IT Analyst II - Access and Provisioning Specialist
Listed on 2026-09-09
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Duly Health and Care, you are supported to do your best work and make a meaningful impact every day. You will be part of a collaborative, physician-led team that works as one and puts patients at the center of everything we do.
With a connected network of providers, care teams, and services across primary and specialty care, surgery centers, imaging, lab, and therapy, you are part of a system designed to deliver high-quality, coordinated care. Together, we create an environment where you can grow, contribute, and help improve the experience and outcomes for every patient we serve.
Benefits- Comprehensive medical, dental, and vision benefits that include healthcare navigation assistance.
- Access to a mental health benefit at no cost.
- Employer provided life and disability insurance.
- $5,250 Tuition Reimbursement per year.
- Immediate 401(k) match.
- 40 hours paid volunteer time off.
- A culture committed to community engagement and social impact.
- Up to 12 weeks parental leave at 100% pay and a financial benefit for adoption and surrogacy for non-physician team members once eligibility requirements are met.
We are seeking an experienced IT Access & Provisioning Specialist to design, implement, and maintain automated identity lifecycle management across the enterprise with a strong focus on onboarding/offboarding automation using tools like SailPoint Identity IQ/Identity Now, Active Directory, and Azure AD (Entra ).
The Specialist partners closely with Cybersecurity, IT Network & Infrastructure, application owners, business stakeholders, and compliance teams on access reviews, role-based access controls, provisioning workflows, and process improvement initiatives.
Key Responsibilities- Design, build, and maintain automated onboarding and offboarding workflows using SailPoint (or equivalent IGA tools) integrated with Active Directory and Azure AD/Entra .
- Manage identity lifecycle events (joiners, movers, leavers) by automating account creation, role/group assignment, license provisioning, and deprovisioning.
- Deep experience managing IAM solutions (e.g. Azure AD, Okta, Imprivata, Ping, AuthX, etc.) in a cloud-centric environment (e.g. Epic, D365, Work Day, Salesforce, Five9, etc.).
- Develop and maintain connectors, rules, and workflows between SailPoint, HRIS systems (e.g., Workday), AD, Azure AD, and downstream applications.
- Configure and manage access certification campaigns, role-based access control (RBAC), and segregation of duties (SoD) policies within the IGA platform.
- Troubleshoot provisioning/deprovisioning failures, sync errors, and connector issues across AD, Azure AD, and SailPoint.
- Partner with HR, IT Service Desk, and business units to ensure timely and accurate identity data flows and lifecycle triggers.
- Create and maintain documentation for IAM processes, workflows, and standard operating procedures.
- Monitor identity-related audit logs and compliance reports to ensure adherence to internal policies and regulatory requirements (e.g., HIPAA).
- Support access request and approval workflows, ensuring least-privilege principles are enforced.
- Participate in IAM tool upgrades, testing, and continuous improvement initiatives, including scripting enhancements (Power Shell, Python, or similar) to extend automation capabilities.
- Assist in incident response related to identity and access issues, including emergency account disablement and access reviews.
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field (or equivalent work experience).
- 5+ years' hands on experience in identity and access management and privileged access management.
- 5+ years of experience with complex, cloud-based enterprise environments
- Strong working knowledge of Active Directory (OUs, group policy, group management) and Azure AD / Microsoft Entra (users, groups, conditional access, licensing).
- Experience building or supporting automated provisioning/deprovisioning workflows tied to HR systems of record.
- Familiarity with identity lifecycle concepts: joiner/mover/leaver processes, RBAC, SoD, access certifications.
- Basic scripting/automation skills (Java, Power Shell, Python, or similar) for extending or troubleshooting integrations.
- Understanding of directory synchronization tools (Azure AD Connect / Entra Connect) and SSO/federation concepts (SAML, OAuth, OIDC).
- Strong analytical and troubleshooting skills, with attention to detail in high-volume, process-driven environments.
- Excellent communication skills and ability to work cross-functionally with HR, security, and application teams.
- Experience with SailPoint Identity IQ
- SailPoint certifications (e.g., SailPoint Certified Identity Now Engineer/Administrator).
- Experience with additional IAM/IGA/PAM tools (Okta, Ping Identity, Cyber Ark, Saviynt).
- Knowledge of ITSM platforms (Zendesk) for access request/ticketing integration.
- Experience supporting compliance frameworks (PCI, GLBA, HIPAA, GDPR, SOC 2 etc.).
- Familiarity with cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).