support secure, timely access changes across workforce, privileged, external, and application identities.
  • Establish and maintain governance standards, onboarding requirements, lifecycle controls, ownership requirements, review processes, and registry capabilities for non-human identities, including service accounts, app registrations, service principals, managed identities, API keys, webhook secrets, certificates, AI-enabled agent identities, and automation accounts.
  • Define ownership, purpose, scope, lifecycle, credential rotation, access review, monitoring, and decommissioning requirements for non-human identities across enterprise platforms and applications.
  • Partner with application, infrastructure, cloud, and security teams to ensure non-human identities are created, secured, documented, reviewed, and retired in alignment with identity security and audit requirements.
  • Support privileged and sensitive non-human identity use cases through vaulting, least privilege, credential management, privileged access controls, and evidence documentation.
  • Serve as a senior engineering resource for Microsoft Entra ID, Active Directory, Entra ID Governance, Entra External ID, Microsoft Graph API, and related hybrid identity capabilities.
  • Design and support Entra ID Governance capabilities including lifecycle workflows, entitlement management, access packages, access reviews, identity lifecycle policies, and governed access models.
  • Engineer identity platform configurations, automation, access control patterns, provisioning models, entitlement structures, integration standards and patterns, and governance controls that support identity lifecycle management, authorization, and access governance.
  • Provide advanced troubleshooting and technical guidance for identity issues involving Entra ID, Active Directory, SSO, federation, authentication flows, directory synchronization, group-based access, and application onboarding, partnering with Security Engineering on Conditional Access, authentication strength, and related identity protection controls.
  • Design and maintain scalable entitlement models including role-based access, baseline access, group and role structures, least-privilege assignments, privileged entitlements, and separation-of-duties controls.
  • Engineer and support privileged identity capabilities including privileged account lifecycle, vault integration, credential rotation, privileged entitlement management, and Microsoft Entra PIM.
  • Lead identity engineering support for application onboarding and integration patterns involving Microsoft Entra ID, Entra External ID, Active Directory, SSO, SCIM, SAML, OAuth/OIDC, LDAP, REST APIs, and Microsoft Graph API.
  • Partner with application owners and business teams to design secure authentication, authorization, provisioning, deprovisioning, and access governance models for enterprise and healthcare-related applications.
  • Support Entra External ID engineering for member, provider, client, and business partner identity use cases, including registration, MFA, SSO, conditional access alignment, account recovery, and authentication/authorization troubleshooting.
  • Design and govern identity controls for healthcare and business integration patterns such as SFTP, EDI, claims/eligibility API clients, regulated data pipeline accounts, and application-specific service identities.
  • Provision and govern AI-enabled agent and automation identities with clear ownership, allowed actions, least privilege, vaulting, monitoring, traceability, and disablement procedures.
  • Support access certification, entitlement review, and remediation processes through automation, workflow integration, and clear operational documentation.
  • Ensure identity controls and automation processes support HIPAA, HITRUST, SOX, and SOC 2 by maintaining audit-ready evidence, reporting, and control documentation for access reviews, remediation activities, regulatory audits, and internal governance needs.
  • Ensure identity platforms, applications, lifecycle systems, and privileged/non-human identity services generate appropriate security telemetry and make required logs available to Security Operations.
  • Partner with Security Operations to provide identity context, account ownership, entitlement information, authentication history, credential status, and other identity data needed to investigate security events.
  • Support incident containment and remediation through credential revocation, account disablement, access removal, session revocation, and other identity-specific response actions.
  • Partner with Security Operations and Security Engineering to improve identity-related detection coverage by identifying relevant telemetry, event sources, and identity context.
  • Document reusable identity engineering patterns, integration standards, operational procedures, and support models for Entra, lifecycle automation, non-human identities, and application integrations.
  • Serve as a senior technical advisor for identity engineering initiatives and mentor engineers on identity platform design, application onboarding, automation practices, and non-human identity governance.

Benefits

  • medical, dental, and paid vision coverage
  • paid time off and company holidays
  • retirement savings with employer contribution
  • employee wellness resources
  • professional development opportunities
  • flexible work arrangements
  • employee assistance programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service