Staff IAM Engineer - Executive Support

CVS HealthNew York, NY
$142,140 - $284,280

About The Position

The Staff IAM Engineer - Executive Operations plays a critical role in ensuring the reliability, security, and effectiveness of the organization's identity and access management services. This position is responsible for supporting and improving core IAM operations across Active Directory, Entra ID, cloud IAM platforms, and privileged access solutions, helping ensure users have the access they need while maintaining strong security controls and compliance with regulatory requirements. Through operational excellence, process improvement, and technical expertise, the role helps strengthen the organization's identity security posture and advance the maturity of the IAM program. In addition to supporting enterprise IAM operations, this role provides specialized support for executive leadership and other high-profile users, requiring a high degree of professionalism, discretion, and responsiveness. Acting as a trusted partner to executives and senior stakeholders, the Staff IAM Engineer helps resolve complex access issues, navigate sensitive situations, and deliver a high-touch service experience in a 24x7 environment.

Requirements

  • 7+ years of experience in Identity & Access Management or related security domains
  • 3+ years of hands-on experience with Active Directory, Entra ID, and cloud IAM platforms (e.g., GCP IAM)
  • 3+ years of experience implementing IAM solutions in enterprise or regulated environments
  • 3+ years of experience supporting audit and compliance requirements (e.g., HIPAA, SOX)

Nice To Haves

  • Experience with infrastructure-as-code or policy-based IAM (e.g., GCP Config Connector)
  • Familiarity with cloud security tools and IAM risk insights platforms (e.g., Security Command Center)
  • Experience with PAM tools such as CyberArk, HashiCorp Vault, or similar solutions
  • Understanding of Privileged Access Management concepts and tools
  • Strong problem-solving and systems design skills
  • Industry certifications such as CISSP, CISM, or cloud security certifications
  • Experience in healthcare or other highly regulated industries

Responsibilities

  • Support execution of enterprise IAM strategy across cloud and hybrid identity platforms.
  • Implement and maintain cloud-first identity patterns leveraging Entra ID while supporting and modernizing on-premises Active Directory.
  • Enforce IAM best practices, including least privilege, group-based access controls, and time-bound privileged access.
  • Support Active Directory security hardening, baseline configurations, and enterprise control requirements.
  • Contribute to Privileged Access Management (PAM) solutions for human and service identities.
  • Partner with Security, Infrastructure, GRC, and Application teams to implement and enhance IAM controls and services.
  • Serve as a senior technical escalation point for complex identity and access management issues.
  • Provide guidance on IAM risks, access decisions, and security design tradeoffs.
  • Support audit, regulatory, and compliance activities, including HIPAA and SOX requirements.
  • Design and maintain Active Directory organizational structures, Group Policy configurations, and access management models.
  • Develop and maintain permission structures that reduce privilege creep and support least-privilege access.
  • Analyze identity and access data to support security investigations, audits, and compliance reviews.
  • Participate in access certification reviews and remediation efforts for excessive or inactive access.
  • Support secure IAM architecture patterns across cloud and hybrid environments.
  • Monitor and improve IAM service health, availability, and operational performance.
  • Lead troubleshooting and root cause analysis for complex identity-related incidents and service disruptions.
  • Support identity lifecycle processes including provisioning, deprovisioning, and access modifications.
  • Maintain operational procedures, runbooks, and technical documentation.
  • Participate in on-call rotations and incident response activities.
  • Support disaster recovery and business continuity planning for IAM platforms.
  • Identify recurring operational issues and drive long-term remediation and service improvements.
  • Provide dedicated support for executive leadership and other high-priority users requiring expedited identity and access services.
  • Manage sensitive access requests, escalations, and incidents with professionalism, discretion, and urgency.
  • Build trusted relationships with executive stakeholders while ensuring adherence to security policies and access governance standards.
  • Deliver a high-touch support experience while balancing business needs, risk, and security requirements.
  • Mentor engineers and promote IAM best practices, operational excellence, and reusable design patterns.
  • Develop documentation, training materials, and knowledge-sharing resources to improve team effectiveness and consistency.
  • Support onboarding and development of team members and contingent resources.
  • Drive improvements to identity lifecycle management, access provisioning, and operational workflows.
  • Contribute to automation initiatives that improve service reliability, efficiency, and compliance.
  • Evaluate emerging IAM and PAM technologies to support evolving business and security needs.
  • Identify opportunities to enhance the user experience, strengthen security controls, and increase operational scalability.
  • Support execution of the IAM roadmap and organizational priorities.
  • Contribute to ongoing improvements in identity governance, access management, and operational maturity.
  • Help balance security, usability, and compliance when implementing IAM solutions.
  • Support the transition of new IAM capabilities and services into sustainable operational processes.

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service