Job Details
Identity Security Engineering Leader
Ascension · Remote US
Tailor My Resume
Start free. No credit card.
About the Role
Your future role at a glance
Location: Remote
Department: Data Delivery and Governance
Schedule: Full-Time, Days
About the Job
Life at Ascension: Where purpose meets opportunity
Ascension is a leading nonprofit Catholic health system with a culture and associate experience grounded in service, growth, care and connection. We empower our 97,000+ associates to bring their skills and expertise every day to reimagining healthcare, together. Recognized as one of the Best 150+ Places to Work in Healthcare and a Military-Friendly Gold Employer, you’ll find an inclusive and supportive environment where your contributions truly matter.
Benefits that help you thrive
- Comprehensive health coverage: medical, dental, vision, prescription coverage and HSA/FSA options
- Financial security & retirement: employer-matched 403(b), planning and hardship resources, disability and life insurance
- Time to recharge: pro-rated paid time off (PTO) and holidays
- Career growth: Ascension-paid tuition (Vocare), reimbursement, ongoing professional development and online learning
- Emotional well-being: Employee Assistance Program, counseling and peer support, spiritual care and stress management resources
- Family support: parental leave, adoption assistance and family benefits
- Other benefits: optional legal and pet insurance, transportation savings and more
How you'll make an impact in this role
- Execute the cloud-first IGA/IAM modernization roadmap, orchestrating enterprise-wide application onboarding and replacing legacy systems with highly scalable, standardized identity service platforms.
- Engineer and automate end-to-end identity lifecycle event flows (Joiner/Mover/Leaver) and access certification workflows, eliminating manual operations through API integrations, infrastructure-as-code, and platform-native automation capabilities.
- Direct and mentor a high-performing engineering team using Agile frameworks, establishing standard operating procedures, robust change management, and a culture of continuous delivery for identity security solutions.
- Optimize and secure hybrid directory infrastructure, maintaining deep technical control over Microsoft Active Directory, Entra ID, and market-leading enterprise IGA platforms (e.g., SailPoint, Saviynt, Okta, OneIdentity).
- Serve as the primary technical escalation authority and compliance SME, managing internal/external IAM audits, designing robust security control documentation, and translating complex identity risk data into strategic counsel for senior leadership.
- What minimum qualifications you'll need
Education
- High School diploma equivalency with 3 years of cumulative experience OR Associate's degree/Bachelor's degree with 2 years of cumulative experience OR 7 years of applicable cumulative job specific experience required.
- 3 years of leadership or management experience preferred.
What additional preferences you'll need
- Advanced Technical Degree: Bachelor’s degree or higher in Computer Science, Information Security, or a closely related engineering discipline.
- Industry Security Credentials: Possession of active, recognized cybersecurity certifications such as CISSP, CISM, or CIAM.
- Vendor Platform Certification: Current, formal engineering or administration certifications on enterprise-grade IGA/IAM platform ecosystems (e.g., SailPoint, Saviynt, Okta).
Responsibilities
- Execute the cloud-first IGA/IAM modernization roadmap, orchestrating enterprise-wide application onboarding and replacing legacy systems with highly scalable, standardized identity service platforms.
- Engineer and automate end-to-end identity lifecycle event flows (Joiner/Mover/Leaver) and access certification workflows, eliminating manual operations through API integrations, infrastructure-as-code, and platform-native automation capabilities.
- Direct and mentor a high-performing engineering team using Agile frameworks, establishing standard operating procedures, robust change management, and a culture of continuous delivery for identity security solutions.
- Optimize and secure hybrid directory infrastructure, maintaining deep technical control over Microsoft Active Directory, Entra ID, and market-leading enterprise IGA platforms (e.g., SailPoint, Saviynt, Okta, OneIdentity).
- Serve as the primary technical escalation authority and compliance SME, managing internal/external IAM audits, designing robust security control documentation, and translating complex identity risk data into strategic counsel for senior leadership.