Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Identity and Access Management Engineer

$98.84k - $148.26k

Washington Health Benefit Exchange

Job Description

Job Description:\n\n The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy-to-use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community. The Exchange is a public-private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in-person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program. The Exchange embraces the following equity statement adopted by our Board of Directors: Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti-racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact with and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange s area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential. SUMMARY The Senior Identity and Access Management Engineer position focuses on designing, developing, and supporting customer IAM solutions using PingOne IdentityCloud to provide secure and seamless digital experiences to customers. Key responsibilities include managing user lifecycle automation, implementing access controls, integrating applications with IAM systems through industry-standard protocols, and enhancing security via Single Sign-On (SSO), Multi-Factor Authentication (MFA), and risk-based policies. The position also involves troubleshooting authentication flows, ensuring regulatory compliance, and collaborating with Information Technology (IT), security, and product teams to deliver robust IAM integrations across cloud platforms. DUTIES AND RESPONSIBILITIES • Design, develop, implement, and support customer IAM solutions utilizing PingOne IdentityCloud, and support transition to Okta where applicable. • Build and maintain automated processes for user lifecycle management, including provisioning, deprovisioning, and role- or attribute-based access controls. • Develop and maintain custom connectors, workflows, APIs, and scripts to integrate IAM systems with enterprise applications. • Integrate web, mobile, and API-based cloud applications with IAM platforms using protocols such as SAML, OAuth, and OIDC. • Implement SSO, adaptive authentication, MFA, and risk-based policies to enhance security and user experience. • Configure and troubleshoot federation and OAuth/OIDC flows, and ensure secure session handling across systems. • Implement and manage workflows for customer registration, login, account recovery, and profile management. • Support migration of CIAM capabilities from PingOne Identity Cloud to Okta, including configuration, testing, validation, troubleshooting, deployment. • Assist with migration planning, architecture design, and implementation of access and identity flows in Okta. • Ensure IAM architecture and solutions adhere to security, privacy, regulatory, and consumer data protection requirements. • Work closely with IT, Security, and Delivery teams to ensure secure IAM solutions across all cloud systems. • Collaborate with delivery teams, product owners, and scrum masters to integrate IAM features into application releases. • Participate in sprint planning, backlog refinement, and technical design discussions to ensure identity requirements are considered early in development. • Support IAM changes during sprint release cycles, ensuring thorough testing and validation. • Coordinate IAM-related changes with DevOps and change management teams to minimize disruptions during deployments. • Provide guidance to IT and Delivery teams on secure authentication patterns, token usage, and best practices for IAM. • Ensure IAM solutions align with enterprise security policies, identify gaps, and provide progress updates. • Monitor IAM environments for authentication issues, anomalies, and performance bottlenecks. • Document IAM architectures, integrations, and operational procedures. • Execute and manage access recertification campaigns, ensuring timely completion and accurate audit reporting. • Implement and maintain least-privilege and segregation-of-duties controls across IAM systems. • Leverage microservices and API architectures to design, build, and manage IAM functionalities, enabling secure and scalable authentication, authorization, and service access controls. • Serve as the primary technical contact with the Ping Identity support team to address environment-related issues, tenant performance concerns, incidents, and troubleshooting. • Track vendor releases, platform updates, and new capabilities for adoption within the organization. • Coordinate maintenance windows, patch updates, and feature releases with the Change Advisory Board, Delivery Team, and Ping Identity vendor. • Validate vendor fixes in lower environments before production rollout. • Monitor authentication health, login trends, and token issuance metrics. • Perform root cause analysis for authentication and authorization incidents. • Assist in investigations of security incidents involving identity compromise. • Maintain detailed logging and audit trails aligned with regulatory requirements. • Monitor IAM logs and integrate events with SIEM platforms to support security monitoring and incident response. • Support audit activities by providing technical guidance and documentation, and act as a liaison for internal and external audit reviews as needed. • Develop automation scripts (e.g., Python, Java, or similar) to streamline IAM processes. • Leverage PingOne REST APIs for configuration management tasks. • Support CI/CD deployment of IAM configurations. • Support infrastructure-as-code initiatives where applicable. • Assist the IAM Lead and Information Security Manager (ISM) in reviewing IAM capabilities and defining a roadmap for IAM enhancements. • Support the development and implementation of information security awareness and training initiatives. • Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the IAM Lead and ISM. • Provide regular briefings to the IAM Lead and ISM, escalating issues and blockers as necessary. • Perform other duties as assigned within the scope of IAM. QUALIFICATIONS Required: • Minimum of seven (7) years of experience in Customer Identity and Access Management (CIAM) implementation and support, with a minimum of three (3) years within that experience focused on implementing and supporting CIAM solutions using PingOne Identity Cloud. • Hands-on experience with Okta including SSO, MFA, federation, application integrations, and identity lifecycle management. • Experience with IAM migration projects. • Hands-on experience implementing authentication and authorization protocols including OAuth, OIDC, and SAML. • Experience integrating web, mobile, and API applications with IAM platforms using token-based authentication mechanisms. • Experience in implementing SSO, MFA, federation, and identity lifecycle management. • Familiarity with customer registration, authentication journeys, and identity flows in CIAM platforms. • Hands-on software development or scripting experience using languages such as Java, JavaScript, Python, or similar. • Demonstrated knowledge of IAM best practices, including risk-based authentication and consumer data protection strategies. • Experience supporting IRS/CMS or other relevant audits in the context of IAM. • Experience working in Agile/Scrum environments, collaborating with product owners, scrum masters, and development teams during sprint cycles. • Familiarity with DevOps processes, change management, and release coordination to support secure and stable deployments. • Understanding of secure authentication patterns, token lifecycle management, and identity integration best practices. • Experience working with enterprise security policies, identity governance practices, and compliance requirements. • Demonstrated communication and collaboration skills with the ability to provide technical guidance to IT, delivery teams, and developers on secure IAM integration. • Minimum of seven (7) years of experience in IAM, including work with Customer Identity and Access Management (CIAM) platforms. • Experience working with REST API integrations for IAM services. • Knowledge in integrating IAM systems with API gateways and backend services to ensure secure access control. • Experience managing IAM platform configuration changes and automated deployments across development, staging, and production environments. • Experience integrating IAM platforms with SIEM or security monitoring tools for authentication and identity event monitoring. Desired: • Experienced in creating comprehensive reports and dashboards to communicate findings, track remediation progress, and provide visibility to management and relevant teams. • Experience participating in sprint planning, backlog refinement, and technical design discussions to integrate identity and authentication requirements into application development. • Motivated self-starter with initiative to take independent action and accept responsibility for your actions. • Excellent understanding of emerging threats in the IAM landscape. • Hands-on experience with CI/CD pipelines for IAM configuration deployments, including tools such as Jenkins. • Experience using source control and deployment workflows with GitHub for managing IAM configuration scripts or integration code. • Familiarity with DevOps practices and infrastructure automation supporting IAM or CIAM platform changes. • Experience troubleshooting authentication failures, federation issues, token validation issues, and identity integrations. • Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross-functional teams as well as external partners and vendors. • Ability to prioritize identified gaps and collaborate with cross-functional teams to ensure timely remediation and effective risk mitigation. • Demonstrates a proactive approach by consistently identifying potential blockers and communicating them early, while maintaining a solutions-focused mindset to facilitate continued progress. • Creative and proactive problem solver; must possess the ability to make independent decisions, set work priorities, and address issues promptly. • Experience in developing, reviewing, and updating security standards, procedures, awareness, and training. • Demonstrated knowledge of secure software development lifecycle (SDLC) and secure architecture design principles. APPLICATION INSTRUCTIONS This position will be open until we find a suitable number of candidates to review. If interested, please submit an application as soon as possible. The Exchange reserves the right to close the recruitment at any time. SALARY INFORMATION Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00. Hiring Range: $ 113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer. The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum. BENEFITS Take a peek at our benefits package. WORKING CONDITIONS Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location. The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. SPECIAL REQUIREMENTS A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The incumbent in this role will also be required to complete a federal fingerprint background check. The results of these background screens must meet the Exchange’s eligibility standards. OTHER INFORMATION The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified. This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice. The Washington Health Benefit Exchange is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. We participate in E-Verify. You can view the Department of Justice's Right to Work poster here.

Vacancy posted 25 days ago
Similar jobs that could be interesting for youBased on the Senior Identity and Access Management Engineer in Olympia, WA vacancy
  • $86.5k - $142.7k

     ...proofs‑of‑concept, and guiding engineering teams through complex...  ...engagements in Digital Engineering Managed Services. Hands‑on solution architecture...  ...products and platforms. Access to modern engineering stacks,...  ..., sexual orientation, gender identity/expression, pregnancy,... 
    Senior
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Olympia, WA
    1 day ago
  •  ...Senior Software Test Engineer [3189A589] ProSidian is a management and operations consulting firm with a reputation for its strong national practice spanning six...  ...national origin, sex, sexual orientation, gender identity and expression, age, disability, Vietnam era, or... 
    Senior
    Temporary work
    Work experience placement
    Work at office
    Flexible hours

    ProSidian Consulting

    Tumwater, WA
    5 days ago
  • $71.2k - $158.2k

     ...seeking a skilled Federal Senior Engineer/Architect (Principal Consultant...  ...teams • 3rd party vendor management and engineering project...  ...employment process. If you require accessibility assistance or accommodation...  ...sexual orientation, gender identity, disability and protected... 
    Senior
    Temporary work
    Flexible hours

    Oracle

    Olympia, WA
    16 hours ago
  • $84.63k - $112.84k

     ...This position is for a Field Engineer that will perform multiple tasks...  ...deemed necessary by management and/or customer. What We Look...  ..., sexual orientation, gender identity, gender expression, marital status...  ...how individuals may request access to or deletion of their... 
    Senior
    Full time
    Temporary work
    For subcontractor
    Remote work

    Lumen

    Olympia, WA
    4 days ago
  •  ...Power Systems, Inc. (EPS) is a specialized engineering firm with deep expertise in power system...  ...clients, vendors, and internal teams to manage design deliverables Conducting field...  ...regard to race, color, religion, gender identity, sexual orientation, age, disability,... 
    Senior
    Relocation package

    Electric Power Systems Inc

    Olympia, WA
    14 days ago
  • $55 - $60 per hour

     ...are seeking an Asset Operations Senior Professional to join a leading...  ...and Asset Administration Manage reporting functions related to...  ...of benefits. Benefits include access to top-tier employers and job...  ...national origin, disability, gender identity, sexual orientation, veteran... 
    Senior
    Hourly pay
    Daily paid
    Work at office

    Edwards Lifesciences Belgium

    Olympia, WA
    5 days ago
  • $58.1k - $95.9k

     ...Position Overview The Change Management Engineer designs, implements, and governs ITIL-aligned change management processes that control...  ...individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are... 
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Olympia, WA
    2 days ago
  • $105.79k - $141.05k

     ...datacenter connectivity, cloud access, and AI workloads. This...  ...flexibility. · Simply complex engineering principles into concise business...  ...action plans. · Ability to manage and execute changing...  ..., sexual orientation, gender identity, gender expression, marital status... 
    Full time
    Temporary work
    Remote work
    Work from home

    Lumen

    Olympia, WA
    2 hours ago
  • $67k - $124k

     ...Sr. Associate, Field, Engineer Job Code: 35737 Job Location...  ...the world. This Senior Associate Field...  ...system engineers, program managers, and field engineers regarding...  ...conditions), gender identity, gender expression,...  ...requirements for access to classified information... 
    Senior
    Local area
    Flexible hours

    Harris Geospatial Solutions

    Dupont, WA
    2 days ago
  • $25.48 - $60.63 per hour

     ...ensuring that veterans have access to timely and high-quality healthcare...  ...focus is the Group Practice Manager (GPM), RCT coordinators,...  ...build. Responsibilities As a Senior Consultant, you will consult...  ..., sexual orientation, gender identity, disability and protected veterans... 
    Senior
    Hourly pay
    Temporary work
    Work experience placement
    Local area
    Flexible hours

    Oracle

    Olympia, WA
    1 day ago
  • $132.23k - $176.31k

     ...us today. The Role The Senior Manager, Security and Enablement...  ...role, you’ll partner across engineering, cloud, and business teams to...  ...sexual orientation, gender identity, gender expression, marital...  ...how individuals may request access to or deletion of their personal... 
    Senior
    Temporary work
    Remote work

    Lumen

    Olympia, WA
    3 days ago
  •  ...Consulting team, Parexel is seeking an experienced Senior Regulatory Affairs Consultant (Program / Client Partnership Manager) to join our team. In this pivotal role, you...  ..., religion, sex, sexual orientation, gender identity, national origin, disability, or protected... 
    Senior
    Remote work

    PAREXEL

    Olympia, WA
    1 day ago
  •  ...Description Position Overview: Provides senior-level technical engineering and implementation support to...  ...system installations and manages projects. · Creates technical system...  ...religion, sex, sexual orientation, gender identity, national origin, veteran or disability... 
    Senior

    Day Wireless Systems

    Olympia, WA
    27 days ago
  •  ...clients. Technology – Data and Decision Science – AI Native Engineering AI Engineering, Senior Manager, Consultant The opportunity EY is making significant...  ...color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national... 
    Senior
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Olympia, WA
    1 day ago
  • $106.9k - $176.5k

     ...your unique skills and ambitions. As a Senior AI Native Engineer, you will be at the forefront of...  ...direction. Proven experience in project management and tracking deliverable completion....  ...age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information... 
    Senior
    Full time
    Work experience placement
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Olympia, WA
    5 days ago
  • $139.4k - $291.8k

     ...work with teams of applied scientists and engineers to deliver high quality computer vision...  ...the employment process. If you require accessibility assistance or accommodation for a...  ...national origin, sexual orientation, gender identity, disability and protected veterans'... 
    Senior
    Temporary work
    Flexible hours

    Oracle

    Olympia, WA
    16 hours ago
  • $162k - $203k

     ...Sales Manager Serve as the sales manager for growing new Digital Data Center Customers. Must have 5 years of experience growing and managing...  ..., marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, sex, religion, or... 
    Senior
    Temporary work
    Work experience placement
    Flexible hours

    Honeywell

    Olympia, WA
    5 days ago
  • $120k - $140k

     ...Overview GovCIO is seeking a highly experienced Senior Technical Advisor/Delivery Manager to serve as a senior consultant and to manage software release...  ...regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin,... 
    Senior
    Full time
    Work at office
    Remote work
    Monday to Friday
    Flexible hours

    GovCIO

    Olympia, WA
    4 days ago
  • $94.1k - $144.8k

     ...The Database Administrator, Senior leads the design, implementation, and lifecycle management of enterprise database platforms...  ...reporting, and analytics workloads. Engineer and oversee high‑availability...  ...strategies, privileged access models, auditing policies, and... 
    Senior
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Olympia, WA
    5 days ago
  •  ...seasoned Regulatory Project Manager who can turn strategy into action...  ...cross‑functional teams and senior leadership to drive clarity,...  ...BA/BS degree in a scientific, engineering, or healthcare discipline...  ..., sexual orientation, gender identity, national origin, disability,... 
    Senior
    Work at office
    Work from home
    Worldwide

    PAREXEL

    Olympia, WA
    1 day ago
  • $130.2k - $143.9k

     ...A leading public sector solutions firm is seeking an experienced Product Manager to lead a team in defining product strategies for enterprise SaaS products. This remote position requires extensive experience in product management, along with strategic planning and excellent... 
    Senior
    Remote work

    Public Consulting Group

    Olympia, WA
    1 day ago
  • $142.6k - $261.5k

     ...data scientists, designers, and software engineers enable our clients to solve their most...  ...requirements. Your key responsibilities As a Manager in Application Design and Development,...  ..., age, sex, sexual orientation, gender identity/expression, pregnancy, genetic... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Olympia, WA
    1 day ago
  • $121.5k - $227.2k

     ...pricing, and commercial models across Audit, Transformations, Managed Services, SaaS, and other relevant business models, as appropriate...  ...to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin,... 
    Senior
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Olympia, WA
    5 days ago
  • $72.7k

     ...completion dates and communicating report status to customers and management, and resolves business problems related to automated systems...  ...policies. As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential... 
    Senior
    For contractors
    Work at office

    Highmark Health

    Olympia, WA
    5 days ago
  •  ...Humana Inc in Olympia, Washington is seeking a Senior Compensation Incentive Design Professional to develop and administer incentive...  ...skills, and experience in data analysis, modeling, and project management, while enjoying competitive benefits and a collaborative work environment... 
    Senior

    Humana

    Olympia, WA
    5 days ago
  •  ...A leading travel management company in Olympia, WA, is looking for a Travel Consultant to provide exceptional service to defense and government travelers. Responsibilities include advising on travel arrangements, utilizing GDS systems like Sabre, and ensuring compliance... 
    Senior
    Flexible hours

    American Express Global Business Travel

    Olympia, WA
    2 days ago
  • $141.12k - $220.5k

     ...We are seeking a Senior Project Manager to join our Capital Execution team. This role reports directly...  .... Responsibilities Identify Chemours engineering and design resources. Work with...  ...family status, sexual orientation, gender identity or expression, or veteran status.... 
    Senior
    Contract work
    For contractors
    Work at office
    Local area

    The Chemours Company

    Olympia, WA
    4 days ago
  • $97.5k - $131.63k

     ...Job Description Summary: The Senior Account Executive is an enterprise...  ...with license account managers. Sells complex services and/or...  ...extended team of Rocket sales engineers, marketing and lab groups. Ensure...  ..., religion, gender, gender identity or expression, sexual... 
    Senior
    Remote work
    Worldwide

    Rocket Software

    Olympia, WA
    5 days ago
  • $67.5k - $126k

     ...Carlsbad Tech is looking for a Senior Epic Systems Analyst (Beaker) to manage Epic software and support environments remotely. The ideal candidate will have over 5 years of experience in Epic systems administration, with excellent communication and customer service skills... 
    Senior
    Remote work

    Carlsbad Tech

    Olympia, WA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Identity and Access Management Engineer. Be the first to apply!