Software Engineer – Identity & Access Management
About the role
We are seeking a Software Engineer with deep interest and experience in Identity & Access Management (IAM) to help design, build, and secure authentication and authorization capabilities across CoverMyMeds’ platforms. This role sits on a core IAM platform team that owns end-user identity, federated authentication, and authentication infrastructure for web applications, partnering closely with Security, Product, and other engineering teams.
Responsibilities
- Identity Engineering & Integrations
- Design, build, and maintain authentication and authorization solutions using OIDC, OAuth 2.0, and SAML.
- Integrate applications and APIs with identity platforms such as Okta, Auth0, Ping, or Microsoft Entra ID.
- Implement SSO, MFA, federated authentication, session management, and secure token handling.
- Contribute to identity services such as login gateways, authorization middleware, claims transformation, and access policy enforcement.
- Support SMART on FHIR (OAuth 2.0) use cases and unified authentication initiatives.
- Security & Standards
- Apply industry-standard security practices including least privilege, secure defaults, defense in depth, and secure secret handling.
- Partner with Security on threat modeling, risk reviews, and secure SDLC practices.
- Implement identity solutions aligned with NIST-based identity and access control principles.
- Software Development & Delivery
- Build production-quality systems using one or more of JavaScript/TypeScript, Ruby, Python, or C#.
- Write clean, testable, maintainable code with strong engineering discipline (CI/CD, code reviews, automated testing).
- Create clear technical documentation for APIs, integrations, and operational support.
- Participate in on-call or operational support for critical identity services as needed.
- Ways of Working
- Work within a Kanban delivery model, managing flow and continuously improving quality and throughput.
- Collaborate with Product, Security, and stakeholders to define outcomes and manage tradeoffs.
- Bring an enterprise-first mindset, constructively challenging designs and contributing new ideas.
Benefits
- Coverage you can rely on - Medical, Dental, and Vision
- Health Spending Accounts
- Flexible Spending Accounts
- 401(k) (U.S.)
- Pension (Canada)
- Employee Stock Purchase Plan
- Mental Health Programs
- Flexible Schedules
- Paid Time Off
- Wellness Program
- Education Reimbursement
- Volunteer Opportunities
- Flexible Work Environment
Culture
Make a meaningful impact by using your problem-solving skills to push the boundaries of innovation in healthcare, while maintaining a healthy work-life balance.
Foster a digital mindset to drive IT transformation across McKesson through our evolving data and technology tools.
Join a supportive environment where you can advance your career and develop both personally and professionally.
Qualifications
- Minimum Qualifications
- 4+ years of relevant experience
- Deep experience (4+ years) with Okta and/or Auth0 (policies, apps, federation, claims)
- Hands-on experience (4+ years) implementing or integrating authentication and authorization using OIDC, OAuth 2.0, and/or SAML
- Strong understanding of secure engineering practices and common identity threats
- Experience working in at least one of the following: JavaScript/TypeScript, Ruby, Python, C#
- Ability to collaborate across engineering, product, and security teams and communicate technical decisions clearly
- Preferred Qualifications
- Experience with SMART on FHIR, SCIM, directory integrations, or identity lifecycle management
- Familiarity with RBAC/ABAC, claims-based authorization, or policy engines
- Experience in regulated environments and audit support
- Experience improving reliability of critical auth systems (SLIs/SLOs, graceful degradation)