via Dayforce
$85K - 120K a year
Design and implement identity security capabilities and provide technical leadership for identity initiatives ensuring healthcare compliance.
7+ years in IAM or security engineering with expertise in Microsoft Entra ID, Active Directory, PowerShell, and Microsoft Graph API.
Senior Identity Engineer Who are we? Versant Health is one of the nation's leading administrators of managed vision care, serving over 35 million of our clients' members across the United States. Our purpose is to make healthy vision a reality for everyone by improving access to care and education in the communities we serve. Fueled by our mission to improve members' lives with easy-to-use vision solutions rooted in choice value, and care, we believe that everyone has the power to become anything they set their sights on. See how you can make a difference with the support of strong leadership and a team environment. Versant Health: Making Healthy Vision a Reality for Everyone What are we looking for? The Sr. Identity Engineer is a senior technical leader within Information Security's Identity & Access Management function, responsible for designing, implementing, and evolving identity security capabilities across workforce users, privileged accounts, external users, application identities, service accounts, AI-enabled agents, and automation identities. This role serves as a senior hands-on engineer and technical lead for complex identity security initiatives that protect enterprise systems and sensitive healthcare data through lifecycle automation, privileged access management, access governance, identity telemetry, customer identity services, and integration security controls. While remaining a hands-on engineering role, this position also provides technical leadership, engineering direction, and subject matter expertise for enterprise identity security initiatives. The engineer is expected to lead complex technical implementations, contribute to identity engineering standards, patterns, and operational practices, and provide technical recommendations and engineering expertise supporting the organization's identity security roadmap while continuing to support operational excellence. Partners with Security Engineering teams responsible for enterprise authentication and access protection controls, providing identity platform expertise, integrations, provisioning services, and governance automation. This role reports to the Senior Manager of Identity and Access Management and partners closely with service owners, security engineering, infrastructure, application teams, compliance, and business stakeholders to deliver secure, resilient, and audit-ready identity capabilities. Where you will have an impact Maintain authoritative records, ownership information, classification, and lifecycle status for enterprise human and non-human identities. Identity Lifecycle Automation Lead the design, implementation, and support of enterprise identity lifecycle automation across joiner, mover, leaver, transfer, and termination processes. Engineer HRIS-driven identity lifecycle workflows integrating the enterprise HR platform with Active Directory, Microsoft Entra ID, Entra ID Governance, ServiceNow, and downstream business applications. Build and maintain automated provisioning, modification, and deprovisioning processes using Microsoft Graph API, PowerShell, SCIM, REST APIs, access packages, lifecycle workflows, group-based automation, and documented request/evidence records. Develop reusable automation patterns that improve accuracy, reduce manual access handling, and support secure, timely access changes across workforce, privileged, external, and application identities. Non-Human Identity Governance Establish and maintain governance standards, onboarding requirements, lifecycle controls, ownership requirements, review processes, and registry capabilities for non-human identities, including service accounts, app registrations, service principals, managed identities, API keys, webhook secrets, certificates, AI-enabled agent identities, and automation accounts. Define ownership, purpose, scope, lifecycle, credential rotation, access review, monitoring, and decommissioning requirements for non-human identities across enterprise platforms and applications. Partner with application, infrastructure, cloud, and security teams to ensure non-human identities are created, secured, documented, reviewed, and retired in alignment with identity security and audit requirements. Support privileged and sensitive non-human identity use cases through vaulting, least privilege, credential management, privileged access controls, and evidence documentation. Entra & Identity Engineering Serve as a senior engineering resource for Microsoft Entra ID, Active Directory, Entra ID Governance, Entra External ID, Microsoft Graph API, and related hybrid identity capabilities. Design and support Entra ID Governance capabilities including lifecycle workflows, entitlement management, access packages, access reviews, identity lifecycle policies, and governed access models. Engineer identity platform configurations, automation, access control patterns, provisioning models, entitlement structures, integration standards and patterns, and governance controls that support identity lifecycle management, authorization, and access governance. Provide advanced troubleshooting and technical guidance for identity issues involving Entra ID, Active Directory, SSO, federation, authentication flows, directory synchronization, group-based access, and application onboarding, partnering with Security Engineering on Conditional Access, authentication strength, and related identity protection controls. Design and maintain scalable entitlement models including role-based access, baseline access, group and role structures, least-privilege assignments, privileged entitlements, and separation-of-duties controls. Engineer and support privileged identity capabilities including privileged account lifecycle, vault integration, credential rotation, privileged entitlement management, and Microsoft Entra PIM. Application Integrations Lead identity engineering support for application onboarding and integration patterns involving Microsoft Entra ID, Entra External ID, Active Directory, SSO, SCIM, SAML, OAuth/OIDC, LDAP, REST APIs, and Microsoft Graph API. Partner with application owners and business teams to design secure authentication, authorization, provisioning, deprovisioning, and access governance models for enterprise and healthcare-related applications. Support Entra External ID engineering for member, provider, client, and business partner identity use cases, including registration, MFA, SSO, conditional access alignment, account recovery, and authentication/authorization troubleshooting. Design and govern identity controls for healthcare and business integration patterns such as SFTP, EDI, claims/eligibility API clients, regulated data pipeline accounts, and application-specific service identities Provision and govern AI-enabled agent and automation identities with clear ownership, allowed actions, least privilege, vaulting, monitoring, traceability, and disablement procedures. Supporting and Cross-Functional responsibilities Access Governance and Audit Readiness Support access certification, entitlement review, and remediation processes through automation, workflow integration, and clear operational documentation. Ensure identity controls and automation processes support HIPAA, HITRUST, SOX, and SOC 2 by maintaining audit-ready evidence, reporting, and control documentation for access reviews, remediation activities, regulatory audits, and internal governance needs. Identity Telemetry and Incident Support Ensure identity platforms, applications, lifecycle systems, and privileged/non-human identity services generate appropriate security telemetry and make required logs available to Security Operations. Partner with Security Operations to provide identity context, account ownership, entitlement information, authentication history, credential status, and other identity data needed to investigate security events. Support incident containment and remediation through credential revocation, account disablement, access removal, session revocation, and other identity-specific response actions. Partner with Security Operations and Security Engineering to improve identity-related detection coverage by identifying relevant telemetry, event sources, and identity context. Engineering Standards and Program Partnership Document reusable identity engineering patterns, integration standards, operational procedures, and support models for Entra, lifecycle automation, non-human identities, and application integrations. Serve as a senior technical advisor for identity engineering initiatives and mentor engineers on identity platform design, application onboarding, automation practices, and non-human identity governance. What’s necessary to do the job? Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field preferred; equivalent engineering experience considered. 7+ years of IAM, identity security, security engineering, or related enterprise technology experience; healthcare or other regulated industry experience preferred. Demonstrated experience leading complex IAM or identity security initiatives from design through implementation in enterprise environments. Hands-on experience with Microsoft Entra ID and Active Directory required; experience with Entra ID Governance preferred, including lifecycle workflows, entitlement management, access packages, access reviews, and PIM. Proficiency with PowerShell and Microsoft Graph API required; Python, REST API, SCIM, LDAP, and ServiceNow workflow experience preferred. Experience with privileged access management, vaulting concepts, and non-human identity governance including service accounts, app registrations, service principals, managed identities, API keys, webhook secrets, and certificates. Familiarity with SIEM/log management, identity event correlation, detection tuning, and identity-related incident response activities. Understanding of HIPAA, HITECH, HITRUST, NIST, and audit/evidence expectations in identity and access management environments. Strong written and verbal communication skills with the ability to explain technical identity concepts to security, compliance, audit, application, infrastructure, and business stakeholders. HIPAA & Security Requirements All Associates must comply with the Health Insurance Portability Accountability Act of 1996 (HIPAA) as it pertains to disclosures of protected health information (PHI) as described in the Notice of Privacy Practices and HIPAA Privacy Policies and Procedures. As a component of job roles and responsibilities, Associates may have access to covered information, cardholder data or other confidential customer information which must be protected at all times. As a result, Associates must explicitly adhere to all data security guidelines established within the Company’s Privacy & Security Training Program. We offer a comprehensive and competitive total rewards package designed to support your health, financial well‑being, and work‑life balance. Benefits include medical, dental, and paid vision coverage; paid time off and company holidays; retirement savings with employer contribution; employee wellness resources; and professional development opportunities. Additional benefits may include flexible work arrangements, employee assistance programs, and other programs that support you both at work and beyond. This role is compensated on an hourly basis. The expected hourly pay range for this position is $150,000.00 – $160,000.00 per hour, based on factors such as experience, skills, and role requirements. Actual pay within the range will be determined during the hiring process and in accordance with applicable wage and hour laws. Versant Health will never request money from candidates who seek employment with us and will never ask for any payment as part of the recruitment process. Versant Health is a proud Equal Employment Opportunity and Affirmative Action employer dedicated to attracting, retaining, and developing a diverse and inclusive workforce. All qualified applicants will receive consideration for employment at Versant Health without regards to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, uniformed service member or veteran status, or any other characteristic protected by law. Our purpose is to make healthy vision a reality for everyone by improving access to care and education in the communities we serve. Fueled by our mission to improve members’ lives with easy-to-use vision solutions rooted in choice, value, and care, Versant Health believes that everyone has the power to become anything they set their sights on. Our team is guided by core Leadership Principles—Perspective, Care, Drive, and Ownership—which shape how we work, lead, and grow together. Our Management Team is committed to fostering a strong and supportive culture, cultivating a thriving work environment, providing clear direction, optimizing resources, enabling innovative solutions, and driving meaningful results. LI-Remote
This job posting was last updated on 9/29/2026