Identity System Engineer
Listed on 2026-02-23
-
IT/Tech
Cybersecurity, Systems Engineer
Careers With Purpose
Sanford Health is one of the largest and fastest-growing not-for-profit health systems in the United States. We're proud to offer many development and advancement opportunities to our nearly 50,000 members of the Sanford Family who are dedicated to the work of health and healing across our broad footprint.
Facility: Sanford Bemidji Peak Ctr
Location: Bemidji, MN
Address: 2017 Net Way NW, Bemidji, MN 56601, USA
Shift: 8 Hours - Day Shifts
Job Schedule: Full time
Weekly
Hours:
40.00
Salary Range: $34.50 - $57.00
Pay Info: Pay starts at $34.50 and increases according to years of applicable experience.
The Identity Systems Engineer is responsible for implementing, and securing enterprise identity and access management infrastructure that enables reliable authentication, authorization, and access management across hybrid environments. Engineers in this family ensure that users, systems, and applications are authenticated, authorized, and protected in alignment with security standards, regulatory requirements, and business needs. The Identity Systems Engineer is a mid-level role responsible for implementing, maintaining, and securing enterprise identity infrastructure across both on-premises and cloud environments.
This position deploys and manages Active Directory services, including domain controllers, OU structures, replication health, schema extensions, and trust relationships, while ensuring alignment with business and security requirements. The engineer oversees synchronization between AD, Entra , and other identity platforms, enabling seamless hybrid identity and single sign-on for applications. Core responsibilities include configuring and managing secure authentication methods, administering enterprise PKI and certificate life cycles, and enforcing access governance policies through Group Policy Objects and role-based models.
The role also integrates systems via API calls (REST, SOAP, JSON), automates provisioning and de-provisioning workflows, and supports modern authentication protocols such as Kerberos, OAuth, OpenID Connect, and SAML. In addition, the Identity Systems Engineer enforces least privilege, conducts access audits, supports compliance with SOX, HIPAA, and GDPR, and provides technical expertise during audits and governance reviews. With a technical focus complemented by operational oversight, this role ensures the organization's identity services remain secure, resilient, and aligned with both regulatory and business objectives.
This role requires technical expertise in Active Directory, Entra , authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, problem-solving skills, a security-first mindset, and least-privilege enforcement. The Identity Systems Engineer ensures the organization's identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices.
QualificationsBachelor’s degree required, in lieu of education, leadership may consider an Associate’s Degree plus 3 years of applicable experience in computer science or related field.
Minimum of 1 to 2 years applicable work experience required. Including but not limited to:
Supporting Active Directory, Domain Services, Hybrid Identities, & Entra
Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC
Maintaining Public Key Infrastructure (PKI)
Supporting Identity Lifecycle & Access Governance workflows and technical integrations
Implementation of information security standards and procedures including HIPAA and PCI
Security Certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are highly desired.
BenefitsSanford Health offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of benefits include health insurance, dental insurance, vision insurance, life insurance, a 401(k) retirement plan, work/life balance benefits, and a generous time off package to maintain a healthy home-work balance. For more information about Total Rewards, visit .
Sanford is an EEO/AA Employer M/F/Disability/Vet. If you are an individual with a disability and would like to request an accommodation for help with your online application, please call or send an email to talent .
Sanford Health has a Drug Free Workplace Policy. An accepted offer will require a drug screen and pre-employment background screening as a condition of employment.
Req Number: R-0246584
Job Function: Information Technology
Featured: No
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).