Cloud IAM Engineer
About HealthEdge
HealthEdge® offers AI-powered operational infrastructure for health insurance companies, guaranteeing an enduring financial edge in an increasingly competitive market. We're experiencing strong market momentum, with a growing number of health plans choosing HealthEdge to modernize their operations and compete more effectively. As we expand, we're investing in the people who power that growth, making this a pivotal moment to join us and shape the future of healthcare technology.
HealthEdge’s mission is to revolutionize healthcare through transaction automation and the enablement of real-time business and clinical engagement among healthcare payers, providers, and patients. Our team works to deliver technology that powers some of the most complex health plan organizations in the country — organizations responsible for the care and coverage of millions of members. Our product portfolio — HealthRules Payer, GuidingCare, Wellframe, and Source — addresses the full spectrum of payer operations, from core administrative processing to care management and member engagement.
We are growing, we are building, and we are looking for people who want to grow and build alongside us. If you are looking for a role where your work has direct relevance to how healthcare gets delivered, and where your development is taken seriously, HealthEdge is that place. HealthEdge is committed to an inclusive workplace where every employee has the opportunity to belong, make an impact, and do the best work of their career.
Position Overview
We're seeking a Cloud IAM Operations Engineer to manage day-to-day identity and access provisioning across our AWS environment. This is a hands-on, execution-focused role; you'll review incoming access requests against least-privilege principles and implement approved access using Infrastructure as Code. This role operates in alignment with established policy rather than defining it, and you'll partner closely with security architecture on escalations and edge cases.
Responsibilities
- Review AWS access requests against least-privilege and organizational access policy
- Provision and implement approved access using Infrastructure as Code (CDK preferred; or similar IaC tools considered)
- Manage and maintain the organization's Just-In-Time (JIT) access management tool, ensuring all human-use AWS access is provisioned on-demand through JIT workflows rather than persistent permissions, reinforcing least-privilege and audit readiness
- Maintain accurate, auditable records of access grants, changes, and revocations
- Identify and escalate access requests that fall outside standard policy or carry elevated risk
- Support periodic access reviews and recertification processes
- Contribute to runbooks and documentation to improve consistency and repeatability of the access request lifecycle
- Partner with security architecture and IAM leadership on process improvements and automation opportunities
- Conduct periodic reviews of AWS IAM permission sets using IAM Access Analyzer and other tooling to identify unused permissions and overly permissive policies, refining access controls to align with least-privilege principles across the environments
Requirements
- 2–4 years of experience in cloud security, IAM, or cloud technologies in AWS
- Working experience with AWS IAM fundamentals (roles, policies, permission sets, least-privilege design)
- Strong interpersonal and communication skills alongside relevant technical experience
- Working experience with Infrastructure as Code (CDK preferred; Pulumi, or CloudFormation also considered)
- Understanding of access review and audit requirements in a regulated environment
- Working experience implementing or administering Just-In-Time (JIT) access management tools in a cloud environment, with a strong understanding of least-privilege access principles and standing-access risk reduction
- Strong attention to detail and sound judgment on what access should and shouldn't be granted
- Clear written communication for documentation and access decision records
Preferred Experience
- Experience in a healthcare or other regulated industry (HIPAA/HITRUST-aware)
- Familiarity with identity governance tooling and access certification workflows
- Basic scripting ability (Python, TypeScript, or similar) to support IaC workflows
Pay
The annual US base salary range for this position is $107,000 to $114,000.
Schedule
Full-time, permanent
Work Environment
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job:
- The employee is occasionally required to move around the office.
- Specific vision abilities required by this job include close vision, color vision, peripheral vision, depth perception, and ability to adjust focus.
- Work across multiple time zones in a hybrid or remote work environment.
- Long periods of time sitting and/or standing in front of a computer using video technology.
- May require travel dependent on company needs.