Security Engineer - IAM
Listed on 2026-09-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
The Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services that support our business. You will understand data and automation are important ingredients to our mission and know how to actively employ these ingredients ond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape.
Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.
Design and deploy advanced identity security controls to safeguards networks, systems, and applications.
Work across disciplines to shape our security services strategy and execution
Set and uphold the standard for security processes to support high-quality engineering
Mentor and galvanize new engineers to do their best work
BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field
8+ years of experience in software or security engineering within Cloud Native environments
Minimum Requirements
Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM, Azure Entra , or GCP IAM), including designing/enforcing least-privilege roles, RBAC/ABAC, and permission policies.
Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML, OIDC, OAuth, LDAP/Directory Services), user lifecycle automation, SSO, MFA, and Just-In-Time (JIT) access.
Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or Cloud Formation) and scripting (Python or Power Shell) to automate identity provisioning, drift detection, and access workflows.
Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts, API keys, bots, and automated workload identities across cloud infrastructure.
Experience architecting, developing, and deploying large-scale distributed systems at scale
Experience with cloud technologies, e.g., AWS, Azure, GCP
Experience building continuous integration and continuous development (CI/CD) pipelines
Familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go)
4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value
Experience with health-tech systems, like Electronic Health Records, Clinical data, etc.
AI Identity & Access Management
NHI Architecture: Design secure, scalable, and automated solutions for managing service accounts, machine identities, secrets, certificates, APIs, and cloud-native workloads.
AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.
AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g., Gemini, Claude, AWS Bedrock), conducting threat modeling for AI systems, or managing automated permission guardrails for AI agents.
Advanced Protocols & Microservice Security: Familiarity with SPIFFE/SPIRE, zero-trust network architectures, or complex containerized identity frameworks.
SIEM & Security Observability Tools: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g., Crowdstrike, Sumo Logic, Wiz, Zscaler).
Industry & Regulatory Context: Experience with health-tech systems, clinical data environments (EHRs), and regulatory standards (HIPAA, SOC 2, ISO 27001).
Certifications: CISSP, OSCP, CEH, Certified AI Security Specialist (CAISS), or GIAC Machine Learning Security Engineer (GMSE).
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are:Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model.
Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best -…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).