Engineer III, Identity and Access Management
PDS Health · Irving, TX · 3 wk ago
Engineering$104k–$136k/yrFull-time
About the role
The Engineer III, Cybersecurity & Risk Mgmt. - Identity & Access Management independently owns and executes Identity Governance & Administration (IGA) functions — including identity lifecycle management, access certifications, entitlement governance, and SaaS security posture — with minimal supervision. Embedded within the IAM team under Cybersecurity & Risk Mgmt., this position carries primary ownership of day-to-day IGA operations and tooling, applying critical thinking to resolve complex access challenges and ensuring all deliverables meet quality and compliance standards.
Responsibilities
- Own and maintain the IGA technical roadmap, governance frameworks, and entitlement catalog, ensuring identity capabilities are consistently implemented and aligned to organizational policy.
- Manage the full identity lifecycle for all human and non-human entities — including automated joiner, mover, and leaver (JML) workflows — ensuring secure and auditable provisioning and deprovisioning across enterprise and clinical systems.
- Design, build, and continuously optimize role-based access control (RBAC) frameworks, including role mining, role design, and access request workflows, to enforce least-privilege principles across all environments.
- Define, implement, and maintain Segregation of Duties (SoD) policies; perform conflict detection and lead remediation workflows in partnership with Compliance and application owners.
- Lead and execute periodic access certification and recertification campaigns, ensuring timely completion, appropriate reviewer engagement, and documented outcomes for audit purposes.
- Manage SaaS application access governance, including shadow IT discovery, OAuth grant reviews, and SaaS-to-SaaS integration risk remediation, using the organization's IGA and SaaS security posture toolset.
- Architect and maintain integrations between IGA platforms and authoritative sources (HR systems, directories) and downstream applications, including EHR/EMR platforms, using SCIM, REST APIs, SAML, and other standards-based protocols.
- Author and maintain comprehensive technical documentation including architectural diagrams, workflow mappings, and SOPs for all IGA systems and processes to ensure operational consistency and audit readiness.
- Proactively identify, measure, and remediate access-related risks; perform compliance reporting and regular access control audits to protect critical assets, including PHI and PII.
- Lead organizational efforts to ensure IGA controls and processes align with HIPAA Security and Privacy Rule, HITRUST, PCI DSS, ISO 27001{{:}}2022, and other applicable regulatory frameworks.
- Ensure the confidentiality, integrity, and availability (CIA) of identity services in accordance with defined SLA metrics, maintaining high levels of data security and patient satisfaction.
- Serve as a technical liaison between Information Technology and business units, proactively identifying access governance gaps and architecting solutions that balance security with operational efficiency.
- Collaborate with leaders, architects, and stakeholders to translate business and compliance requirements into IGA controls, building trust-based relationships that position security as an enabler.
- Research emerging IGA technologies and trends, proposing scalable solutions that create business value and support organizational growth.
- Provide subject matter expertise and technical mentorship to junior engineers, driving team proficiency in IGA platforms, access governance practices, and regulatory frameworks.
Qualifications
- Bachelor’s Degree in Arts/Sciences (BA/BS) from an accredited college in IT/Information Security, Computer Science, IT, Engineering or related field. In lieu of degree, 5+ years of experience is required or the equivalent combination of education and experience.
- 6+ years years of direct experience in Identity & Access Management, with at least 2 years focused specifically on hands-on experience administering an enterprise IGA platform (e.g., Okta Lifecycle Management, Microsoft Entra Identity Governance, Sa2+ including ownership of IGA programs, platform administration, and lifecycle automation at enterprise scale. Must include a proven track record of driving IGA maturity, executing governance roadmaps, and taking on increasing responsibility within complex, multi-application environments.
- 2+ years of experience designing and enforcing SoD policies, including conflict detection, remediation workflows, and entitlement reviews across enterprise and clinical applications.
- 2+ years of experience building and troubleshooting IGA integrations using REST APIs, SCIM, and SAML — with proficiency using tools such as Postman for testing and validation.
- 2+ years of experience with scripting and automation (PowerShell, Python, or equivalent) applied specifically to identity lifecycle events, provisioning routines, and access governance workflows.
- Strong grasp of identity lifecycle management, RBAC, and access governance in complex, multi-application environments
- Strong working knowledge of identity provisioning standards and protocols including SCIM, SAML, OAuth/OIDC, and LDAP as applied to IGA platform integrations.
- Proven ability to communicate access governance risks and IGA program status to non-technical stakeholders and leadership, translating compliance requirements into business-aligned solutions.
- Expert-level understanding of identity governance principles and regulatory frameworks — including NIST 800-63, ISO 27001, HIPAA, and HITRUST — with a demonstrated ability to operationalize these standards through IGA controls and processes.
Pay
$104,000.00-$136,000.00 / Annually
Schedule
N/A