Principal Security Access Engineer
Our Mission
Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS.โฏ Come be part of remarkable.
Overview
How you can make a difference
HealthEquity is seeking an experienced and highly motivated Principal IAM Security Access Engineer to join our Security & IT team. This role is critical to the design, implementation, and management of our identity, access, and privileged access management (IAM/PAM) systems โ spanning human, non-employee, service, and AI agent identities. The ideal candidate has deep, hands-on experience with SailPoint Identity Security Cloud (ISC) and Non-Employee Risk Management (NERM), BeyondTrust, Microsoft Entra (including Conditional Access), and Silverfort, along with a strong point of view on how identity security must evolve to govern AI agents, non-human identities, and machine-to-machine access. This role requires a deep understanding of IAM principles, excellent problem-solving skills, and the ability to mentor and guide team members while exercising indirect leadership and influence across all levels of the organization.
What youโll be doing
Engineering and Strategy:
- Implementation of robust IAM/PAM solutions using SailPoint Identity Security Cloud, BeyondTrust, Microsoft Entra, Silverfort, and other IAM tools/platforms.
- Help develop and maintain IAM strategies; including governance for AI agents, non-human identities (NHIs), and machine-to-machine access โ that align with organizational goals and industry best practices.
- Function as a subject matter expert for IAM technologies and processes, including emerging practices for agentic AI identity, authorization, and lifecycle management.
- Clearly articulate strategic initiatives, gain buy-in, and establish a shared understanding with key decision makers at the leadership level.
System Management and Implementation:
- Manage the configuration and administration of SailPoint ISC (including NERM for non-employee identity risk), BeyondTrust, Microsoft Entra, and Silverfort.
- Design and manage Conditional Access policies within Microsoft Entra to enforce risk-based, adaptive access controls across users, devices, and workloads.
- Partner closely with the IAM Governance team to implement IAM policies, standards, and procedures using IAM & PAM tools and processes.
- Ensure seamless integration of IAM systems with applications, services, secrets management/vaulting platforms, and CI/CD pipelines.
- Implement governance models for AI agents and service accounts, including credential issuance, scoped permissions, rotation, and decommissioning.
- Drive timely execution of IAM & PAM initiatives in alignment with strategic and tactical plans.
AI and Agentic Identity Enablement:
- Establish identity and access frameworks for AI agents and autonomous workflows, ensuring least-privilege access, auditability, and policy enforcement equivalent to human identity controls.
- Evaluate and integrate secrets management solutions to secure credentials, API keys, and tokens used by AI agents, automations, and service-to-service connections.
- Assess and pilot AI-assisted capabilities within IAM tooling (e.g., SailPoint AI, Entra ID Protection risk signals, Silverfort risk analytics) to improve access certification accuracy, anomaly detection, and operational efficiency.
- Program Management Support:
- Help IAM projects go from initiation to completion, ensuring timely delivery and alignment with project goals.
- Coordinate with cross-functional teams, including IT, HR, Security, and business units, to gather requirements and ensure successful project outcomes.
- Manage project timelines and resources effectively.
Team Development:
- Provide indirect leadership and guidance to IAM engineers and other IAM team members.
- Conduct training sessions and workshops โ including on AI/agentic identity risk โ to enhance the skills and knowledge of the team.
- Foster the culture of continuous improvement and profession