About The Position

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you. We are seeking a Software Engineer with deep interest and experience in Identity & Access Management (IAM) to help design, build, and secure authentication and authorization capabilities across CoverMyMeds’ platforms. This role sits on a core IAM platform team that owns end‑user identity, federated authentication, and authentication infrastructure for web applications, partnering closely with Security, Product, and other engineering teams. This is a hands‑on individual contributor role in a product‑oriented, Kanban-driven environment, where impact is achieved through technical depth, secure engineering practices, and collaboration.

Requirements

  • 4+ years' experience building and shipping production software as an individual contributor.
  • Deep experience (4+ years) with Okta and/or Auth0 (policies, apps, federation, claims).
  • Hands-on experience (4+ years) implementing or integrating authentication and authorization using OIDC, OAuth 2.0, and/or SAML.
  • Strong understanding of secure engineering practices and common identity threats.
  • Experience working in at least one of the following: JavaScript/TypeScript, Ruby, Python, C#.
  • Ability to collaborate across engineering, product, and security teams and communicate technical decisions clearly.

Nice To Haves

  • Experience with SMART on FHIR, SCIM, directory integrations, or identity lifecycle management.
  • Familiarity with RBAC/ABAC, claims-based authorization, or policy engines.
  • Experience in regulated environments and audit support.
  • Experience improving reliability of critical auth systems (SLIs/SLOs, graceful degradation).

Responsibilities

  • Identity Engineering & Integrations Design, build, and maintain authentication and authorization solutions using OIDC, OAuth 2.0, and SAML.
  • Integrate applications and APIs with identity platforms such as Okta, Auth0, Ping, or Microsoft Entra ID.
  • Implement SSO, MFA, federated authentication, session management, and secure token handling.
  • Contribute to identity services such as login gateways, authorization middleware, claims transformation, and access policy enforcement.
  • Support SMART on FHIR (OAuth 2.0) use cases and unified authentication initiatives.
  • Security & Standards Apply industry-standard security practices including least privilege, secure defaults, defense in depth, and secure secret handling.
  • Partner with Security on threat modeling, risk reviews, and secure SDLC practices.
  • Implement identity solutions aligned with NIST-based identity and access control principles.
  • Software Development & Delivery Build production-quality systems using one or more of JavaScript/TypeScript, Ruby, Python, or C#.
  • Write clean, testable, maintainable code with strong engineering discipline (CI/CD, code reviews, automated testing).
  • Create clear technical documentation for APIs, integrations, and operational support.
  • Participate in on-call or operational support for critical identity services as needed.
  • Ways of Working Work within a Kanban delivery model, managing flow and continuously improving quality and throughput.
  • Collaborate with Product, Security, and stakeholders to define outcomes and manage tradeoffs.
  • Bring an enterprise-first mindset, constructively challenging designs and contributing new ideas.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service