IAM Engineer
Ensemble Health Partners · United States
Skills in this posting
Benefits
The posting
Thank you for considering a career at Ensemble!
Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.
Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference!
O.N.E Purpose
Customer Obsession: Consistently provide exceptional experiences for our clients, patients, and colleagues by understanding their needs and exceeding their expectations.
Embracing New Ideas: Continuously innovate by embracing emerging technology and fostering a culture of creativity and experimentation.
Striving for Excellence: Execute at a high level by demonstrating our “Best in KLAS” Ensemble Difference Principles and consistently delivering outstanding results.
The Opportunity
IAM Engineer – Client Implementation & Automation
Company Overview
Ensemble Health Partners is a leading healthcare revenue cycle management organization focused on delivering operational excellence, innovation, and meaningful outcomes for healthcare providers and the patients they serve. Our Technology Security organization plays a critical role in protecting Ensemble, enabling secure business operations, and supporting scalable growth across enterprise and client environments.
Job Summary
The IAM Engineer – Client Implementation & Automation is responsible for supporting secure, scalable, and audit-ready identity and access management capabilities across Ensemble’s client and enterprise environments. This role helps ensure Day-1 access readiness by translating client requirements into access models, workflows, role-based access mappings, automation opportunities, testing plans, and operational support practices.
This position works within Ensemble’s IAM operating model, supporting an identity-first, automation-first, and RBAC-first approach to client onboarding, lifecycle management, access governance, and continuous improvement. The ideal candidate is a hands-on IAM professional with strong technical troubleshooting skills, process discipline, documentation quality, and the ability to partner effectively across IAM, ServiceNow, HR/Workday, Operations, PMO, application owners, and client stakeholders.
Essential Job Functions
Client Implementation & Readiness
Support IAM delivery across all onboarding phases, including discovery, design, build, UAT, go-live, and stabilization.
Translate client requirements into access models, workflows, and RBAC mappings.
Coordinate readiness activities across key milestones, including T-30, T-10, T-0, and T+10.
Maintain clear and complete documentation, including requirements, workflows, UAT results, and runbooks.
Access Workflow & Lifecycle Management
Design and support access request workflows through ServiceNow or other approved intake channels.
Ensure access requests capture the required data for provisioning, approvals, and audit evidence.
Manage identity lifecycle processes including Joiner, Mover, Leaver, rehire, and client changes.
Identify and resolve workflow, approval, and provisioning issues in a timely and effective manner.
RBAC & Access Governance
Maintain RBAC models, entitlement mappings, and access profiles.
Ensure access is aligned with least-privilege principles and approved role definitions.
Support access reviews, certifications, and exception handling.
Document risks, exceptions, and compensating controls.
Automation & Integration
Develop automation that reduces manual provisioning effort and improves operational scalability.
Support integrations across IAM, ServiceNow, HR/Workday, and applications.
Leverage APIs, scripting, and workflows for lifecycle automation.
Identify, document, and track automation opportunities and technical debt.
Audit & Operations
Maintain complete and traceable audit evidence for access-related activities.
Support SLA tracking, operational reporting, and leadership visibility.
Manage exceptions with clear ownership, documented rationale, and remediation plans.
Contribute to SOPs, runbooks, and workflow documentation.
Collaboration & Client Engagement
Partner with IAM, ServiceNow, HR/Workday, Operations, PMO, and client teams.
Communicate status, risks, dependencies, and decisions clearly and professionally.
Support escalations and promote transparency throughout go-live and hypercare activities.
Translate technical IAM concepts into clear business impact and operational value.
Minimum Qualifications
Three or more years of experience in Identity and Access Management, cybersecurity, access provisioning, security operations, or a related technology function.
Experience supporting identity lifecycle management, including joiner, mover, leaver, rehire, transfer, and access change processes.
Experience working with workflow platforms, access request processes, system integrations, or process automation.
Knowledge of RBAC, least privilege, and access governance.
Experience with APIs, scripting, or automation.
Understanding of SSO, MFA, SAML, OAuth, and LDAP.
Strong troubleshooting, documentation, communication, and stakeholder engagement skills.
Preferred Qualifications
Experience supporting client onboarding, implementations, or large-scale transformation initiatives.
Background in healthcare or regulated environments.
Familiarity with ITSM platforms, cloud identity solutions, and SaaS application environments.
Experience supporting audit, compliance, access reviews, or control validation activities.
Relevant certifications such as Security+, ITIL, CISSP, or CISM.
Core Competencies
Customer obsession and commitment to delivering reliable, high-quality access services.
Strong ownership, accountability, and follow-through across implementation and operational activities.
Ability to simplify complex IAM concepts and communicate effectively with technical and business stakeholders.
Continuous improvement mindset with a focus on automation, standardization, scalability, and measurable outcomes.
Technical Skills
Identity lifecycle management (JML).
RBAC and entitlement mapping.
Access request workflows and SLA tracking.
APIs and integrations such as REST, SCIM, and JSON.
Authentication including SSO, MFA, SAML, and OAuth.
Automation, scripting, and cloud/SaaS identity concepts.
Soft Skills
Strong communication and stakeholder engagement.
Client-facing professionalism.
Attention to detail and accountability.
Problem-solving orientation and commitment to continuous improvement.
This position pays between $84,000 - 144,900 based on experience
Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- What security engineers do insteadevery measured route out
- Penetration Tester → Security Engineer51% readiness
- All open security engineer rolesthe full board
Where these skills also reach
- 78 open penetration tester roles78% readiness from security engineer
- 396 open network engineer roles61% readiness from security engineer
- 730 open systems administrator roles52% readiness from security engineer
- 2019 open systems engineer roles51% readiness from security engineer
More security engineer roles
- Senior Security Engineer at Dropzone AIUnited States · Remote$175k–$217kTodayApply
- Security Engineer at Direct employerBerlin Office · RemoteTodayUnlock
- Lead Security Engineer at Direct employerLondonTodayUnlock
- Security Engineer at Direct employerPrague, Czech RepublicTodayUnlock
- Security Engineer at Direct employerMumbaiTodayUnlock
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.